CIS Controls Account Management Capability Group

Use processes and tools to assign and manage authorization to credentials for user accounts, including administrator accounts, as well as service accounts, to enterprise assets and software.

All Mappings

Capability ID Capability Description Mapping Type ATT&CK ID ATT&CK Name Notes
CIS-5.2 Use Unique Passwords mitigates T1110 Brute Force
Comments
Unique passwords and minimum password lengths, which directly reduce the effectiveness of brute-force attacks by increasing the number of possible password combinations and limiting the reuse of compromised credentials across systems. This makes online password guessing and offline password cracking more difficult and reduces the success of credential-stuffing attacks.
References
CIS-5.2 Use Unique Passwords mitigates T1110.001 Password Guessing
Comments
Enforced minimum password length increases the search space and reduces the effectiveness of password guessing.
References
CIS-5.2 Use Unique Passwords mitigates T1110.002 Password Cracking
Comments
Longer passwords materially increase the effort required to recover plaintext passwords from captured hashes or related material.
References
CIS-5.2 Use Unique Passwords mitigates T1110.003 Password Spraying
Comments
Unique, non-common passwords reduce success of spraying common passwords across many accounts.
References
CIS-5.2 Use Unique Passwords mitigates T1078.001 Default Accounts
Comments
Unique passwords reduce adversary use of default or vendor-provided account credentials.
References
CIS-5.2 Use Unique Passwords mitigates T1078.002 Domain Accounts
Comments
Domain accounts can span users, admins, and services; unique passwords reduce domain credential reuse and lateral reuse risk.
References
CIS-5.2 Use Unique Passwords mitigates T1078.003 Local Accounts
Comments
Unique local passwords reduce reuse of one compromised local account credential across multiple endpoints or servers.
References
CIS-5.2 Use Unique Passwords mitigates T1078 Valid Accounts
Comments
Unique passwords reduce credential reuse across systems and accounts, limiting adversary use of one compromised password to pivot through valid accounts.
References
CIS-5.3 Disable Dormant Accounts mitigates T1110.004 Credential Stuffing
Comments
Disabling dormant accounts removes stale accounts that may still have breached or reused credentials, reducing credential-stuffing success against abandoned identities.
References
CIS-5.3 Disable Dormant Accounts mitigates T1078.004 Cloud Accounts
Comments
Disabling inactive cloud/SaaS accounts removes abandoned identities usable for access, persistence, or privilege abuse.
References
CIS-5.3 Disable Dormant Accounts mitigates T1078.003 Local Accounts
Comments
Disabling inactive local accounts reduces stale local credential abuse, dependent on endpoint/server coverage.
References
CIS-5.3 Disable Dormant Accounts mitigates T1078.002 Domain Accounts
Comments
Dormant domain accounts can retain broad access; disabling them removes stale domain credentials from the attack surface.
References
CIS-5.3 Disable Dormant Accounts mitigates T1078 Valid Accounts
Comments
Disabling stale accounts removes valid authentication paths available to adversaries.
References
CIS-5.4 Restrict Administrator Privileges to Dedicated Administrator Accounts mitigates T1078 Valid Accounts
Comments
Separating privileged accounts from daily-use accounts limits the privilege available if a primary account is compromised.
References
CIS-5.4 Restrict Administrator Privileges to Dedicated Administrator Accounts mitigates T1078.002 Domain Accounts
Comments
Dedicated domain admin accounts reduce the chance that routine domain account compromise yields domain-level privileges.
References
CIS-5.4 Restrict Administrator Privileges to Dedicated Administrator Accounts mitigates T1078.003 Local Accounts
Comments
Restricting local admin rights to dedicated accounts reduces local privilege availability in routine user sessions.
References
CIS-5.4 Restrict Administrator Privileges to Dedicated Administrator Accounts mitigates T1078.004 Cloud Accounts
Comments
Dedicated cloud admin accounts reduce privileged cloud exposure during normal user activity, though cloud-specific PAM controls are not required by the safeguard.
References
CIS-5.4 Restrict Administrator Privileges to Dedicated Administrator Accounts mitigates T1548 Abuse Elevation Control Mechanism
Comments
The safeguard limits which accounts can legitimately elevate, reducing the opportunity to abuse elevation paths from compromised routine accounts.
References
CIS-5.4 Restrict Administrator Privileges to Dedicated Administrator Accounts mitigates T1548.002 Bypass User Account Control
Comments
If routine accounts lack admin rights, UAC bypass from normal browsing/email sessions is less useful to an adversary.
References
CIS-5.4 Restrict Administrator Privileges to Dedicated Administrator Accounts mitigates T1548.003 Sudo and Sudo Caching
Comments
Dedicated admin accounts reduce privileged sudo exposure during routine activity, though sudo policy hardening is outside the safeguard.
References
CIS-5.4 Restrict Administrator Privileges to Dedicated Administrator Accounts mitigates T1548.005 Temporary Elevated Cloud Access
Comments
If dedicated administrator accounts include cloud privileged-access workflows or separate privileged cloud identities, the safeguard can reduce abuse of temporary elevated cloud access.
References
CIS-5.3 Disable Dormant Accounts mitigates T1078.001 Default Accounts
Comments
Disabling stale accounts removes valid authentication paths available to adversaries.
References
CIS-5.2 Use Unique Passwords mitigates T1110.004 Credential Stuffing
Comments
This directly counters password overlap from breached credentials reused across personal, third-party, and enterprise accounts.
References
CIS-5.2 Use Unique Passwords mitigates T1078.004 Cloud Accounts
Comments
Unique passwords reduce cloud/SaaS credential overlap and lateral reuse risk
References

Capabilities

Capability ID Capability Name Number of Mappings
CIS-5.2 Use Unique Passwords 10
CIS-5.4 Restrict Administrator Privileges to Dedicated Administrator Accounts 8
CIS-5.3 Disable Dormant Accounts 6