Develop processes and technical controls to identify, classify, securely handle, retain, and dispose of data.
| Capability ID | Capability Description | Mapping Type | ATT&CK ID | ATT&CK Name | Notes |
|---|---|---|---|---|---|
| CIS-3.11 | Encrypt Sensitive Data At Rest | mitigates | T1565.001 | Stored Data Manipulation |
Comments
Adversaries modify stored data to affect outcomes or conceal activity. At-rest encryption may hinder offline manipulation where the adversary lacks the decryption key, but it does not prevent modification through an authorized application, database write access, or transparently decrypted storage
References
|
| CIS-3.11 | Encrypt Sensitive Data At Rest | mitigates | T1565 | Data Manipulation |
Comments
Adversaries insert, delete, or manipulate data to influence outcomes or conceal activity. Encrypting sensitive data at rest can prevent an adversary who lacks the decryption capability from understanding the protected content sufficiently to perform targeted or meaningful modifications, reducing the effectiveness of the manipulation.
References
|
| CIS-3.11 | Encrypt Sensitive Data At Rest | mitigates | T1003 | OS Credential Dumping |
Comments
Encrypting sensitive data at rest prevents dumping credentials from OS caches, memory, or credential structures to obtain hashes or plaintext passwords on domain controller backups.
References
|
| CIS-3.11 | Encrypt Sensitive Data At Rest | mitigates | T1552.004 | Private Keys |
Comments
Private keys are frequently stored on disk. Encrypting storage can reduce exposure from theft of key files, especially during offline access or storage compromise.
References
|
| CIS-3.11 | Encrypt Sensitive Data At Rest | mitigates | T1649 | Steal or Forge Authentication Certificates |
Comments
Certificates and private keys are commonly stored on disk. Encryption at rest can reduce exposure when attackers attempt to steal certificate material from storage.
References
|
| CIS-3.11 | Encrypt Sensitive Data At Rest | mitigates | T1119 | Automated Collection |
Comments
Adversaries use automated methods to search for and copy data across systems, cloud APIs, pipelines, or RAT functionality. Encryption at rest can mitigate the automated collection of files/storage objects from being usable when the adversary lacks access to the decryption key.
References
|
| CIS-3.11 | Encrypt Sensitive Data At Rest | mitigates | T1003.003 | NTDS |
Comments
NTDS dumping targets Active Directory credential material. Encryption and secure storage of DC backups can prevent an adversary who obtains an offline backup from directly accessing NTDS credential material.
References
|
| CIS-3.11 | Encrypt Sensitive Data At Rest | mitigates | T1550.001 | Application Access Token |
Comments
Application access tokens are sensitive credential material commonly stored in databases, configuration stores, browser profiles, caches, or application files. Encrypting those tokens at rest can prevent an adversary who obtains raw storage, a database backup, snapshot, or filesystem access from reading and reusing the tokens.
References
|
| CIS-3.4 | Enforce Data Retention | mitigates | T1070.009 | Clear Persistence |
Comments
This sub-technique removes scheduled tasks or registry keys after use. Retaining system modification logs according to enterprise timelines ensures the lifecycle of the persistence mechanism remains fully reviewable.
References
|
| CIS-3.4 | Enforce Data Retention | mitigates | T1070.008 | Clear Mailbox Data |
Comments
This sub-technique permanently purges emails to hide phishing or exfiltration. CIS 3.4 requires a minimum retention window for email archives, blocking adversaries from destroying corporate messaging records.
References
|
| CIS-3.4 | Enforce Data Retention | mitigates | T1070.007 | Clear Network Connection History and Configurations |
Comments
This sub-technique wipes local network state data and active connection logs. Enforcing retention timelines on network telemetry ensures lateral movement records survive local configuration resets.
References
|
| CIS-3.4 | Enforce Data Retention | mitigates | T1070.003 | Clear Command History |
Comments
This sub-technique purges terminal histories like .bash_history or PowerShell logs. Data retention policies mandate logging shell commands directly to a central repository, preserving the operational history despite local terminal purges.
References
|
| CIS-3.4 | Enforce Data Retention | mitigates | T1685.005 | Clear Windows Event Logs |
Comments
This technique targets local Windows security and system event logs. Enforcing a minimum retention timeline ensures Windows event data is moved off-host and preserved, defeating local log-clearing attempts.
References
|
| CIS-3.4 | Enforce Data Retention | mitigates | T1685.006 | Clear Linux or Mac System Logs |
Comments
This technique deletes critical Unix artifacts like /var/log system logs. Documented retention processes guarantee that Unix system trails are streamed to a repository where minimum storage timelines are strictly enforced.
References
|
| CIS-3.4 | Enforce Data Retention | mitigates | T1070 | Indicator Removal |
Comments
This overarching technique covers deleting artifacts across an environment. CIS 3.4 protects the evidence chain by establishing mandatory retention periods that an attacker cannot alter or shorten.
References
|
| CIS-3.4 | Enforce Data Retention | mitigates | T1485 | Data Destruction |
Comments
Retention is protective because it limits the time window in which valuable data remains available for destruction, tampering, or cleanup by an attacker. Data retention policies protect against adversaries deleting logs by mandating strict storage lifecycles, off-site replication, and immutability.
References
|
| CIS-3.11 | Encrypt Sensitive Data At Rest | mitigates | T1552 | Unsecured Credentials |
Comments
Credentials and authentication material are often stored within files, databases, configuration repositories, and application data stores. Encrypting sensitive data at rest reduces the usefulness of credential artifacts obtained from protected storage locations by preventing direct access to plaintext credential material.
References
|
| CIS-3.5 | Securely Dispose of Data | mitigates | T1530 | Data from Cloud Storage |
Comments
Secure disposal reduces sensitive data retained in cloud object storage, lowering the value of compromised storage access
References
|
| CIS-3.5 | Securely Dispose of Data | mitigates | T1552 | Unsecured Credentials |
Comments
This applies when secure disposal explicitly removes old credential files, keys, exports, secrets, or configuration files that could expose credentials.
References
|
| CIS-3.5 | Securely Dispose of Data | mitigates | T1213 | Data from Information Repositories |
Comments
Secure disposal reduces stale sensitive records in repositories such as document stores, collaboration platforms, or knowledge bases.
References
|
| CIS-3.5 | Securely Dispose of Data | mitigates | T1039 | Data from Network Shared Drive |
Comments
Secure disposal reduces obsolete or unnecessary sensitive data left on shared drives, limiting what an adversary can collect from network shares.
References
|
| CIS-3.5 | Securely Dispose of Data | mitigates | T1005 | Data from Local System |
Comments
Secure disposal reduces residual sensitive files on endpoints and servers that an adversary could later collect from local storage.
References
|
| CIS-3.12 | Segment Data Processing and Storage Based on Sensitivity | mitigates | T1530 | Data from Cloud Storage |
Comments
Segregated cloud environments reduce exposure of sensitive cloud storage resources.
References
|
| CIS-3.12 | Segment Data Processing and Storage Based on Sensitivity | mitigates | T1021 | Remote Services |
Comments
Segmentation directly limits attacker movement between remote-accessible systems and sensitive environments.
References
|
| CIS-3.4 | Enforce Data Retention | mitigates | T1070 | Indicator Removal |
Comments
Data Retention restricts, hardens against, or increases visibility into the adversary behavior.
References
|
| CIS-3.4 | Enforce Data Retention | mitigates | T1485 | Data Destruction |
Comments
Retention is protective because it limits the time window in which valuable data remains available for destruction, tampering, or cleanup by an attacker.
References
|
| CIS-3.13 | Deploy a Data Loss Prevention Solution | mitigates | T1537 | Transfer Data to Cloud Account |
Comments
DLP is a direct control for blocking or alerting on exfiltration and data staging behaviors. DLP solutions commonly inspect and restrict uploads to external cloud services.
References
|
| CIS-3.13 | Deploy a Data Loss Prevention Solution | mitigates | T1048 | Exfiltration Over Alternative Protocol |
Comments
DLP is a direct control for blocking or alerting on exfiltration and data staging behaviors. DLP inspection capabilities may identify sensitive-data transfer across non-standard protocols.
References
|
| CIS-3.13 | Deploy a Data Loss Prevention Solution | mitigates | T1567 | Exfiltration Over Web Service |
Comments
DLP is a direct control for blocking or alerting on exfiltration and data staging behaviors. Web upload monitoring and restriction are core DLP use cases.
References
|
| CIS-3.13 | Deploy a Data Loss Prevention Solution | mitigates | T1052.001 | Exfiltration over USB |
Comments
DLP is a direct control for blocking or alerting on exfiltration and data staging behaviors. Device-control and removable-media DLP policies directly target USB-based exfiltration.
References
|
| CIS-3.13 | Deploy a Data Loss Prevention Solution | mitigates | T1041 | Exfiltration Over C2 Channel |
Comments
DLP is a direct control for blocking or alerting on exfiltration and data staging behaviors. DLP solutions explicitly monitor and restrict unauthorized outbound transfer of sensitive data.
References
|
| CIS-3.11 | Encrypt Sensitive Data At Rest | mitigates | T1039 | Data from Network Shared Drive |
Comments
Encryption protects sensitive shared-drive data against unauthorized disclosure
References
|
| CIS-3.11 | Encrypt Sensitive Data At Rest | mitigates | T1530 | Data from Cloud Storage |
Comments
Cloud storage encryption directly protects sensitive stored cloud data.
References
|
| CIS-3.11 | Encrypt Sensitive Data At Rest | mitigates | T1213 | Data from Information Repositories |
Comments
Repository encryption protects stored sensitive data even after unauthorized access.
References
|
| CIS-3.11 | Encrypt Sensitive Data At Rest | mitigates | T1005 | Data from Local System |
Comments
Encryption at rest directly reduces usability of stolen or accessed local data.
References
|
| CIS-3.10 | Encrypt Sensitive Data in Transit | mitigates | T1557 | Adversary-in-the-Middle |
Comments
Transport encryption directly constrains interception and manipulation of communications.
References
|
| CIS-3.10 | Encrypt Sensitive Data in Transit | mitigates | T1040 | Network Sniffing |
Comments
Encryption in transit directly mitigates readable interception of network traffic.
References
|
| CIS-3.9 | Encrypt Data on Removable Media | mitigates | T1052.001 | Exfiltration over USB |
Comments
Encrypting removable media directly reduces the usefulness of data exfiltrated via USB storage devices.
References
|
| CIS-3.9 | Encrypt Data on Removable Media | mitigates | T1025 | Data from Removable Media |
Comments
The safeguard explicitly protects removable-media-stored data from unauthorized access.
References
|
| CIS-3.6 | Encrypt Data on End-User Devices | mitigates | T1025 | Data from Removable Media |
Comments
Encryption protects copied endpoint data stored on removable media from unauthorized disclosure.
References
|
| CIS-3.6 | Encrypt Data on End-User Devices | mitigates | T1005 | Data from Local System |
Comments
Encryption on endpoints reduces the value of locally collected data and raises the bar for simple exfiltration after collection.
References
|
| CIS-3.5 | Securely Dispose of Data | mitigates | T1070.004 | File Deletion |
Comments
The safeguard specifically concerns secure deletion and sanitization of residual data artifacts.
References
|
| CIS-3.5 | Securely Dispose of Data | mitigates | T1561 | Disk Wipe |
Comments
This control protects against attacker behaviors that destroy or overwrite data and storage media.
References
|
| CIS-3.5 | Securely Dispose of Data | mitigates | T1485 | Data Destruction |
Comments
Secure disposal directly addresses preventing unauthorized recovery or persistence of sensitive data remnants.
References
|
| CIS-3.3 | Configure Data Access Control Lists | mitigates | T1078 | Valid Accounts |
Comments
ACLs constrain which accounts can reach data and therefore directly reduce abuse of valid accounts and local data access for collection.
References
|
| CIS-3.3 | Configure Data Access Control Lists | mitigates | T1005 | Data from Local System |
Comments
The control either restricts, detects, hardens against, or increases visibility into the adversary behavior associated with this technique. The control reduces unauthorized access opportunities and raises the difficulty of account misuse.
References
|