CIS Controls Service Provider Management Capability Group

Develop a process to evaluate service providers who hold sensitive data, or are responsible for an enterprise’s critical IT platforms or processes, to ensure these providers are protecting those platforms and data appropriately.

All Mappings

Capability ID Capability Description Mapping Type ATT&CK ID ATT&CK Name Notes
CIS-15.7 Securely Decommission Service Providers mitigates T1072 Software Deployment Tools
Comments
Securely decommissioning service providers with service accounts or other access to software deployment, endpoint management, or configuration management platforms prevents residual provider access from being abused through these centralized software suites.
References
    CIS-15.7 Securely Decommission Service Providers mitigates T1199 Trusted Relationship
    Comments
    Remove accounts and permissions used by parties in trusted relationships to minimize potential abuse by the party and if the party is compromised by an adversary.
    References
      CIS-15.7 Securely Decommission Service Providers mitigates T1078 Valid Accounts
      Comments
      Disabling provider user and service accounts and revoking associated credentials, tokens, and access permissions prevents residual provider identities from being abused by adversaries to access enterprise resources.
      References

        Capabilities

        Capability ID Capability Name Number of Mappings
        CIS-15.7 Securely Decommission Service Providers 3