Develop a process to evaluate service providers who hold sensitive data, or are responsible for an enterprise’s critical IT platforms or processes, to ensure these providers are protecting those platforms and data appropriately.
| Capability ID | Capability Description | Mapping Type | ATT&CK ID | ATT&CK Name | Notes |
|---|---|---|---|---|---|
| CIS-15.7 | Securely Decommission Service Providers | mitigates | T1072 | Software Deployment Tools |
Comments
Securely decommissioning service providers with service accounts or other access to software deployment, endpoint management, or configuration management platforms prevents residual provider access from being abused through these centralized software suites.
References
|
| CIS-15.7 | Securely Decommission Service Providers | mitigates | T1199 | Trusted Relationship |
Comments
Remove accounts and permissions used by parties in trusted relationships to minimize potential abuse by the party and if the party is compromised by an adversary.
References
|
| CIS-15.7 | Securely Decommission Service Providers | mitigates | T1078 | Valid Accounts |
Comments
Disabling provider user and service accounts and revoking associated credentials, tokens, and access permissions prevents residual provider identities from being abused by adversaries to access enterprise resources.
References
|
| Capability ID | Capability Name | Number of Mappings |
|---|---|---|
| CIS-15.7 | Securely Decommission Service Providers | 3 |