CIS Controls CIS-6.3

Require all externally-exposed enterprise or third-party applications to enforce MFA, where supported. Enforcing MFA through a directory service or SSO provider is a satisfactory implementation of this Safeguard.

Mappings

Capability ID Capability Description Mapping Type ATT&CK ID ATT&CK Name Notes
CIS-6.3 Require MFA for Externally-Exposed Applications mitigates T1114.002 Remote Email Collection
Comments
Enabling multi-factor authentication for public-facing webmail servers helps minimize the usefulness of email usernames and passwords collected by adversaries.
References
CIS-6.3 Require MFA for Externally-Exposed Applications mitigates T1114 Email Collection
Comments
Enabling multi-factor authentication for public-facing webmail servers helps minimize the usefulness of email usernames and passwords collected by adversaries.
References
CIS-6.3 Require MFA for Externally-Exposed Applications mitigates T1110.003 Password Spraying
Comments
Enabling multi-factor authentication can prevent adversaries from gaining access through brute force password spraying attacks against authentication interfaces on externally facing services.
References
CIS-6.3 Require MFA for Externally-Exposed Applications mitigates T1110.002 Password Cracking
Comments
Enabling multi-factor authentication can prevent adversaries from gaining access through brute force password cracking attacks against authentication interfaces on externally facing services.
References
CIS-6.3 Require MFA for Externally-Exposed Applications mitigates T1110.001 Password Guessing
Comments
Enabling multi-factor authentication can prevent adversaries from gaining access through brute force password guessing attacks against authentication interfaces on externally facing services.
References
CIS-6.3 Require MFA for Externally-Exposed Applications mitigates T1110 Brute Force
Comments
Enabling multi-factor authentication can prevent adversaries from gaining access through brute force attacks against authentication interfaces on externally facing services.
References
CIS-6.3 Require MFA for Externally-Exposed Applications mitigates T1110.004 Credential Stuffing
Comments
Enabling multi-factor authentication can prevent adversaries from gaining access through brute force credential stuffing attacks against authentication interfaces on externally facing services.
References