Require all externally-exposed enterprise or third-party applications to enforce MFA, where supported. Enforcing MFA through a directory service or SSO provider is a satisfactory implementation of this Safeguard.
| Capability ID | Capability Description | Mapping Type | ATT&CK ID | ATT&CK Name | Notes |
|---|---|---|---|---|---|
| CIS-6.3 | Require MFA for Externally-Exposed Applications | mitigates | T1114.002 | Remote Email Collection |
Comments
Enabling multi-factor authentication for public-facing webmail servers helps minimize the usefulness of email usernames and passwords collected by adversaries.
References
|
| CIS-6.3 | Require MFA for Externally-Exposed Applications | mitigates | T1114 | Email Collection |
Comments
Enabling multi-factor authentication for public-facing webmail servers helps minimize the usefulness of email usernames and passwords collected by adversaries.
References
|
| CIS-6.3 | Require MFA for Externally-Exposed Applications | mitigates | T1110.003 | Password Spraying |
Comments
Enabling multi-factor authentication can prevent adversaries from gaining access through brute force password spraying attacks against authentication interfaces on externally facing services.
References
|
| CIS-6.3 | Require MFA for Externally-Exposed Applications | mitigates | T1110.002 | Password Cracking |
Comments
Enabling multi-factor authentication can prevent adversaries from gaining access through brute force password cracking attacks against authentication interfaces on externally facing services.
References
|
| CIS-6.3 | Require MFA for Externally-Exposed Applications | mitigates | T1110.001 | Password Guessing |
Comments
Enabling multi-factor authentication can prevent adversaries from gaining access through brute force password guessing attacks against authentication interfaces on externally facing services.
References
|
| CIS-6.3 | Require MFA for Externally-Exposed Applications | mitigates | T1110 | Brute Force |
Comments
Enabling multi-factor authentication can prevent adversaries from gaining access through brute force attacks against authentication interfaces on externally facing services.
References
|
| CIS-6.3 | Require MFA for Externally-Exposed Applications | mitigates | T1110.004 | Credential Stuffing |
Comments
Enabling multi-factor authentication can prevent adversaries from gaining access through brute force credential stuffing attacks against authentication interfaces on externally facing services.
References
|