CIS Controls Data Recovery Capability Group

Establish and maintain data recovery practices sufficient to restore in-scope enterprise assets to a pre-incident and trusted state.

All Mappings

Capability ID Capability Description Mapping Type ATT&CK ID ATT&CK Name Notes
CIS-11.3 Protect Recovery Data mitigates T1530 Data from Cloud Storage
Comments
Adversaries collect data directly from improperly secured or compromised cloud storage. When backup or recovery data is stored in cloud object storage, this safeguard requires that recovery data be protected with controls such as encryption and separation, directly reducing unauthorized access to those backup objects
References
CIS-11.3 Protect Recovery Data mitigates T1003.003 NTDS
Comments
Adversaries may obtain NTDS.dit from Domain Controller backups rather than directly from a live Domain Controller and extract credential material from the database. This safeguard requires recovery data to receive equivalent protections, including encryption or separation, which directly restricts unauthorized access to Domain Controller backup copies containing NTDS data
References
CIS-11.2 Perform Automated Backups mitigates T1490 Inhibit System Recovery
Comments
Adversaries inhibit recovery by deleting or disabling backups, snapshots, recovery catalogs, and related recovery mechanisms. This safeguard requires automated, recurring backups of in-scope enterprise assets, ensuring that recoverable copies are created on a regular basis and thereby reducing the effectiveness of attempts to eliminate available recovery data.
References
CIS-11.4 Establish and Maintain an Isolated Instance of Recovery Data mitigates T1561.002 Disk Structure Wipe
Comments
Disk structure wiping damages partitions, filesystems, or boot structures required to access a system. Recovery data stored on an isolated repository remains unaffected by those disk-level changes and can be used to rebuild the system.
References
CIS-11.4 Establish and Maintain an Isolated Instance of Recovery Data mitigates T1561.001 Disk Content Wipe
Comments
Disk content wiping destroys data on the affected storage device. An isolated recovery repository is not dependent on that disk and preserves the data needed to restore the wiped system.
References
CIS-11.4 Establish and Maintain an Isolated Instance of Recovery Data mitigates T1561 Disk Wipe
Comments
Adversaries erase disk data or structures to make systems unusable. Offline, cloud-separated, or off-site recovery copies remain outside the disk-wipe operation, directly preserving data required for restoration.
References
CIS-11.4 Establish and Maintain an Isolated Instance of Recovery Data mitigates T1491.002 External Defacement
Comments
External defacement modifies public-facing web or application content. Where an isolated recovery instance contains the affected content and configuration, known-good copies can be restored and the attacker-controlled state removed.
References
CIS-11.4 Establish and Maintain an Isolated Instance of Recovery Data mitigates T1491.001 Internal Defacement
Comments
Internal defacement changes internal application or web content visible to users. Where an isolated recovery instance preserves known-good versions of that content, the altered files or configuration can be replaced with trusted copies.
References
CIS-11.4 Establish and Maintain an Isolated Instance of Recovery Data mitigates T1491 Defacement
Comments
Adversaries alter operational or visible data to damage integrity. An isolated recovery copy preserves the trusted pre-defacement state, directly enabling restoration.
References
CIS-11.4 Establish and Maintain an Isolated Instance of Recovery Data mitigates T1490 Inhibit System Recovery
Comments
Recovery inhibition relies on eliminating backups, snapshots, or other recovery resources available to the victim. An isolated recovery instance remains outside the compromised recovery path, preventing the attacker from removing every usable recovery copy through the same access.
References
CIS-11.4 Establish and Maintain an Isolated Instance of Recovery Data mitigates T1486 Data Encrypted for Impact
Comments
Encryption for impact depends on the attacker being able to reach and modify usable data. An isolated recovery copy that is inaccessible through the compromised production path remains unencrypted and available for restoration.
References
CIS-11.4 Establish and Maintain an Isolated Instance of Recovery Data mitigates T1485.001 Lifecycle-Triggered Deletion
Comments
Lifecycle-triggered deletion relies on cloud policies automatically removing stored objects. Where the isolated recovery copy resides in a separate account, vault, or lifecycle boundary, those deletion rules do not affect the recovery copy.
References
CIS-11.4 Establish and Maintain an Isolated Instance of Recovery Data mitigates T1485 Data Destruction
Comments
Data destruction removes or overwrites production data to make it unrecoverable. An isolated recovery copy sits outside the same destructive access path, preserving data that can be restored after production copies are destroyed.
References
CIS-11.4 Establish and Maintain an Isolated Instance of Recovery Data mitigates T1565.001 Stored Data Manipulation
Comments
Stored data manipulation relies on altered data remaining authoritative or being used by downstream systems. Where the isolated recovery environment retains versioned or known-good data from before the manipulation, the modified production copy can be replaced with a trusted version.
References
CIS-11.4 Establish and Maintain an Isolated Instance of Recovery Data mitigates T1565 Data Manipulation
Comments
Adversaries manipulate data to affect operations or hide activity. An isolated recovery copy remains outside the compromised production write path, preserving a trusted version that can replace manipulated data.
References
CIS-11.3 Protect Recovery Data mitigates T1561.002 Disk Structure Wipe
Comments
Adversaries destroy file-system or partition structures to make data inaccessible. Recovery copies protected independently from the affected storage remain usable, directly enabling restoration despite destruction of the disk structure.
References
CIS-11.3 Protect Recovery Data mitigates T1561.001 Disk Content Wipe
Comments
Adversaries overwrite disk contents to eliminate stored information. Protected recovery copies remain unavailable to the local wiping operation, directly preserving recoverable versions of the destroyed data.
References
CIS-11.3 Protect Recovery Data mitigates T1561 Disk Wipe
Comments
Adversaries wipe disks to destroy data or render systems unusable. Recovery data protected on separate storage remains outside the affected disk's destructive operation, directly preserving the data required to rebuild the system.
References
CIS-11.3 Protect Recovery Data mitigates T1491.002 External Defacement
Comments
Adversaries modify externally visible content. Protected recovery copies preserve the legitimate content and enable replacement of the defaced version, directly reducing the duration and effectiveness of the attack
References
CIS-11.3 Protect Recovery Data mitigates T1491.001 Internal Defacement
Comments
Adversaries alter internally used content or systems. Protected backup copies maintain a trusted version outside the attacker's ordinary modification path, directly enabling restoration of internally defaced data
References
CIS-11.3 Protect Recovery Data mitigates T1491 Defacement
Comments
Adversaries alter content to disrupt operations or damage integrity. Protected recovery copies preserve trusted versions that remain available for restoration, directly limiting the persistence of the defacement.
References
CIS-11.3 Protect Recovery Data mitigates T1486 Data Encrypted for Impact
Comments
Encryption for impact depends on write access to the data the attacker wants to render unusable. Where recovery repositories are immutable, write-protected, or administered through separate credentials, ransomware cannot encrypt or overwrite the protected recovery copy.
References
CIS-11.3 Protect Recovery Data mitigates T1485.001 Lifecycle-Triggered Deletion
Comments
Adversaries manipulate cloud lifecycle policies or similar automation to cause stored data to be deleted. Immutable/versioned recovery storage and restricted lifecycle-policy modification preserve prior backup objects, directly preventing automated deletion from eliminating the recovery copy.
References
CIS-11.3 Protect Recovery Data mitigates T1485 Data Destruction
Comments
Data destruction depends on the attacker being able to delete or overwrite stored data. Where recovery data is held on immutable storage, deletion-protected repositories, or tightly restricted backup systems, those controls can prevent destruction of the protected copy.
References
CIS-11.3 Protect Recovery Data mitigates T1565.001 Stored Data Manipulation
Comments
Stored data manipulation changes data at rest so the altered state is trusted or used operationally. Where recovery repositories enforce immutability, integrity validation, or write restrictions, unauthorized changes to the recovery copy can be blocked or detected.
References
CIS-11.3 Protect Recovery Data mitigates T1565 Data Manipulation
Comments
Adversaries alter enterprise data to affect operations or hide activity. Integrity controls, access restrictions, and protected recovery copies preserve trusted versions that cannot be modified through ordinary production access, directly reducing the lasting effect of manipulation.
References
CIS-11.3 Protect Recovery Data mitigates T1490 Inhibit System Recovery
Comments
Recovery inhibition commonly relies on deleting, modifying, or disabling backup and recovery resources. Where recovery data is protected with immutability, write restrictions, separate credentials, or access isolation, those controls can prevent the compromised access path from removing or altering the recovery copy.
References
CIS-11.2 Perform Automated Backups mitigates T1565.001 Stored Data Manipulation
Comments
Adversaries alter data stored in files, databases, or other repositories. Automated backups preserve historical versions of the stored data, directly enabling recovery of the unmodified state.
References
CIS-11.2 Perform Automated Backups mitigates T1565 Data Manipulation
Comments
Adversaries alter data to affect decisions, processes, or system outcomes. Automated backups preserve earlier trusted versions of that data, directly enabling defenders to replace manipulated information with a known-good state.
References
CIS-11.2 Perform Automated Backups mitigates T1491.002 External Defacement
Comments
External defacement changes public-facing website or application content. Where the affected content and configuration are included in automated backups, known-good versions can be restored and the defaced state can be removed.
References
CIS-11.2 Perform Automated Backups mitigates T1491.001 Internal Defacement
Comments
Internal defacement modifies organizational web, application, or other internal content. Where that content is included in automated backups, known-good versions can replace the altered resources and shorten the duration of the defacement.
References
CIS-11.2 Perform Automated Backups mitigates T1491 Defacement
Comments
Automated backups preserve trusted versions of the modified data or content, directly enabling restoration of the pre-defacement state.
References
CIS-11.2 Perform Automated Backups mitigates T1485.001 Lifecycle-Triggered Deletion
Comments
Lifecycle-triggered deletion relies on cloud retention or lifecycle rules deleting stored objects. Where automated backups retain the same data outside the affected lifecycle policy or account, those copies survive the deletion and can be restored.
References
CIS-11.2 Perform Automated Backups mitigates T1561.002 Disk Structure Wipe
Comments
Disk structure wiping corrupts partitions, filesystems, or other structures needed to access stored data. Automated backups preserve recoverable copies independent of the damaged disk structure, directly supporting restoration.
References
CIS-11.2 Perform Automated Backups mitigates T1561.001 Disk Content Wipe
Comments
Disk content wiping destroys the data stored on an affected device. Automated backups preserve prior copies of the overwritten data, directly enabling restoration.
References
    CIS-11.2 Perform Automated Backups mitigates T1561 Disk Wipe
    Comments
    Adversaries erase disk data or structures to render systems unusable. Automated backups preserve data outside the destroyed disk state, directly enabling restoration after the wipe.
    References
    CIS-11.2 Perform Automated Backups mitigates T1486 Data Encrypted for Impact
    Comments
    Ransomware and similar impact activity encrypt accessible production data to deny legitimate use. Automated backups preserve recoverable copies from before encryption, directly reducing the attacker's ability to make the encrypted data permanently unavailable.
    References
      CIS-11.2 Perform Automated Backups mitigates T1485 Data Destruction
      Comments
      Adversaries destroy data to impair operations or deny access to information. Automated backups preserve earlier copies of the affected data, directly enabling restoration and reducing the operational effectiveness of the destruction.
      References

      Capabilities

      Capability ID Capability Name Number of Mappings
      CIS-11.2 Perform Automated Backups 12
      CIS-11.3 Protect Recovery Data 14
      CIS-11.4 Establish and Maintain an Isolated Instance of Recovery Data 12