Securely manage enterprise assets and software. Example implementations include managing configuration through version-controlled Infrastructure-as-Code (IaC) and accessing administrative interfaces over secure network protocols, such as Secure Shell (SSH) and Hypertext Transfer Protocol Secure (HTTPS). Do not use insecure management protocols, such as Telnet (Teletype Network) and HTTP, unless operationally essential.
| Capability ID | Capability Description | Mapping Type | ATT&CK ID | ATT&CK Name | Notes |
|---|---|---|---|---|---|
| CIS-4.6 | Securely Manage Enterprise Assets and Software | mitigates | T1040 | Network Sniffing |
Comments
Replacing plaintext administrative protocols such as Telnet and HTTP with SSH and HTTPS prevents captured management traffic from directly exposing credentials, commands, and configuration data. Encryption does not prevent packet capture, but it materially reduces the value of the captured traffic.
References
|
| CIS-4.6 | Securely Manage Enterprise Assets and Software | mitigates | T1072 | Software Deployment Tools |
Comments
Safeguard 4.6 directly concerns securely managing software and configuration-management platforms, including tools integrated with CI/CD systems. Restricting administrative access and managing deployment configuration through controlled, versioned mechanisms reduces unauthorized use of these platforms for execution and lateral movement.
References
|
| CIS-4.6 | Securely Manage Enterprise Assets and Software | mitigates | T1210 | Exploitation of Remote Services |
Comments
Disabling obsolete management protocols and securely configuring required administrative services reduces the number of remotely reachable and vulnerable services. The safeguard does not patch vulnerabilities, but it directly removes insecure management paths that could be exploited.
References
|
| CIS-4.6 | Securely Manage Enterprise Assets and Software | mitigates | T1552.007 | Container API |
Comments
Disabling unauthenticated Docker and Kubernetes API access and requiring secured channels such as SSH or TLS directly reduces unauthorized access to container-management interfaces. This closely matches the safeguard's requirement to access administrative interfaces through secure protocols.
References
|
| CIS-4.6 | Securely Manage Enterprise Assets and Software | mitigates | T1557 | Adversary-in-the-Middle |
Comments
Authenticated encryption through SSH, HTTPS, and TLS limits an adversary's ability to read or alter administrative traffic even after obtaining a network interception position. Certificate and SSH host-key validation remain essential to the effectiveness of the mitigation.
References
|
| CIS-4.6 | Securely Manage Enterprise Assets and Software | mitigates | T1565.002 | Transmitted Data Manipulation |
Comments
SSH and HTTPS provide confidentiality and integrity protection for management commands and configuration data in transit. This makes undetected modification of administrative traffic substantially more difficult.
References
|
| CIS-4.6 | Securely Manage Enterprise Assets and Software | mitigates | T1602 | Data from Configuration Repository |
Comments
Secure management protocols, authenticated access, and controlled configuration repositories directly reduce unauthorized collection of device and infrastructure configuration. Version-controlled Infrastructure-as-Code can also reduce the need to retrieve configurations through insecure management interfaces.
References
|
| CIS-4.6 | Securely Manage Enterprise Assets and Software | mitigates | T1602.001 | SNMP (MIB Dump) |
Comments
Migrating from insecure SNMP versions to SNMPv3 with authentication and privacy protection directly reduces unauthorized MIB collection. Restricting management access to approved systems further limits successful enumeration.
References
|
| CIS-4.6 | Securely Manage Enterprise Assets and Software | mitigates | T1602.002 | Network Device Configuration Dump |
Comments
Using SSH, HTTPS, SNMPv3, and securely managed configuration repositories reduces exposure of network-device configurations and embedded credentials. Insecure services such as Telnet, HTTP, TFTP, or legacy management protocols create substantially greater collection risk.
References
|
| CIS-4.6 | Securely Manage Enterprise Assets and Software | mitigates | T1609 | Container Administration Command |
Comments
Restricting Docker and Kubernetes administration to authenticated TLS, SSH, local sockets, or other secured management channels directly reduces unauthorized remote container commands. Version-controlled manifests and Infrastructure-as-Code also reduce unreviewed administrative changes.
References
|
| CIS-4.6 | Securely Manage Enterprise Assets and Software | mitigates | T1659 | Content Injection |
Comments
HTTPS and other authenticated encrypted protocols make it more difficult for an adversary positioned in the network path to inject malicious content into management downloads or administrative sessions. This is a direct benefit of prohibiting plaintext HTTP management.
References
|
| CIS-4.6 | Securely Manage Enterprise Assets and Software | mitigates | T1689 | Downgrade Attack |
Comments
This safeguard explicitly prohibits fallback to insecure protocols such as HTTP and Telnet. Enforcing HTTPS, modern TLS, SSH, and policies such as HSTS directly limits attempts to downgrade management communications to weaker or plaintext alternatives.
References
|
| CIS-4.6 | Securely Manage Enterprise Assets and Software | mitigates | T1021 | Remote Services |
Comments
Securely managing which remote services are permitted and requiring authenticated encrypted protocols reduces exposed administrative paths. The safeguard does not independently prevent adversaries from using valid credentials through an approved service.
References
|
| CIS-4.6 | Securely Manage Enterprise Assets and Software | mitigates | T1021.001 | Remote Desktop Protocol |
Comments
Secure RDP configuration, gateways, TLS, and restricted administrative access reduce interception and direct exposure. RDP remains usable by an adversary who possesses authorized credentials or an active session.
References
|
| CIS-4.6 | Securely Manage Enterprise Assets and Software | mitigates | T1021.002 | SMB/Windows Admin Shares |
Comments
Secure management can disable unnecessary administrative shares and require modern SMB signing or encryption where remote administration is needed. It does not fully prevent abuse of an authorized SMB management path.
References
|
| CIS-4.6 | Securely Manage Enterprise Assets and Software | mitigates | T1021.003 | Distributed Component Object Model |
Comments
Securely managing DCOM availability and restricting it to approved administrative workflows reduces remote abuse. DCOM does not have a simple SSH or HTTPS replacement, so effectiveness depends on disabling or tightly constraining it.
References
|
| CIS-4.6 | Securely Manage Enterprise Assets and Software | mitigates | T1021.004 | SSH |
Comments
SSH protects administrative credentials and commands from plaintext interception and should replace Telnet. It does not prevent an adversary with valid credentials or an unauthorized SSH key from using the service.
References
|
| CIS-4.6 | Securely Manage Enterprise Assets and Software | mitigates | T1021.005 | VNC |
Comments
Secure management can prohibit unencrypted VNC deployments or require encrypted tunnels and approved administrative tooling. The relationship is partial because some VNC implementations or tunnels remain accessible with valid credentials.
References
|
| CIS-4.6 | Securely Manage Enterprise Assets and Software | mitigates | T1021.006 | Windows Remote Management |
Comments
Requiring WinRM over HTTPS rather than unencrypted HTTP protects management credentials and commands in transit. Authorized-account abuse remains possible through the secured channel.
References
|
| CIS-4.6 | Securely Manage Enterprise Assets and Software | mitigates | T1021.007 | Cloud Services |
Comments
Securing cloud administrative consoles and APIs, using controlled automation, and managing resources through version-controlled Infrastructure-as-Code reduces ad hoc and insecure administration. It does not prevent malicious activity performed through a compromised authorized cloud account.
References
|
| CIS-4.6 | Securely Manage Enterprise Assets and Software | mitigates | T1021.008 | Direct Cloud VM Connections |
Comments
Approved and securely configured cloud-native VM connection methods reduce exposure from direct or insecure management services. Cloud control-plane access may bypass the guest operating system's network controls, so identity and cloud policy protections are also required.
References
|
| CIS-4.6 | Securely Manage Enterprise Assets and Software | mitigates | T1059.008 | Network Device CLI |
Comments
Requiring SSH rather than Telnet protects command-line interface credentials and commands in transit and reduces interception or manipulation. Once an adversary has authorized administrative access, the encrypted CLI still permits malicious commands.
References
|
| CIS-4.6 | Securely Manage Enterprise Assets and Software | mitigates | T1133 | External Remote Services |
Comments
Requiring secure protocols and centrally managed administrative access reduces risk from externally accessible management services. Additional protections such as multi-factor authentication, gateways, and network restrictions remain necessary.
References
|
| CIS-4.6 | Securely Manage Enterprise Assets and Software | mitigates | T1190 | Exploit Public-Facing Application |
Comments
Administrative web interfaces should use HTTPS and should not be exposed through unnecessary plaintext or legacy services. HTTPS does not remediate an application vulnerability, so this mitigation primarily reduces unnecessary exposure and traffic manipulation.
References
|
| CIS-4.6 | Securely Manage Enterprise Assets and Software | mitigates | T1098.004 | SSH Authorized Keys |
Comments
Version-controlled SSH configuration and managed deployment of approved keys can prevent or identify unauthorized additions to authorized_keys. File permissions and privileged access controls are still needed to prevent local modification.
References
|
| CIS-4.6 | Securely Manage Enterprise Assets and Software | mitigates | T1213.003 | Code Repositories |
Comments
Infrastructure-as-Code repositories may reveal infrastructure topology, administrative endpoints, configuration, and embedded credentials. Secure repository administration and keeping secrets outside version control reduce the value and accessibility of these repositories.
References
|
| CIS-4.6 | Securely Manage Enterprise Assets and Software | mitigates | T1219 | Remote Access Tools |
Comments
Secure software management can limit administration to approved and securely configured remote-access products. The safeguard does not prevent an approved tool or account from being abused by an adversary.
References
|
| CIS-4.6 | Securely Manage Enterprise Assets and Software | mitigates | T1219.001 | IDE Tunneling |
Comments
Securely managing development tools can disable unnecessary tunneling functions and restrict approved remote-development services. Legitimate HTTPS or SSH development channels may still be abused.
References
|
| CIS-4.6 | Securely Manage Enterprise Assets and Software | mitigates | T1219.002 | Remote Desktop Software |
Comments
Organizations can centrally approve, configure, and secure remote-support software while removing unauthorized products. An adversary may still misuse an approved product or compromised support account.
References
|
| CIS-4.6 | Securely Manage Enterprise Assets and Software | mitigates | T1552.001 | Credentials In Files |
Comments
Infrastructure code, configuration files, deployment manifests, and automation scripts frequently create a risk of embedded passwords or tokens. Secure management should keep credentials out of source-controlled configuration and use protected secret stores or runtime injection.
References
|
| CIS-4.6 | Securely Manage Enterprise Assets and Software | mitigates | T1552.004 | Private Keys |
Comments
SSH administration depends on protecting private keys and preventing them from being embedded in repositories or widely distributed. Managed key storage, permissions, and rotation reduce the likelihood that stolen keys can be used for administration.
References
|
| CIS-4.6 | Securely Manage Enterprise Assets and Software | mitigates | T1610 | Deploy Container |
Comments
Requiring container deployments through approved, authenticated orchestration interfaces and version-controlled manifests reduces unauthorized container creation. A compromised orchestrator account or approved pipeline may still deploy a malicious container.
References
|
| CIS-4.6 | Securely Manage Enterprise Assets and Software | mitigates | T1612 | Build Image on Host |
Comments
Securing container-management APIs and restricting builds to controlled Infrastructure-as-Code or pipeline processes reduces unauthorized image construction on managed hosts. It does not prevent misuse by a compromised authorized build identity.
References
|
| CIS-4.6 | Securely Manage Enterprise Assets and Software | mitigates | T1651 | Cloud Administration Command |
Comments
Version-controlled Infrastructure-as-Code and controlled cloud-administration interfaces reduce unreviewed interactive commands and restrict administration to approved mechanisms. The technique remains possible through a compromised privileged cloud account.
References
|
| CIS-4.6 | Securely Manage Enterprise Assets and Software | mitigates | T1677 | Poisoned Pipeline Execution |
Comments
Version-controlled infrastructure and reviewed changes can prevent untrusted code or malicious Infrastructure-as-Code modifications from automatically reaching privileged deployment pipelines. Additional CI/CD isolation, branch protection, and secrets controls are required.
References
|
| CIS-4.6 | Securely Manage Enterprise Assets and Software | mitigates | T1557.001 | Name Resolution Poisoning and SMB Relay |
Comments
SSH host-key validation, HTTPS certificate validation, SMB signing, and encrypted management channels reduce the ability to capture or relay administrative authentication. Disabling LLMNR, NBT-NS, and unnecessary SMB remains an important complementary control.
References
|
| CIS-4.6 | Securely Manage Enterprise Assets and Software | mitigates | T1557.002 | ARP Cache Poisoning |
Comments
An adversary may still redirect management traffic through ARP poisoning, but properly validated SSH and HTTPS sessions protect the confidentiality and integrity of that traffic. The safeguard does not prevent the underlying ARP manipulation.
References
|
| CIS-4.6 | Securely Manage Enterprise Assets and Software | mitigates | T1557.003 | DHCP Spoofing |
Comments
Secure protocols reduce credential theft and command manipulation even if DHCP spoofing redirects traffic. DHCP snooping and network-level controls are still required to prevent the spoofing behavior itself.
References
|
| CIS-4.6 | Securely Manage Enterprise Assets and Software | mitigates | T1565 | Data Manipulation |
Comments
Version-controlled configuration and authenticated encrypted management channels reduce unauthorized or undetected changes to enterprise configuration. The safeguard does not protect every type of business or application data.
References
|
| CIS-4.6 | Securely Manage Enterprise Assets and Software | mitigates | T1565.001 | Stored Data Manipulation |
Comments
Version-controlled Infrastructure-as-Code provides history, review, comparison, and restoration for managed configurations, reducing the persistence of unauthorized configuration changes. This applies only where the affected configuration is actually managed as code.
References
|
| CIS-4.6 | Securely Manage Enterprise Assets and Software | mitigates | T1563 | Remote Service Session Hijacking |
Comments
Securely configuring remote services can reduce unnecessary sessions and restrict features that facilitate hijacking. Encryption does not prevent an adversary already executing on a system from taking control of an existing session.
References
|
| CIS-4.6 | Securely Manage Enterprise Assets and Software | mitigates | T1563.001 | SSH Hijacking |
Comments
Disabling SSH agent forwarding and tightly managing SSH configuration reduces some hijacking paths. It does not prevent local theft or reuse of an established SSH socket or session.
References
|
| CIS-4.6 | Securely Manage Enterprise Assets and Software | mitigates | T1563.002 | RDP Hijacking |
Comments
Secure RDP gateways and restricted administration reduce access to RDP sessions. They do not prevent a locally privileged adversary from taking control of an existing session.
References
|
| CIS-4.6 | Securely Manage Enterprise Assets and Software | mitigates | T1090.001 | Internal Proxy |
Comments
Secure SSH configuration can disable unnecessary forwarding and proxy features, reducing the ability to turn a managed asset into a pivot.
References
|
| CIS-4.6 | Securely Manage Enterprise Assets and Software | mitigates | T1572 | Protocol Tunneling |
Comments
Securely configuring SSH, VPN, and administrative tools can disable unnecessary port forwarding and tunneling functions. The safeguard does not prevent tunneling through an otherwise approved secure protocol when that capability is operationally required.
References
|
| CIS-4.6 | Securely Manage Enterprise Assets and Software | mitigates | T1484 | Domain or Tenant Policy Modification |
Comments
Version-controlled domain or tenant configuration can make unauthorized policy changes visible and allow restoration to approved state. Many identity policies are still managed directly through consoles or APIs rather than Infrastructure-as-Code.
References
|
| CIS-4.6 | Securely Manage Enterprise Assets and Software | mitigates | T1484.001 | Group Policy Modification |
Comments
Managing Group Policy definitions through controlled configuration processes can identify or reverse unauthorized changes. Version control does not prevent direct modification by an account that retains write access to the policy.
References
|
| CIS-4.6 | Securely Manage Enterprise Assets and Software | mitigates | T1578 | Modify Cloud Compute Infrastructure |
Comments
Version-controlled Infrastructure-as-Code can define expected compute infrastructure and identify or reverse out-of-band changes. An adversary with sufficient cloud permissions may still modify resources directly.
References
|
| CIS-4.6 | Securely Manage Enterprise Assets and Software | mitigates | T1578.005 | Modify Cloud Compute Configurations |
Comments
Infrastructure-as-Code provides an approved baseline for quotas, instance settings, and compute configurations, allowing unauthorized drift to be identified or corrected.
References
|