CIS Controls CIS-4.6

Securely manage enterprise assets and software. Example implementations include managing configuration through version-controlled Infrastructure-as-Code (IaC) and accessing administrative interfaces over secure network protocols, such as Secure Shell (SSH) and Hypertext Transfer Protocol Secure (HTTPS). Do not use insecure management protocols, such as Telnet (Teletype Network) and HTTP, unless operationally essential.

Mappings

Capability ID Capability Description Mapping Type ATT&CK ID ATT&CK Name Notes
CIS-4.6 Securely Manage Enterprise Assets and Software mitigates T1040 Network Sniffing
Comments
Replacing plaintext administrative protocols such as Telnet and HTTP with SSH and HTTPS prevents captured management traffic from directly exposing credentials, commands, and configuration data. Encryption does not prevent packet capture, but it materially reduces the value of the captured traffic.
References
    CIS-4.6 Securely Manage Enterprise Assets and Software mitigates T1072 Software Deployment Tools
    Comments
    Safeguard 4.6 directly concerns securely managing software and configuration-management platforms, including tools integrated with CI/CD systems. Restricting administrative access and managing deployment configuration through controlled, versioned mechanisms reduces unauthorized use of these platforms for execution and lateral movement.
    References
      CIS-4.6 Securely Manage Enterprise Assets and Software mitigates T1210 Exploitation of Remote Services
      Comments
      Disabling obsolete management protocols and securely configuring required administrative services reduces the number of remotely reachable and vulnerable services. The safeguard does not patch vulnerabilities, but it directly removes insecure management paths that could be exploited.
      References
        CIS-4.6 Securely Manage Enterprise Assets and Software mitigates T1552.007 Container API
        Comments
        Disabling unauthenticated Docker and Kubernetes API access and requiring secured channels such as SSH or TLS directly reduces unauthorized access to container-management interfaces. This closely matches the safeguard's requirement to access administrative interfaces through secure protocols.
        References
          CIS-4.6 Securely Manage Enterprise Assets and Software mitigates T1557 Adversary-in-the-Middle
          Comments
          Authenticated encryption through SSH, HTTPS, and TLS limits an adversary's ability to read or alter administrative traffic even after obtaining a network interception position. Certificate and SSH host-key validation remain essential to the effectiveness of the mitigation.
          References
            CIS-4.6 Securely Manage Enterprise Assets and Software mitigates T1565.002 Transmitted Data Manipulation
            Comments
            SSH and HTTPS provide confidentiality and integrity protection for management commands and configuration data in transit. This makes undetected modification of administrative traffic substantially more difficult.
            References
              CIS-4.6 Securely Manage Enterprise Assets and Software mitigates T1602 Data from Configuration Repository
              Comments
              Secure management protocols, authenticated access, and controlled configuration repositories directly reduce unauthorized collection of device and infrastructure configuration. Version-controlled Infrastructure-as-Code can also reduce the need to retrieve configurations through insecure management interfaces.
              References
                CIS-4.6 Securely Manage Enterprise Assets and Software mitigates T1602.001 SNMP (MIB Dump)
                Comments
                Migrating from insecure SNMP versions to SNMPv3 with authentication and privacy protection directly reduces unauthorized MIB collection. Restricting management access to approved systems further limits successful enumeration.
                References
                  CIS-4.6 Securely Manage Enterprise Assets and Software mitigates T1602.002 Network Device Configuration Dump
                  Comments
                  Using SSH, HTTPS, SNMPv3, and securely managed configuration repositories reduces exposure of network-device configurations and embedded credentials. Insecure services such as Telnet, HTTP, TFTP, or legacy management protocols create substantially greater collection risk.
                  References
                    CIS-4.6 Securely Manage Enterprise Assets and Software mitigates T1609 Container Administration Command
                    Comments
                    Restricting Docker and Kubernetes administration to authenticated TLS, SSH, local sockets, or other secured management channels directly reduces unauthorized remote container commands. Version-controlled manifests and Infrastructure-as-Code also reduce unreviewed administrative changes.
                    References
                      CIS-4.6 Securely Manage Enterprise Assets and Software mitigates T1659 Content Injection
                      Comments
                      HTTPS and other authenticated encrypted protocols make it more difficult for an adversary positioned in the network path to inject malicious content into management downloads or administrative sessions. This is a direct benefit of prohibiting plaintext HTTP management.
                      References
                        CIS-4.6 Securely Manage Enterprise Assets and Software mitigates T1689 Downgrade Attack
                        Comments
                        This safeguard explicitly prohibits fallback to insecure protocols such as HTTP and Telnet. Enforcing HTTPS, modern TLS, SSH, and policies such as HSTS directly limits attempts to downgrade management communications to weaker or plaintext alternatives.
                        References
                          CIS-4.6 Securely Manage Enterprise Assets and Software mitigates T1021 Remote Services
                          Comments
                          Securely managing which remote services are permitted and requiring authenticated encrypted protocols reduces exposed administrative paths. The safeguard does not independently prevent adversaries from using valid credentials through an approved service.
                          References
                            CIS-4.6 Securely Manage Enterprise Assets and Software mitigates T1021.001 Remote Desktop Protocol
                            Comments
                            Secure RDP configuration, gateways, TLS, and restricted administrative access reduce interception and direct exposure. RDP remains usable by an adversary who possesses authorized credentials or an active session.
                            References
                              CIS-4.6 Securely Manage Enterprise Assets and Software mitigates T1021.002 SMB/Windows Admin Shares
                              Comments
                              Secure management can disable unnecessary administrative shares and require modern SMB signing or encryption where remote administration is needed. It does not fully prevent abuse of an authorized SMB management path.
                              References
                                CIS-4.6 Securely Manage Enterprise Assets and Software mitigates T1021.003 Distributed Component Object Model
                                Comments
                                Securely managing DCOM availability and restricting it to approved administrative workflows reduces remote abuse. DCOM does not have a simple SSH or HTTPS replacement, so effectiveness depends on disabling or tightly constraining it.
                                References
                                  CIS-4.6 Securely Manage Enterprise Assets and Software mitigates T1021.004 SSH
                                  Comments
                                  SSH protects administrative credentials and commands from plaintext interception and should replace Telnet. It does not prevent an adversary with valid credentials or an unauthorized SSH key from using the service.
                                  References
                                    CIS-4.6 Securely Manage Enterprise Assets and Software mitigates T1021.005 VNC
                                    Comments
                                    Secure management can prohibit unencrypted VNC deployments or require encrypted tunnels and approved administrative tooling. The relationship is partial because some VNC implementations or tunnels remain accessible with valid credentials.
                                    References
                                      CIS-4.6 Securely Manage Enterprise Assets and Software mitigates T1021.006 Windows Remote Management
                                      Comments
                                      Requiring WinRM over HTTPS rather than unencrypted HTTP protects management credentials and commands in transit. Authorized-account abuse remains possible through the secured channel.
                                      References
                                        CIS-4.6 Securely Manage Enterprise Assets and Software mitigates T1021.007 Cloud Services
                                        Comments
                                        Securing cloud administrative consoles and APIs, using controlled automation, and managing resources through version-controlled Infrastructure-as-Code reduces ad hoc and insecure administration. It does not prevent malicious activity performed through a compromised authorized cloud account.
                                        References
                                          CIS-4.6 Securely Manage Enterprise Assets and Software mitigates T1021.008 Direct Cloud VM Connections
                                          Comments
                                          Approved and securely configured cloud-native VM connection methods reduce exposure from direct or insecure management services. Cloud control-plane access may bypass the guest operating system's network controls, so identity and cloud policy protections are also required.
                                          References
                                            CIS-4.6 Securely Manage Enterprise Assets and Software mitigates T1059.008 Network Device CLI
                                            Comments
                                            Requiring SSH rather than Telnet protects command-line interface credentials and commands in transit and reduces interception or manipulation. Once an adversary has authorized administrative access, the encrypted CLI still permits malicious commands.
                                            References
                                              CIS-4.6 Securely Manage Enterprise Assets and Software mitigates T1133 External Remote Services
                                              Comments
                                              Requiring secure protocols and centrally managed administrative access reduces risk from externally accessible management services. Additional protections such as multi-factor authentication, gateways, and network restrictions remain necessary.
                                              References
                                                CIS-4.6 Securely Manage Enterprise Assets and Software mitigates T1190 Exploit Public-Facing Application
                                                Comments
                                                Administrative web interfaces should use HTTPS and should not be exposed through unnecessary plaintext or legacy services. HTTPS does not remediate an application vulnerability, so this mitigation primarily reduces unnecessary exposure and traffic manipulation.
                                                References
                                                  CIS-4.6 Securely Manage Enterprise Assets and Software mitigates T1098.004 SSH Authorized Keys
                                                  Comments
                                                  Version-controlled SSH configuration and managed deployment of approved keys can prevent or identify unauthorized additions to authorized_keys. File permissions and privileged access controls are still needed to prevent local modification.
                                                  References
                                                    CIS-4.6 Securely Manage Enterprise Assets and Software mitigates T1213.003 Code Repositories
                                                    Comments
                                                    Infrastructure-as-Code repositories may reveal infrastructure topology, administrative endpoints, configuration, and embedded credentials. Secure repository administration and keeping secrets outside version control reduce the value and accessibility of these repositories.
                                                    References
                                                      CIS-4.6 Securely Manage Enterprise Assets and Software mitigates T1219 Remote Access Tools
                                                      Comments
                                                      Secure software management can limit administration to approved and securely configured remote-access products. The safeguard does not prevent an approved tool or account from being abused by an adversary.
                                                      References
                                                        CIS-4.6 Securely Manage Enterprise Assets and Software mitigates T1219.001 IDE Tunneling
                                                        Comments
                                                        Securely managing development tools can disable unnecessary tunneling functions and restrict approved remote-development services. Legitimate HTTPS or SSH development channels may still be abused.
                                                        References
                                                          CIS-4.6 Securely Manage Enterprise Assets and Software mitigates T1219.002 Remote Desktop Software
                                                          Comments
                                                          Organizations can centrally approve, configure, and secure remote-support software while removing unauthorized products. An adversary may still misuse an approved product or compromised support account.
                                                          References
                                                            CIS-4.6 Securely Manage Enterprise Assets and Software mitigates T1552.001 Credentials In Files
                                                            Comments
                                                            Infrastructure code, configuration files, deployment manifests, and automation scripts frequently create a risk of embedded passwords or tokens. Secure management should keep credentials out of source-controlled configuration and use protected secret stores or runtime injection.
                                                            References
                                                              CIS-4.6 Securely Manage Enterprise Assets and Software mitigates T1552.004 Private Keys
                                                              Comments
                                                              SSH administration depends on protecting private keys and preventing them from being embedded in repositories or widely distributed. Managed key storage, permissions, and rotation reduce the likelihood that stolen keys can be used for administration.
                                                              References
                                                                CIS-4.6 Securely Manage Enterprise Assets and Software mitigates T1610 Deploy Container
                                                                Comments
                                                                Requiring container deployments through approved, authenticated orchestration interfaces and version-controlled manifests reduces unauthorized container creation. A compromised orchestrator account or approved pipeline may still deploy a malicious container.
                                                                References
                                                                  CIS-4.6 Securely Manage Enterprise Assets and Software mitigates T1612 Build Image on Host
                                                                  Comments
                                                                  Securing container-management APIs and restricting builds to controlled Infrastructure-as-Code or pipeline processes reduces unauthorized image construction on managed hosts. It does not prevent misuse by a compromised authorized build identity.
                                                                  References
                                                                    CIS-4.6 Securely Manage Enterprise Assets and Software mitigates T1651 Cloud Administration Command
                                                                    Comments
                                                                    Version-controlled Infrastructure-as-Code and controlled cloud-administration interfaces reduce unreviewed interactive commands and restrict administration to approved mechanisms. The technique remains possible through a compromised privileged cloud account.
                                                                    References
                                                                      CIS-4.6 Securely Manage Enterprise Assets and Software mitigates T1677 Poisoned Pipeline Execution
                                                                      Comments
                                                                      Version-controlled infrastructure and reviewed changes can prevent untrusted code or malicious Infrastructure-as-Code modifications from automatically reaching privileged deployment pipelines. Additional CI/CD isolation, branch protection, and secrets controls are required.
                                                                      References
                                                                        CIS-4.6 Securely Manage Enterprise Assets and Software mitigates T1557.001 Name Resolution Poisoning and SMB Relay
                                                                        Comments
                                                                        SSH host-key validation, HTTPS certificate validation, SMB signing, and encrypted management channels reduce the ability to capture or relay administrative authentication. Disabling LLMNR, NBT-NS, and unnecessary SMB remains an important complementary control.
                                                                        References
                                                                          CIS-4.6 Securely Manage Enterprise Assets and Software mitigates T1557.002 ARP Cache Poisoning
                                                                          Comments
                                                                          An adversary may still redirect management traffic through ARP poisoning, but properly validated SSH and HTTPS sessions protect the confidentiality and integrity of that traffic. The safeguard does not prevent the underlying ARP manipulation.
                                                                          References
                                                                            CIS-4.6 Securely Manage Enterprise Assets and Software mitigates T1557.003 DHCP Spoofing
                                                                            Comments
                                                                            Secure protocols reduce credential theft and command manipulation even if DHCP spoofing redirects traffic. DHCP snooping and network-level controls are still required to prevent the spoofing behavior itself.
                                                                            References
                                                                              CIS-4.6 Securely Manage Enterprise Assets and Software mitigates T1565 Data Manipulation
                                                                              Comments
                                                                              Version-controlled configuration and authenticated encrypted management channels reduce unauthorized or undetected changes to enterprise configuration. The safeguard does not protect every type of business or application data.
                                                                              References
                                                                                CIS-4.6 Securely Manage Enterprise Assets and Software mitigates T1565.001 Stored Data Manipulation
                                                                                Comments
                                                                                Version-controlled Infrastructure-as-Code provides history, review, comparison, and restoration for managed configurations, reducing the persistence of unauthorized configuration changes. This applies only where the affected configuration is actually managed as code.
                                                                                References
                                                                                  CIS-4.6 Securely Manage Enterprise Assets and Software mitigates T1563 Remote Service Session Hijacking
                                                                                  Comments
                                                                                  Securely configuring remote services can reduce unnecessary sessions and restrict features that facilitate hijacking. Encryption does not prevent an adversary already executing on a system from taking control of an existing session.
                                                                                  References
                                                                                    CIS-4.6 Securely Manage Enterprise Assets and Software mitigates T1563.001 SSH Hijacking
                                                                                    Comments
                                                                                    Disabling SSH agent forwarding and tightly managing SSH configuration reduces some hijacking paths. It does not prevent local theft or reuse of an established SSH socket or session.
                                                                                    References
                                                                                      CIS-4.6 Securely Manage Enterprise Assets and Software mitigates T1563.002 RDP Hijacking
                                                                                      Comments
                                                                                      Secure RDP gateways and restricted administration reduce access to RDP sessions. They do not prevent a locally privileged adversary from taking control of an existing session.
                                                                                      References
                                                                                        CIS-4.6 Securely Manage Enterprise Assets and Software mitigates T1090.001 Internal Proxy
                                                                                        Comments
                                                                                        Secure SSH configuration can disable unnecessary forwarding and proxy features, reducing the ability to turn a managed asset into a pivot.
                                                                                        References
                                                                                          CIS-4.6 Securely Manage Enterprise Assets and Software mitigates T1572 Protocol Tunneling
                                                                                          Comments
                                                                                          Securely configuring SSH, VPN, and administrative tools can disable unnecessary port forwarding and tunneling functions. The safeguard does not prevent tunneling through an otherwise approved secure protocol when that capability is operationally required.
                                                                                          References
                                                                                            CIS-4.6 Securely Manage Enterprise Assets and Software mitigates T1484 Domain or Tenant Policy Modification
                                                                                            Comments
                                                                                            Version-controlled domain or tenant configuration can make unauthorized policy changes visible and allow restoration to approved state. Many identity policies are still managed directly through consoles or APIs rather than Infrastructure-as-Code.
                                                                                            References
                                                                                              CIS-4.6 Securely Manage Enterprise Assets and Software mitigates T1484.001 Group Policy Modification
                                                                                              Comments
                                                                                              Managing Group Policy definitions through controlled configuration processes can identify or reverse unauthorized changes. Version control does not prevent direct modification by an account that retains write access to the policy.
                                                                                              References
                                                                                                CIS-4.6 Securely Manage Enterprise Assets and Software mitigates T1578 Modify Cloud Compute Infrastructure
                                                                                                Comments
                                                                                                Version-controlled Infrastructure-as-Code can define expected compute infrastructure and identify or reverse out-of-band changes. An adversary with sufficient cloud permissions may still modify resources directly.
                                                                                                References
                                                                                                  CIS-4.6 Securely Manage Enterprise Assets and Software mitigates T1578.005 Modify Cloud Compute Configurations
                                                                                                  Comments
                                                                                                  Infrastructure-as-Code provides an approved baseline for quotas, instance settings, and compute configurations, allowing unauthorized drift to be identified or corrected.
                                                                                                  References