CIS Controls CIS-4.11

Remotely wipe enterprise data from enterprise-owned portable end-user devices when deemed appropriate such as lost or stolen devices, or when an individual no longer supports the enterprise.

Mappings

Capability ID Capability Description Mapping Type ATT&CK ID ATT&CK Name Notes
CIS-4.11 Enforce Remote Wipe Capability on Portable End-User Devices mitigates T1005 Data from Local System
Comments
A successful remote wipe removes enterprise files, local databases, cached content, and other managed data before an adversary with possession of the device can collect it.
References
    CIS-4.11 Enforce Remote Wipe Capability on Portable End-User Devices mitigates T1114.001 Local Email Collection
    Comments
    Wiping managed email applications and locally cached mailbox files can prevent collection of Outlook PST or OST files and other locally stored enterprise email.
    References
      CIS-4.11 Enforce Remote Wipe Capability on Portable End-User Devices mitigates T1539 Steal Web Session Cookie
      Comments
      Wiping managed browsers and application data removes locally stored enterprise session cookies before they can be extracted from a lost or stolen device.
      References
        CIS-4.11 Enforce Remote Wipe Capability on Portable End-User Devices mitigates T1552.001 Credentials In Files
        Comments
        Remote wipe can remove managed files containing passwords, API keys, connection strings, or other credential material. The mitigation is limited to files covered by the wipe and does not address credentials stored elsewhere.
        References
          CIS-4.11 Enforce Remote Wipe Capability on Portable End-User Devices mitigates T1552.002 Credentials in Registry
          Comments
          A full Windows device wipe removes local Registry hives containing enterprise credential material before they can be searched or exported. A selective enterprise-data wipe may not remove operating-system Registry data.
          References
            CIS-4.11 Enforce Remote Wipe Capability on Portable End-User Devices mitigates T1552.004 Private Keys
            Comments
            Wiping enterprise-managed key files, certificates, VPN profiles, and application containers can prevent private keys from being obtained from a lost device. Keys synchronized elsewhere or already exported remain exposed and should be revoked separately.
            References
              CIS-4.11 Enforce Remote Wipe Capability on Portable End-User Devices mitigates T1555.001 Keychain
              Comments
              A full wipe of a managed macOS device removes locally stored Keychain databases and enterprise certificates. Items synchronized to other devices or already extracted are not revoked merely by wiping the device.
              References
                CIS-4.11 Enforce Remote Wipe Capability on Portable End-User Devices mitigates T1555.003 Credentials from Web Browsers
                Comments
                Remote wipe of managed browser profiles can remove locally stored enterprise passwords and related authentication data. Browser-synchronized credentials and already extracted copies require separate account or server-side action.
                References
                  CIS-4.11 Enforce Remote Wipe Capability on Portable End-User Devices mitigates T1555.004 Windows Credential Manager
                  Comments
                  A full Windows wipe removes local Credential Manager vault files and associated enterprise credentials. Selective wipe implementations may not remove credentials stored outside managed application containers.
                  References
                    CIS-4.11 Enforce Remote Wipe Capability on Portable End-User Devices mitigates T1552.003 Shell History
                    Comments
                    A full device wipe removes local shell-history files that may contain passwords, tokens, or sensitive commands. Selective enterprise wipes may not remove operating-system shell histories.
                    References
                      CIS-4.11 Enforce Remote Wipe Capability on Portable End-User Devices mitigates T1555.005 Password Managers
                      Comments
                      Remote wipe can remove a managed password-manager application, its local vault, and cached decrypted data. Cloud-hosted vault contents remain available and require account revocation, device removal, or token invalidation.
                      References