CIS Controls CIS-6.8

Define and maintain role-based access control, through determining and documenting the access rights necessary for each role within the enterprise to successfully carry out its assigned duties. Perform access control reviews of enterprise assets to validate that all privileges are authorized, on a recurring schedule at a minimum annually, or more frequently.

Mappings

Capability ID Capability Description Mapping Type ATT&CK ID ATT&CK Name Notes
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1003.006 DCSync
Comments
Role-based access control (RBAC) can restrict Active Directory replication permissions, including Replicating Directory Changes rights, to authorized administrative roles. Enforcing these permissions limits which identities can perform the directory replication operations required for DCSync.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1021.002 SMB/Windows Admin Shares
Comments
Role-based access control (RBAC) can restrict local administrator membership and administrative-share access to authorized roles. These enforced permissions limit the accounts that can use SMB and Windows administrative shares for remote administration and lateral movement.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1021.006 Windows Remote Management
Comments
Role-based access control (RBAC) can restrict WinRM accounts and permissions to authorized administrative roles. Enforced WinRM permissions limit which identities can use the service for remote execution and lateral movement.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1218.007 Msiexec
Comments
Role-based access control (RBAC) can restrict execution of Msiexec.exe to privileged accounts or groups with an authorized operational need. Enforcing this entitlement reduces opportunities for adversaries to abuse Windows Installer for proxy execution.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1525 Implant Internal Image
Comments
Role-based access control (RBAC) can limit permissions to create, modify, or publish platform and container images to authorized roles. Enforcing these permissions reduces an adversary's ability to implant malicious images within enterprise repositories.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1538 Cloud Service Dashboard
Comments
Role-based access control (RBAC) can enforce least-privilege dashboard visibility so users can access only the cloud resources required for their assigned roles. This limits the information and resources exposed through a cloud service dashboard when an account is compromised.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1548.002 Bypass User Account Control
Comments
Role-based access control (RBAC) can restrict local administrator membership to authorized roles. Removing unnecessary administrative rights reduces the accounts from which adversaries can leverage UAC bypass techniques to obtain elevated privileges.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1548.003 Sudo and Sudo Caching
Comments
Role-based access control (RBAC) can enforce which users or groups are authorized for sudo privileges and which elevated commands they may run. Restricting these entitlements limits the identities and operations available for privilege elevation through sudo.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1556.004 Network Device Authentication
Comments
Role-based access control (RBAC) can restrict network-device administrator privileges to narrowly scoped authorized roles. Enforcing least-privilege administrative access reduces the identities capable of modifying network-device authentication mechanisms.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1550.003 Pass the Ticket
Comments
Using role-based access control (RBAC) to prevent domain users from being local administrators on multiple systems can help limit adversaries’ ability to reuse Kerberos tickets for lateral movement.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1550.002 Pass the Hash
Comments
Using role-based access control (RBAC) to prevent domain users from being local administrators on multiple systems can help limit adversaries’ ability to reuse NTLM hashes for lateral movement.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1550 Use Alternate Authentication Material
Comments
Using role-based access control (RBAC) to enforce least privilege and prevent domain users from holding local-administrator rights across multiple systems can help limit an adversary’s ability to use alternate authentication material for lateral movement.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1552.007 Container API
Comments
Enforce authentication and role-based access control (RBAC) on the container API to restrict users to the least privileges required to help prevent adversaries from gathering credentials via APIs within a containers environment.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1537 Transfer Data to Cloud Account
Comments
Using role-based access control (RBAC) to limit user-account and identity access management (IAM) permissions to the least privileges required can help prevent adversaries from transferring organizational data to cloud accounts they control.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1199 Trusted Relationship
Comments
Implement role-based access control (RBAC) to manage accounts and permissions used by parties in trusted relationships to minimize potential abuse by the party or if the party is compromised by an adversary.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1569.003 Systemctl
Comments
Implement role-based access control (RBAC) to ensure lower-privileged users cannot create or interact with higher-privileged system services to help prevent adversaries from abusing systemctl to execute commands or programs.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1569.001 Launchctl
Comments
Implement role-based access control (RBAC) to ensure lower-privileged users cannot create or interact with higher-privileged system services to help prevent adversaries from abusing launchctl to execute commands or programs.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1047 Windows Management Instrumentation
Comments
Using role-based access control (RBAC) to restrict remote WMI access to authorized administrative roles can help prevent adversaries from abusing Windows Management Instrumentation (WMI) to execute malicious commands and payloads.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1195 Supply Chain Compromise
Comments
Implement role-based access control (RBAC) to ensure software and development tools run with the lowest necessary privileges to help limit an adversary’s ability to propagate or perform unauthorized actions in the event of a supply chain compromise.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1528 Steal Application Access Token
Comments
Enforce role-based access control (RBAC) to limit accounts to the least privileges they require to help prevent adversaries from obtaining or abusing application access tokens.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1489 Service Stop
Comments
Using role-based access control (RBAC) to limit user accounts and groups so that only authorized administrators can interact with service changes and service configurations can help prevent adversaries from stopping or disabling services.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1648 Serverless Execution
Comments
Using role-based access control (RBAC) to limit permissions to create, modify, or run serverless resources only to users that explicitly require them can help prevent adversaries from abusing serverless computing, integration, and automation services to execute arbitrary code in cloud environments.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1505.003 Web Shell
Comments
Using role-based access control (RBAC) to limit permissions to upload, create, or modify content in web-server application directories to users with a legitimate need can help prevent adversaries from backdooring web servers with web shells.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1505 Server Software Component
Comments
Using role-based access control (RBAC) to limit permissions to add or modify server software components to users with a legitimate need can help prevent adversaries from abusing legitimate extensible development features of servers.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1021.001 Remote Desktop Protocol
Comments
Using role-based access control (RBAC) to limit Remote Desktop Users group membership and Remote Desktop Protocol (RDP) permissions to users with a legitimate need can help prevent adversaries from using RDP for lateral movement.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1053.006 Systemd Timers
Comments
Using role-based access control (RBAC) to limit permissions to create or modify scheduled tasks via system utilities to authorized administrator roles to help prevent adversaries from abusing task scheduling functionality.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1053.003 Cron
Comments
Using role-based access control (RBAC) to limit permissions to create or modify scheduled tasks via the cron utility to authorized administrator roles to help prevent adversaries from abusing task scheduling functionality.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1053 Scheduled Task/Job
Comments
Using role-based access control (RBAC) to limit permissions to create or modify scheduled tasks and jobs on remote systems to authorized administrator roles to help prevent adversaries from abusing task scheduling functionality.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1053.002 At
Comments
Using role-based access control (RBAC) to limit permissions to create or modify scheduled tasks via the at utility to authorized administrator roles to help prevent adversaries from abusing task scheduling functionality.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1053.005 Scheduled Task
Comments
Using role-based access control (RBAC) to limit permissions to create or modify scheduled tasks on remote systems to authorized administrator roles to help prevent adversaries from abusing task scheduling functionality.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1021.004 SSH
Comments
Using role-based access control (RBAC) to limit SSH access and permitted commands to users with a legitimate need can help prevent adversaries from using SSH for lateral movement.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1053.007 Container Orchestration Job
Comments
Using role-based access control (RBAC) to limit permissions to create or modify scheduled tasks via container orchestration tools to authorized administrator roles to help prevent adversaries from abusing task scheduling functionality.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1072 Software Deployment Tools
Comments
Using role-based access control (RBAC) to limit access to and use of centralized software suites to a limited number of authorized administrators with a verified business need can help prevent adversaries from accessing and abusing software deployment tools.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1021 Remote Services
Comments
Using role-based access control (RBAC) to limit which accounts can use remote services and restrict the commands or resources available to those accounts to help prevent adversaries from using remote services for lateral movement.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1563.001 SSH Hijacking
Comments
Using role-based access control (RBAC) to limit remote user permissions to necessary users to help prevent adversaries from commandeering these sessions.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1563.002 RDP Hijacking
Comments
Using role-based access control (RBAC) to limit remote user permissions to necessary users to help prevent adversaries from commandeering these sessions.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1563 Remote Service Session Hijacking
Comments
Using role-based access control (RBAC) to limit remote user permissions to necessary users to help prevent adversaries from commandeering these sessions.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1677 Poisoned Pipeline Execution
Comments
Using role-based access control (RBAC) to limit write access to internal repositories and CI/CD pipeline permissions to users and services with a legitimate need can help prevent adversaries from modifying pipelines to execute malicious code.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1566.003 Spearphishing via Service
Comments
Using role-based access control (RBAC) to limit third-party messaging and collaboration-service account privileges to users with a legitimate need can help prevent adversaries from abusing compromised service accounts for spearphishing.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1566.002 Spearphishing Link
Comments
Using role-based access control (RBAC) to apply limitations on which roles can grant consent to third-party applications can help prevent users from granting consent to unfamiliar or unverified third-party applications through spearphishing links.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1566.001 Spearphishing Attachment
Comments
Using role-based access control (RBAC) to limit file-opening and execution permissions to only the accounts that require them can help reduce the impact of malicious email attachments by preventing unauthorized execution or spread of malware.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1040 Network Sniffing
Comments
In cloud environments, using role-based access control (RBAC) to ensure that users are not granted permissions to create or modify traffic mirrors unless explicitly required can help prevent adversaries from capturing network traffic.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1666 Modify Cloud Resource Hierarchy
Comments
Using role-based access control (RBAC) to limit permissions to add, delete, or modify cloud resource groups and hierarchy structures to authorized roles can help prevent adversaries from evading organizational guardrails and cloud security policies.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1578.005 Modify Cloud Compute Configurations
Comments
Using role-based access control (RBAC) to limit permissions to modify cloud compute settings, quotas, and tenant-level configurations to authorized roles can help prevent adversaries from altering infrastructure resources or bypassing restrictions.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1578.003 Delete Cloud Instance
Comments
Using role-based access control (RBAC) to limit permissions to delete cloud instances to authorized roles can help prevent adversaries from removing instances to destroy evidence of malicious activity.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1578.002 Create Cloud Instance
Comments
Using role-based access control (RBAC) to limit permissions to create cloud instances to authorized roles can help prevent adversaries from deploying new instances to evade defenses or conduct unauthorized activity.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1578.001 Create Snapshot
Comments
Using role-based access control (RBAC) to limit permissions to create cloud snapshots and backups to authorized roles can help prevent adversaries from creating copies of cloud resources for unauthorized access or data collection.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1578 Modify Cloud Compute Infrastructure
Comments
Using role-based access control (RBAC) to limit permissions to create, delete, and modify cloud compute infrastructure to authorized roles can help prevent adversaries from altering cloud resources to evade defenses or gain unauthorized access.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1021.008 Direct Cloud VM Connections
Comments
Using role-based access control (RBAC) to limit direct cloud-native VM connection permissions to users with a legitimate need can help prevent adversaries from accessing cloud compute infrastructure for lateral movement.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1556.006 Multi-Factor Authentication
Comments
Using role-based access control (RBAC) to limit permissions to enroll, disable, or modify multi-factor authentication (MFA) methods and policies to authorized administrative roles can help prevent adversaries from weakening MFA protections on compromised accounts.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1556 Modify Authentication Process
Comments
Using role-based access control (RBAC) to limit permissions to modify authentication processes and identity-provider settings to authorized administrative roles can help prevent adversaries from altering authentication controls to gain unauthorized access.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1654 Log Enumeration
Comments
Using role-based access control (RBAC) to limit permissions to access and export sensitive system and service logs to privileged roles can help prevent adversaries from enumerating logs for valuable information.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1490 Inhibit System Recovery
Comments
Using role-based access control (RBAC) to limit permissions to backups to only required users with a legitimate need can help prevent adversaries from deleting or removing built-in data and turning off services designed to aid in the recovery of a corrupted system.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1574.012 COR_PROFILER
Comments
Using role-based access control (RBAC) to limit permissions to modify COR_PROFILER environment variables and related .NET configuration settings to users with a legitimate need can help prevent adversaries from loading malicious DLLs into .NET processes.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1574.010 Services File Permissions Weakness
Comments
Using role-based access control (RBAC) to limit permissions to modify service executables and their file paths to users with a legitimate need can help prevent adversaries from replacing service binaries with malicious payloads.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1574.005 Executable Installer File Permissions Weakness
Comments
Using role-based access control (RBAC) to limit permissions to modify installer executables and their file paths to users with a legitimate need can help prevent adversaries from replacing installer binaries with malicious payloads.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1574 Hijack Execution Flow
Comments
Using role-based access control (RBAC) to limit permissions to modify service configurations, registry settings, and protected file paths to users with a legitimate need can help prevent adversaries from hijacking execution flow.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1530 Data from Cloud Storage
Comments
Using role-based access control (RBAC) to limit user groups and roles for access to cloud storage to only users with a legitimate need can help prevent adversaries from accessing and collecting data from cloud storage solutions.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1606 Forge Web Credentials
Comments
Using role-based access control (RBAC) to limit access to identity infrastructure and token-issuance permissions to narrowly scoped privileged roles reduces opportunities to forge credential materials.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1657 Financial Theft
Comments
Using role-based access control (RBAC) to limit sensitive financial transactions and approval privileges to narrowly scoped roles can mitigate use of a compromised account to initiate or authorize unauthorized payments.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1556.009 Conditional Access Policies
Comments
Using role-based access control (RBAC) to limit permissions to modify conditional access policies to authorized administrative roles can help prevent adversaries from removing multi-factor authentication (MFA) requirements or adding exclusions that enable persistent access.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1606.002 SAML Tokens
Comments
Using role-based access control (RBAC) to limit access to identity infrastructure and token-issuance permissions to narrowly scoped privileged roles reduces opportunities to forge SAML tokens.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1048 Exfiltration Over Alternative Protocol
Comments
Using role-based access control (RBAC) to limit user groups and roles for access to cloud storage systems and objects to only users with a legitimate need can help prevent adversaries from exfiltrating data from cloud storage.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1484.001 Group Policy Modification
Comments
Role-based access control (RBAC) can be used to limit which users and computers can access Group Policy Objects (GPOs), helping to prevent adversaries from modifying GPOs.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1484 Domain or Tenant Policy Modification
Comments
Role-based access control (RBAC) can be used to limit which users and computers can access domain and identity tenant settings, helping to prevent adversaries from modifying their configuration settings.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1610 Deploy Container
Comments
Enforcing role-based access control (RBAC) to limit container dashboard access to only necessary users can prevent adversaries from deploying a container into an environment.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1213.006 Databases
Comments
Using role-based access control (RBAC) to limit database access to only authorized users helps prevent adversaries from leveraging these databases to mine valuable information.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1213.001 Confluence
Comments
Using role-based access control (RBAC) to limit Confluence repository access to only authorized users helps prevent adversaries from leveraging these repositories to mine valuable information.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1484.002 Trust Modification
Comments
In cloud environments, role-based access control (RBAC) can be used to limit permissions to create new identity providers to only those accounts that require them. This can prevent adversaries from adding new domain trusts, modifying the properties of existing domain trusts, or otherwise changing the configuration of trust relationships between domains and tenants.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1213.004 Customer Relationship Management Software
Comments
Using role-based access control (RBAC) to limit Customer Relationship Management (CRM) software access to only authorized users helps prevent adversaries from leveraging CRM software to mine valuable information.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1213.003 Code Repositories
Comments
Using role-based access control (RBAC) to limit code repository access to only authorized users helps prevent adversaries from leveraging these repositories to mine valuable information.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1213 Data from Information Repositories
Comments
Using role-based access control (RBAC) to limit information repository access to only authorized users helps prevent adversaries from leveraging these repositories to mine valuable information.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1543 Create or Modify System Process
Comments
Using role-based access control (RBAC) to ensure only authorized administrator roles can interact with system-level process changes and service configurations helps prevent adversaries from leveraging this functionality to establish persistence or escalate privileges.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1485.001 Lifecycle-Triggered Deletion
Comments
In cloud environments, using role-based access control (RBAC) to limit user permissions to modify cloud bucket lifecycle policies to only users with a legitimate need can help prevent adversaries from destroying all objects stored within buckets.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1485 Data Destruction
Comments
In cloud environments, using role-based access control (RBAC) to limit user permissions to modify cloud bucket lifecycle policies to only users with a legitimate need can help prevent adversaries from destroying data and files.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1543.005 Container Service
Comments
Using role-based access control (RBAC) to limit user access to utilities such as docker to only users with a legitimate need helps prevent adversaries from creating or modifying container or cluster management tools to establish persistence or escalate privileges.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1543.004 Launch Daemon
Comments
Using role-based access control (RBAC) to ensure only authorized administrator roles can create new Launch Daemons helps prevent adversaries from creating or modifying Launch Daemons to establish persistence or escalate privileges.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1543.003 Windows Service
Comments
Using role-based access control (RBAC) to ensure only authorized administrator roles can interact with service changes and service configurations helps prevent adversaries from leveraging this functionality to establish persistence or escalate privileges.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1543.002 Systemd Service
Comments
Using role-based access control (RBAC) to limit user access to system utilities to only users with a legitimate need helps prevent adversaries from creating or modifying systemd services to establish persistence or escalate privileges.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1213.002 Sharepoint
Comments
Using role-based access control (RBAC) to limit SharePoint repository access to only authorized users helps prevent adversaries from leveraging these repositories to mine valuable information.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1134.002 Create Process with Token
Comments
Role-based access control (RBAC) can help mitigate access token manipulation by restricting which roles are allowed to create new processes with tokens and limiting privileges to a small set of tightly controlled roles.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1609 Container Administration Command
Comments
Enforcing authentication and role-based access control (RBAC) on the container administration service to restrict users to the least privileges required can help prevent adversaries from abusing the service to execute commands within the container.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1059.008 Network Device CLI
Comments
Role-based access control (RBAC) helps mitigate this technique by enforcing least privilege and command authorization on network device CLI access, limiting which roles can run perform authorization changes.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1619 Cloud Storage Object Discovery
Comments
Role-based access control (RBAC) can help mitigate discovery of cloud storage objects by limiting cloud storage list permissions to narrowly scoped roles, reducing who can enumerate storage objects for discovery.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1580 Cloud Infrastructure Discovery
Comments
Role-based access control (RBAC) can help mitigate discovery of cloud infrastructure and resources by limiting which roles can access, manage, or query cloud infrastructure metadata and enforcing who can see and do what in cloud service dashboards.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1185 Browser Session Hijacking
Comments
Role-based access control (RBAC) can help mitigate browser session hijacking techniques by enforcing least privilege so that hijacked browser sessions are associated with minimally scoped roles, limiting what an adversary can do with a captured session.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1547.012 Print Processors
Comments
Role-based access control (RBAC) can help mitigate this technique by limiting which roles can load or unload device drivers by disabling SeLoadDriverPrivilege.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1613 Container and Resource Discovery
Comments
Role-based access control (RBAC) can help mitigate this technique by tightly controlling which roles can view or query container APIs and dashboards and restricting discovery of cluster resources to narrowly scoped roles.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1547.009 Shortcut Modification
Comments
Role-based access control (RBAC) can help mitigate this technique by limiting shortcut creation and modification to narrowly scoped roles.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1547.006 Kernel Modules and Extensions
Comments
Role-based access control (RBAC) can help mitigate this technique by limiting which roles can load or configure kernel modules and extensions to tightly controlled admin roles.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1547.004 Winlogon Helper DLL
Comments
Role-based access control (RBAC) can help mitigate this technique by restricting Winlogon configuration changes to a small set of tightly controlled admin roles.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1547.013 XDG Autostart Entries
Comments
Role-based access control (RBAC) can help mitigate this technique by limiting which roles can can create and modify XDG autostart entries to narrowly scoped privileged roles.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1098.004 SSH Authorized Keys
Comments
Role-based access control (RBAC) can help mitigate account manipulation by limiting which roles in cloud environments are allowed to modify SSH authorized_keys files and ensuring that only users who explicitly require the permissions to update instance metadata or configurations can do so.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1197 BITS Jobs
Comments
Role-based access control (RBAC) can help mitigate abuse of BITS jobs by limiting access to the BITS interface to specific user roles or groups.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1098.003 Additional Cloud Roles
Comments
Role-based access control (RBAC) can help mitigate account manipulation by limiting which roles are allowed to create or modify accounts and ensuring that low-privileged users do not have permissions to add permissions to accounts or update IAM policies.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1098.001 Additional Cloud Credentials
Comments
Role-based access control (RBAC) can help mitigate account manipulation by limiting which roles are allowed to create or modify accounts and ensuring that low-privileged users do not have permissions to add access keys to accounts.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1098 Account Manipulation
Comments
Role-based access control (RBAC) can help mitigate account manipulation by limiting which roles are allowed to create or modify accounts and ensuring that low-privileged users do not have permissions to modify accounts or account-related policies.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1087.004 Cloud Account
Comments
Role-based access control (RBAC) can help mitigate account discovery by limiting what each role can see or query.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1087 Account Discovery
Comments
Role-based access control (RBAC) can help mitigate account discovery by limiting what each role can see or query.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1098.006 Additional Container Cluster Roles
Comments
Role-based access control (RBAC) can help mitigate account manipulation by limiting which roles are allowed to add additional roles or permissions and ensuring that low-privileged accounts do not have permissions to add permissions to accounts or to update container cluster roles.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1546.003 Windows Management Instrumentation Event Subscription
Comments
Using role-based access control (RBAC) to restrict or disallow user groups allowed to connect to WMI can help prevent adversaries from maliciously using WMI event subscription capabilities.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1134.001 Token Impersonation/Theft
Comments
Role-based access control (RBAC) can help mitigate access token manipulation by restricting which roles are allowed to create or impersonate tokens and limiting privileges to a small set of tightly controlled roles.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1134 Access Token Manipulation
Comments
Role-based access control (RBAC) can help mitigate access token manipulation by restricting which roles are allowed to create or modify tokens and limiting privileges to a small set of tightly controlled roles.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1548.005 Temporary Elevated Cloud Access
Comments
Role-based access control (RBAC), implemented under least privilege and access enforcement controls, helps mitigate this technique by limiting which identities can use elevation mechanisms and what they can elevate to.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1548 Abuse Elevation Control Mechanism
Comments
Role-based access control (RBAC), implemented under least privilege and access enforcement controls, helps mitigate this technique by limiting which identities can use elevation mechanisms and what they can elevate to.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1134.003 Make and Impersonate Token
Comments
Role-based access control (RBAC) can help mitigate access token manipulation by restricting which roles are allowed to create and impersonate tokens and limiting privileges to a small set of tightly controlled roles.
References