CIS Controls Data Protection Capability Group

Develop processes and technical controls to identify, classify, securely handle, retain, and dispose of data.

All Mappings

Capability ID Capability Description Mapping Type ATT&CK ID ATT&CK Name Notes
CIS-3.11 Encrypt Sensitive Data At Rest mitigates T1565.001 Stored Data Manipulation
Comments
Adversaries modify stored data to affect outcomes or conceal activity. At-rest encryption may hinder offline manipulation where the adversary lacks the decryption key, but it does not prevent modification through an authorized application, database write access, or transparently decrypted storage
References
CIS-3.11 Encrypt Sensitive Data At Rest mitigates T1565 Data Manipulation
Comments
Adversaries insert, delete, or manipulate data to influence outcomes or conceal activity. Encrypting sensitive data at rest can prevent an adversary who lacks the decryption capability from understanding the protected content sufficiently to perform targeted or meaningful modifications, reducing the effectiveness of the manipulation.
References
CIS-3.11 Encrypt Sensitive Data At Rest mitigates T1003 OS Credential Dumping
Comments
Encrypting sensitive data at rest prevents dumping credentials from OS caches, memory, or credential structures to obtain hashes or plaintext passwords on domain controller backups.
References
CIS-3.11 Encrypt Sensitive Data At Rest mitigates T1552.004 Private Keys
Comments
Private keys are frequently stored on disk. Encrypting storage can reduce exposure from theft of key files, especially during offline access or storage compromise.
References
CIS-3.11 Encrypt Sensitive Data At Rest mitigates T1649 Steal or Forge Authentication Certificates
Comments
Certificates and private keys are commonly stored on disk. Encryption at rest can reduce exposure when attackers attempt to steal certificate material from storage.
References
CIS-3.11 Encrypt Sensitive Data At Rest mitigates T1119 Automated Collection
Comments
Adversaries use automated methods to search for and copy data across systems, cloud APIs, pipelines, or RAT functionality. Encryption at rest can mitigate the automated collection of files/storage objects from being usable when the adversary lacks access to the decryption key.
References
CIS-3.11 Encrypt Sensitive Data At Rest mitigates T1003.003 NTDS
Comments
NTDS dumping targets Active Directory credential material. Encryption and secure storage of DC backups can prevent an adversary who obtains an offline backup from directly accessing NTDS credential material.
References
CIS-3.11 Encrypt Sensitive Data At Rest mitigates T1550.001 Application Access Token
Comments
Application access tokens are sensitive credential material commonly stored in databases, configuration stores, browser profiles, caches, or application files. Encrypting those tokens at rest can prevent an adversary who obtains raw storage, a database backup, snapshot, or filesystem access from reading and reusing the tokens.
References
CIS-3.4 Enforce Data Retention mitigates T1070.009 Clear Persistence
Comments
This sub-technique removes scheduled tasks or registry keys after use. Retaining system modification logs according to enterprise timelines ensures the lifecycle of the persistence mechanism remains fully reviewable.
References
CIS-3.4 Enforce Data Retention mitigates T1070.008 Clear Mailbox Data
Comments
This sub-technique permanently purges emails to hide phishing or exfiltration. CIS 3.4 requires a minimum retention window for email archives, blocking adversaries from destroying corporate messaging records.
References
CIS-3.4 Enforce Data Retention mitigates T1070.007 Clear Network Connection History and Configurations
Comments
This sub-technique wipes local network state data and active connection logs. Enforcing retention timelines on network telemetry ensures lateral movement records survive local configuration resets.
References
CIS-3.4 Enforce Data Retention mitigates T1070.003 Clear Command History
Comments
This sub-technique purges terminal histories like .bash_history or PowerShell logs. Data retention policies mandate logging shell commands directly to a central repository, preserving the operational history despite local terminal purges.
References
CIS-3.4 Enforce Data Retention mitigates T1685.005 Clear Windows Event Logs
Comments
This technique targets local Windows security and system event logs. Enforcing a minimum retention timeline ensures Windows event data is moved off-host and preserved, defeating local log-clearing attempts.
References
CIS-3.4 Enforce Data Retention mitigates T1685.006 Clear Linux or Mac System Logs
Comments
This technique deletes critical Unix artifacts like /var/log system logs. Documented retention processes guarantee that Unix system trails are streamed to a repository where minimum storage timelines are strictly enforced.
References
CIS-3.4 Enforce Data Retention mitigates T1070 Indicator Removal
Comments
This overarching technique covers deleting artifacts across an environment. CIS 3.4 protects the evidence chain by establishing mandatory retention periods that an attacker cannot alter or shorten.
References
CIS-3.4 Enforce Data Retention mitigates T1485 Data Destruction
Comments
Retention is protective because it limits the time window in which valuable data remains available for destruction, tampering, or cleanup by an attacker. Data retention policies protect against adversaries deleting logs by mandating strict storage lifecycles, off-site replication, and immutability.
References
CIS-3.11 Encrypt Sensitive Data At Rest mitigates T1552 Unsecured Credentials
Comments
Credentials and authentication material are often stored within files, databases, configuration repositories, and application data stores. Encrypting sensitive data at rest reduces the usefulness of credential artifacts obtained from protected storage locations by preventing direct access to plaintext credential material.
References
    CIS-3.5 Securely Dispose of Data mitigates T1530 Data from Cloud Storage
    Comments
    Secure disposal reduces sensitive data retained in cloud object storage, lowering the value of compromised storage access
    References
    CIS-3.5 Securely Dispose of Data mitigates T1552 Unsecured Credentials
    Comments
    This applies when secure disposal explicitly removes old credential files, keys, exports, secrets, or configuration files that could expose credentials.
    References
    CIS-3.5 Securely Dispose of Data mitigates T1213 Data from Information Repositories
    Comments
    Secure disposal reduces stale sensitive records in repositories such as document stores, collaboration platforms, or knowledge bases.
    References
    CIS-3.5 Securely Dispose of Data mitigates T1039 Data from Network Shared Drive
    Comments
    Secure disposal reduces obsolete or unnecessary sensitive data left on shared drives, limiting what an adversary can collect from network shares.
    References
    CIS-3.5 Securely Dispose of Data mitigates T1005 Data from Local System
    Comments
    Secure disposal reduces residual sensitive files on endpoints and servers that an adversary could later collect from local storage.
    References
    CIS-3.12 Segment Data Processing and Storage Based on Sensitivity mitigates T1530 Data from Cloud Storage
    Comments
    Segregated cloud environments reduce exposure of sensitive cloud storage resources.
    References
    CIS-3.12 Segment Data Processing and Storage Based on Sensitivity mitigates T1021 Remote Services
    Comments
    Segmentation directly limits attacker movement between remote-accessible systems and sensitive environments.
    References
    CIS-3.4 Enforce Data Retention mitigates T1070 Indicator Removal
    Comments
    Data Retention restricts, hardens against, or increases visibility into the adversary behavior.
    References
    CIS-3.4 Enforce Data Retention mitigates T1485 Data Destruction
    Comments
    Retention is protective because it limits the time window in which valuable data remains available for destruction, tampering, or cleanup by an attacker.
    References
    CIS-3.13 Deploy a Data Loss Prevention Solution mitigates T1537 Transfer Data to Cloud Account
    Comments
    DLP is a direct control for blocking or alerting on exfiltration and data staging behaviors. DLP solutions commonly inspect and restrict uploads to external cloud services.
    References
    CIS-3.13 Deploy a Data Loss Prevention Solution mitigates T1048 Exfiltration Over Alternative Protocol
    Comments
    DLP is a direct control for blocking or alerting on exfiltration and data staging behaviors. DLP inspection capabilities may identify sensitive-data transfer across non-standard protocols.
    References
    CIS-3.13 Deploy a Data Loss Prevention Solution mitigates T1567 Exfiltration Over Web Service
    Comments
    DLP is a direct control for blocking or alerting on exfiltration and data staging behaviors. Web upload monitoring and restriction are core DLP use cases.
    References
    CIS-3.13 Deploy a Data Loss Prevention Solution mitigates T1052.001 Exfiltration over USB
    Comments
    DLP is a direct control for blocking or alerting on exfiltration and data staging behaviors. Device-control and removable-media DLP policies directly target USB-based exfiltration.
    References
    CIS-3.13 Deploy a Data Loss Prevention Solution mitigates T1041 Exfiltration Over C2 Channel
    Comments
    DLP is a direct control for blocking or alerting on exfiltration and data staging behaviors. DLP solutions explicitly monitor and restrict unauthorized outbound transfer of sensitive data.
    References
    CIS-3.11 Encrypt Sensitive Data At Rest mitigates T1039 Data from Network Shared Drive
    Comments
    Encryption protects sensitive shared-drive data against unauthorized disclosure
    References
    CIS-3.11 Encrypt Sensitive Data At Rest mitigates T1530 Data from Cloud Storage
    Comments
    Cloud storage encryption directly protects sensitive stored cloud data.
    References
    CIS-3.11 Encrypt Sensitive Data At Rest mitigates T1213 Data from Information Repositories
    Comments
    Repository encryption protects stored sensitive data even after unauthorized access.
    References
    CIS-3.11 Encrypt Sensitive Data At Rest mitigates T1005 Data from Local System
    Comments
    Encryption at rest directly reduces usability of stolen or accessed local data.
    References
    CIS-3.10 Encrypt Sensitive Data in Transit mitigates T1557 Adversary-in-the-Middle
    Comments
    Transport encryption directly constrains interception and manipulation of communications.
    References
    CIS-3.10 Encrypt Sensitive Data in Transit mitigates T1040 Network Sniffing
    Comments
    Encryption in transit directly mitigates readable interception of network traffic.
    References
    CIS-3.9 Encrypt Data on Removable Media mitigates T1052.001 Exfiltration over USB
    Comments
    Encrypting removable media directly reduces the usefulness of data exfiltrated via USB storage devices.
    References
    CIS-3.9 Encrypt Data on Removable Media mitigates T1025 Data from Removable Media
    Comments
    The safeguard explicitly protects removable-media-stored data from unauthorized access.
    References
    CIS-3.6 Encrypt Data on End-User Devices mitigates T1025 Data from Removable Media
    Comments
    Encryption protects copied endpoint data stored on removable media from unauthorized disclosure.
    References
    CIS-3.6 Encrypt Data on End-User Devices mitigates T1005 Data from Local System
    Comments
    Encryption on endpoints reduces the value of locally collected data and raises the bar for simple exfiltration after collection.
    References
    CIS-3.5 Securely Dispose of Data mitigates T1070.004 File Deletion
    Comments
    The safeguard specifically concerns secure deletion and sanitization of residual data artifacts.
    References
    CIS-3.5 Securely Dispose of Data mitigates T1561 Disk Wipe
    Comments
    This control protects against attacker behaviors that destroy or overwrite data and storage media.
    References
    CIS-3.5 Securely Dispose of Data mitigates T1485 Data Destruction
    Comments
    Secure disposal directly addresses preventing unauthorized recovery or persistence of sensitive data remnants.
    References
    CIS-3.3 Configure Data Access Control Lists mitigates T1078 Valid Accounts
    Comments
    ACLs constrain which accounts can reach data and therefore directly reduce abuse of valid accounts and local data access for collection.
    References
    CIS-3.3 Configure Data Access Control Lists mitigates T1005 Data from Local System
    Comments
    The control either restricts, detects, hardens against, or increases visibility into the adversary behavior associated with this technique. The control reduces unauthorized access opportunities and raises the difficulty of account misuse.
    References

    Capabilities

    Capability ID Capability Name Number of Mappings
    CIS-3.13 Deploy a Data Loss Prevention Solution 5
    CIS-3.12 Segment Data Processing and Storage Based on Sensitivity 2
    CIS-3.6 Encrypt Data on End-User Devices 2
    CIS-3.3 Configure Data Access Control Lists 2
    CIS-3.4 Enforce Data Retention 10
    CIS-3.5 Securely Dispose of Data 8
    CIS-3.11 Encrypt Sensitive Data At Rest 13
    CIS-3.10 Encrypt Sensitive Data in Transit 2
    CIS-3.9 Encrypt Data on Removable Media 2