CIS Controls CIS-7.3

Perform operating system updates on enterprise assets through automated patch management on a monthly, or more frequent, basis.

Mappings

Capability ID Capability Description Mapping Type ATT&CK ID ATT&CK Name Notes
CIS-7.3 Perform Automated Operating System Patch Management mitigates T1495 Firmware Corruption
Comments
Applying BIOS, UEFI, device, and component firmware updates can remove vulnerabilities that permit unauthorized firmware modification or corruption. Other protections are still required against adversaries that already possess authorized firmware-update capability.
References
CIS-7.3 Perform Automated Operating System Patch Management mitigates T1542 Pre-OS Boot
Comments
This is a partial parent mapping because remediation of vulnerable BIOS, UEFI, and component firmware can remove known pre-OS exploitation paths. Other pre-OS persistence methods may require boot-integrity, signing, and hardware-root-of-trust controls.
References
CIS-7.3 Perform Automated Operating System Patch Management mitigates T1542.001 System Firmware
Comments
Applying current BIOS and UEFI updates directly remediates known system-firmware vulnerabilities that could enable persistence or execution below the operating system.
References
CIS-7.3 Perform Automated Operating System Patch Management mitigates T1542.002 Component Firmware
Comments
Firmware updates for storage devices, controllers, network adapters, and other components remove known vulnerabilities that could allow malicious component-level persistence or modification.
References
CIS-7.3 Perform Automated Operating System Patch Management mitigates T1176.002 IDE Extensions
Comments
ATT&CK mentions ensuring operating systems and software are using the most current version.
References
    CIS-7.3 Perform Automated Operating System Patch Management mitigates T1176.001 Browser Extensions
    Comments
    ATT&CK mentions ensuring operating systems and software are using the most current version.
    References
      CIS-7.3 Perform Automated Operating System Patch Management mitigates T1176 Software Extensions
      Comments
      ATT&CK mentions ensuring operating systems and software are using the most current version.
      References
        CIS-7.3 Perform Automated Operating System Patch Management mitigates T1072 Software Deployment Tools
        Comments
        ATT&CK mentions having a patch deployment systems regularly to prevent potential remote access through Exploitation for Privilege Escalation.
        References
          CIS-7.3 Perform Automated Operating System Patch Management mitigates T1195.002 Compromise Software Supply Chain
          Comments
          ATT&CK mentions a patch management process should be implemented to check unused dependencies, unmaintained and/or previously vulnerable dependencies, unnecessary features, components, files, and documentation.
          References
            CIS-7.3 Perform Automated Operating System Patch Management mitigates T1195.001 Compromise Software Dependencies and Development Tools
            Comments
            ATT&CK mentions a patch management process should be implemented to check unused dependencies, unmaintained and/or previously vulnerable dependencies, unnecessary features, components, files, and documentation.
            References
              CIS-7.3 Perform Automated Operating System Patch Management mitigates T1195 Supply Chain Compromise
              Comments
              ATT&CK mentions a patch management process should be implemented to check unused dependencies, unmaintained and/or previously vulnerable dependencies, unnecessary features, components, files, and documentation.
              References
                CIS-7.3 Perform Automated Operating System Patch Management mitigates T1546 Event Triggered Execution
                Comments
                OS patches that address specific Windows event-triggered execution mechanisms, particularly Application Shimming.
                References
                  CIS-7.3 Perform Automated Operating System Patch Management mitigates T1552 Unsecured Credentials
                  Comments
                  ATT&CK specifically recommends applying patch KB2962486 which prevents credentials from being stored in GPPs.
                  References
                    CIS-7.3 Perform Automated Operating System Patch Management mitigates T1686.002 Network Device Firewall
                    Comments
                    ATT&CK specifically recommends maintaining network firewalls with current security patches. Include this where network firewall appliances and their operating systems are considered enterprise assets covered by the automated an OS-patching process.
                    References
                      CIS-7.3 Perform Automated Operating System Patch Management mitigates T1548 Abuse Elevation Control Mechanism
                      Comments
                      OS updates can close vulnerabilities and implementation weaknesses used to bypass native elevation mechanisms, especially UAC, but they do not prevent abuse of sudo permissions, temporary cloud elevation, or other correctly functioning mechanisms.
                      References
                        CIS-7.3 Perform Automated Operating System Patch Management mitigates T1211 Exploitation for Stealth
                        Comments
                        OS updates can correct vulnerabilities in kernels, logging components, security tools, and system services that could be exploited to conceal activity. Application-specific exploitation remains outside 7.3.
                        References
                          CIS-7.3 Perform Automated Operating System Patch Management mitigates T1210 Exploitation of Remote Services
                          Comments
                          OS patching directly addresses vulnerabilities in operating-system services such as SMB, RDP, RPC, SSH components, and other built-in remote services. The technique also includes independently installed applications that would fall under application patch management instead.
                          References
                            CIS-7.3 Perform Automated Operating System Patch Management mitigates T1550.002 Pass the Hash
                            Comments
                            ATT&CK identifies Windows 7 and higher system patch KB2871997 as limiting default access available to local administrator accounts, reducing some pass-the-hash lateral movement.
                            References
                              CIS-7.3 Perform Automated Operating System Patch Management mitigates T1552.006 Group Policy Preferences
                              Comments
                              ATT&CK identifies Windows patch KB2962486, which prevents credentials from being stored in Group Policy Preferences. This is a direct OS-patch implementation.
                              References
                                CIS-7.3 Perform Automated Operating System Patch Management mitigates T1546.011 Application Shimming
                                Comments
                                ATT&CK identifies a specific Windows patch, KB3045645, that removes an auto-elevation behavior used to abuse application shims. Automated OS patch deployment directly applies this type of mitigation.
                                References
                                  CIS-7.3 Perform Automated Operating System Patch Management mitigates T1548.002 Bypass User Account Control
                                  Comments
                                  Windows updates include changes that close known UAC-bypass methods and improve elevation protections. ATT&CK directly recommends maintaining the latest Windows version and patch level.
                                  References
                                    CIS-7.3 Perform Automated Operating System Patch Management mitigates T1611 Escape to Host
                                    Comments
                                    Container and VM escapes may exploit vulnerabilities in the host kernel, hypervisor, or operating-system components. ATT&CK explicitly recommends keeping hosts current with security patches.
                                    References
                                      CIS-7.3 Perform Automated Operating System Patch Management mitigates T1068 Exploitation for Privilege Escalation
                                      Comments
                                      OS and kernel vulnerabilities are a primary means of escalating from user privileges to SYSTEM or root. Automated OS patching directly removes known vulnerable code paths. ATT&CK specifically recommends patch management for internal endpoints and servers.
                                      References