CIS Controls CIS-9.1

Ensure only fully supported browsers and email clients are allowed to execute in the enterprise, only using the latest version of browsers and email clients provided through the vendor.

Mappings

Capability ID Capability Description Mapping Type ATT&CK ID ATT&CK Name Notes
CIS-9.1 Ensure Use of Only Fully Supported Browsers and Email Clients mitigates T1212 Exploitation for Credential Access
Comments
Browsers and email clients are common targets for vulnerabilities. Requiring the latest vendor-supported versions directly reduces exposure to known client-software vulnerabilities.
References
    CIS-9.1 Ensure Use of Only Fully Supported Browsers and Email Clients mitigates T1068 Exploitation for Privilege Escalation
    Comments
    Browsers and email clients are common targets for vulnerabilities. Requiring the latest vendor-supported versions directly reduces exposure to known client-software vulnerabilities.
    References
      CIS-9.1 Ensure Use of Only Fully Supported Browsers and Email Clients mitigates T1211 Exploitation for Stealth
      Comments
      Browsers and email clients are common targets for vulnerabilities. Requiring the latest vendor-supported versions directly reduces exposure to known client-software vulnerabilities.
      References
        CIS-9.1 Ensure Use of Only Fully Supported Browsers and Email Clients mitigates T1189 Drive-by Compromise
        Comments
        Fully supported, current browsers contain vendor patches and modern security features that reduce successful exploitation when users visit compromised or malicious websites.
        References
          CIS-9.1 Ensure Use of Only Fully Supported Browsers and Email Clients mitigates T1203 Exploitation for Client Execution
          Comments
          Browsers and email clients are common targets for vulnerabilities that provide adversary code execution. Requiring the latest vendor-supported versions directly reduces exposure to known client-software vulnerabilities.
          References
            CIS-9.1 Ensure Use of Only Fully Supported Browsers and Email Clients mitigates T1137.003 Outlook Forms
            Comments
            Current Outlook versions include vendor changes that restrict or warn about custom Outlook forms that may otherwise be abused for persistence and execution. The safeguard ensures those security updates are present.
            References
              CIS-9.1 Ensure Use of Only Fully Supported Browsers and Email Clients mitigates T1137.004 Outlook Home Page
              Comments
              Microsoft updates removed or restricted the legacy Outlook Home Page functionality used for persistence. Preventing obsolete Outlook versions from executing directly prevents continued access to older vulnerable implementations.
              References
                CIS-9.1 Ensure Use of Only Fully Supported Browsers and Email Clients mitigates T1137.005 Outlook Rules
                Comments
                Vendor patches address Outlook mechanisms that adversaries may use to establish rule-triggered persistence or execution. Requiring current supported Outlook versions ensures the relevant security changes are applied.
                References
                  CIS-9.1 Ensure Use of Only Fully Supported Browsers and Email Clients mitigates T1689 Downgrade Attack
                  Comments
                  Allowing only the latest supported browser and email-client versions prevents adversaries or users from running obsolete versions that lack current protections. This directly reduces downgrade opportunities involving older, weaker software versions.
                  References
                    CIS-9.1 Ensure Use of Only Fully Supported Browsers and Email Clients mitigates T1137 Office Application Startup
                    Comments
                    This is a partial mapping because several sub-techniques specifically abuse Outlook features addressed by vendor patches. Other Office startup methods involving templates, test keys, and general add-ins are outside the browser-and-email-client scope.
                    References
                      CIS-9.1 Ensure Use of Only Fully Supported Browsers and Email Clients mitigates T1176.001 Browser Extensions
                      Comments
                      Current browsers incorporate newer extension permission models, security controls, and protections against outdated installation methods. This does not prevent users or adversaries from installing an otherwise permitted malicious extension.
                      References
                        CIS-9.1 Ensure Use of Only Fully Supported Browsers and Email Clients mitigates T1539 Steal Web Session Cookie
                        Comments
                        Updating browsers reduces the likelihood that known vulnerabilities can be exploited to extract cookies from browser storage or memory. It does not prevent malware with sufficient local access from directly reading cookies or browser data.
                        References
                          CIS-9.1 Ensure Use of Only Fully Supported Browsers and Email Clients mitigates T1555.003 Credentials from Web Browsers
                          Comments
                          Current browser versions reduce exploitation of known weaknesses that expose stored passwords and authentication data. Updating the browser does not prevent credential theft by malware already executing with access to the user's browser profile.
                          References
                            CIS-9.1 Ensure Use of Only Fully Supported Browsers and Email Clients mitigates T1176 Software Extensions
                            Comments
                            Keeping browsers current affects browser extensions.
                            References