CIS Controls Access Control Management Capability Group

Use processes and tools to create, assign, manage, and revoke access credentials and privileges for user, administrator, and service accounts for enterprise assets and software.

All Mappings

Capability ID Capability Description Mapping Type ATT&CK ID ATT&CK Name Notes
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1003.006 DCSync
Comments
Role-based access control (RBAC) can restrict Active Directory replication permissions, including Replicating Directory Changes rights, to authorized administrative roles. Enforcing these permissions limits which identities can perform the directory replication operations required for DCSync.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1021.002 SMB/Windows Admin Shares
Comments
Role-based access control (RBAC) can restrict local administrator membership and administrative-share access to authorized roles. These enforced permissions limit the accounts that can use SMB and Windows administrative shares for remote administration and lateral movement.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1021.006 Windows Remote Management
Comments
Role-based access control (RBAC) can restrict WinRM accounts and permissions to authorized administrative roles. Enforced WinRM permissions limit which identities can use the service for remote execution and lateral movement.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1218.007 Msiexec
Comments
Role-based access control (RBAC) can restrict execution of Msiexec.exe to privileged accounts or groups with an authorized operational need. Enforcing this entitlement reduces opportunities for adversaries to abuse Windows Installer for proxy execution.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1525 Implant Internal Image
Comments
Role-based access control (RBAC) can limit permissions to create, modify, or publish platform and container images to authorized roles. Enforcing these permissions reduces an adversary's ability to implant malicious images within enterprise repositories.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1538 Cloud Service Dashboard
Comments
Role-based access control (RBAC) can enforce least-privilege dashboard visibility so users can access only the cloud resources required for their assigned roles. This limits the information and resources exposed through a cloud service dashboard when an account is compromised.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1548.002 Bypass User Account Control
Comments
Role-based access control (RBAC) can restrict local administrator membership to authorized roles. Removing unnecessary administrative rights reduces the accounts from which adversaries can leverage UAC bypass techniques to obtain elevated privileges.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1548.003 Sudo and Sudo Caching
Comments
Role-based access control (RBAC) can enforce which users or groups are authorized for sudo privileges and which elevated commands they may run. Restricting these entitlements limits the identities and operations available for privilege elevation through sudo.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1556.004 Network Device Authentication
Comments
Role-based access control (RBAC) can restrict network-device administrator privileges to narrowly scoped authorized roles. Enforcing least-privilege administrative access reduces the identities capable of modifying network-device authentication mechanisms.
References
CIS-6.5 Require MFA for Administrative Access mitigates T1556.008 Network Provider DLL
Comments
Integrate multi-factor authentication (MFA) for administrative accounts to reduce the risk of adversaries using compromised privileged credentials to register malicious network provider dynamic link libraries (DLLs) to capture cleartext user credentials during the authentication process.
References
CIS-6.5 Require MFA for Administrative Access mitigates T1556.007 Hybrid Identity
Comments
Integrate multi-factor authentication (MFA) for administrative accounts to reduce the risk of adversaries using compromised privileged credentials (e.g., hybrid identity environment admin, synchronization service, cloud tenant) to patch, modify, or otherwise backdoor cloud authentication processes
References
CIS-6.5 Require MFA for Administrative Access mitigates T1556.006 Multi-Factor Authentication
Comments
Integrate multi-factor authentication (MFA) for administrative accounts to reduce the risk of adversaries using compromised privileged credentials to disable or modify MFA mechanisms and enable persistent access to compromised accounts.
References
CIS-6.5 Require MFA for Administrative Access mitigates T1556.005 Reversible Encryption
Comments
Integrate multi-factor authentication (MFA) for administrative accounts to reduce the risk of adversaries using compromised privileged credentials (e.g., domain/identity policy administrator, local security policy administrator) to abuse Active Directory encryption properties and gain access to credentials on Windows systems.
References
CIS-6.5 Require MFA for Administrative Access mitigates T1556.004 Network Device Authentication
Comments
Integrate multi-factor authentication (MFA) for administrative accounts to reduce the risk of adversaries using compromised privileged credentials to bypass of native authentication mechanisms for tenant/device management accounts on network devices.
References
CIS-6.5 Require MFA for Administrative Access mitigates T1556.003 Pluggable Authentication Modules
Comments
Integrate multi-factor authentication (MFA) for administrative accounts to reduce the risk of adversaries using compromised privileged credentials to modify pluggable authentication modules (PAM) to access user credentials or enable otherwise unwarranted access to accounts.
References
CIS-6.5 Require MFA for Administrative Access mitigates T1556.002 Password Filter DLL
Comments
Integrate multi-factor authentication (MFA) for administrative accounts to reduce the risk of adversaries using compromised privileged credentials to register malicious password filter dynamic link libraries (DLLs) into the authentication process.
References
CIS-6.5 Require MFA for Administrative Access mitigates T1556.001 Domain Controller Authentication
Comments
Integrate multi-factor authentication (MFA) for administrative accounts to reduce the risk of adversaries using compromised privileged credentials to patch the authentication process on a domain controller to bypass the typical authentication mechanisms and enable access to accounts.
References
CIS-6.5 Require MFA for Administrative Access mitigates T1556 Modify Authentication Process
Comments
Integrate multi-factor authentication (MFA) for administrative accounts to reduce the risk of adversaries using compromised privileged credentials to modify authentication processes or mechanisms.
References
CIS-6.5 Require MFA for Administrative Access mitigates T1110.004 Credential Stuffing
Comments
Implement multi-factor authentication (MFA) for administrative accounts to help prevent adversaries from using credentials obtained from breach dumps to gain access to admin accounts through credential overlap.
References
CIS-6.5 Require MFA for Administrative Access mitigates T1110.003 Password Spraying
Comments
Implement multi-factor authentication (MFA) for administrative accounts to help prevent adversaries from using commonly used passwords to attempt to acquire valid admin credentials.
References
CIS-6.5 Require MFA for Administrative Access mitigates T1110.002 Password Cracking
Comments
Implement multi-factor authentication (MFA) for administrative accounts to help prevent adversaries from using password cracking to recover admin credentials.
References
CIS-6.5 Require MFA for Administrative Access mitigates T1110.001 Password Guessing
Comments
Implement multi-factor authentication (MFA) for administrative accounts to help prevent adversaries from using password guessing to access admin accounts.
References
CIS-6.5 Require MFA for Administrative Access mitigates T1110 Brute Force
Comments
Implement multi-factor authentication (MFA) for administrative accounts to help prevent adversaries from brute forcing admin credentials.
References
CIS-6.5 Require MFA for Administrative Access mitigates T1072 Software Deployment Tools
Comments
Implement multi-factor authentication (MFA) for administrative accounts to provide system and access isolation for critical network systems.
References
CIS-6.5 Require MFA for Administrative Access mitigates T1556.009 Conditional Access Policies
Comments
Integrate multi-factor authentication (MFA) for administrative accounts to reduce the risk of adversaries using compromised privileged credentials to disable or modify conditional access policies.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1550.003 Pass the Ticket
Comments
Using role-based access control (RBAC) to prevent domain users from being local administrators on multiple systems can help limit adversaries’ ability to reuse Kerberos tickets for lateral movement.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1550.002 Pass the Hash
Comments
Using role-based access control (RBAC) to prevent domain users from being local administrators on multiple systems can help limit adversaries’ ability to reuse NTLM hashes for lateral movement.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1550 Use Alternate Authentication Material
Comments
Using role-based access control (RBAC) to enforce least privilege and prevent domain users from holding local-administrator rights across multiple systems can help limit an adversary’s ability to use alternate authentication material for lateral movement.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1552.007 Container API
Comments
Enforce authentication and role-based access control (RBAC) on the container API to restrict users to the least privileges required to help prevent adversaries from gathering credentials via APIs within a containers environment.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1537 Transfer Data to Cloud Account
Comments
Using role-based access control (RBAC) to limit user-account and identity access management (IAM) permissions to the least privileges required can help prevent adversaries from transferring organizational data to cloud accounts they control.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1199 Trusted Relationship
Comments
Implement role-based access control (RBAC) to manage accounts and permissions used by parties in trusted relationships to minimize potential abuse by the party or if the party is compromised by an adversary.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1569.003 Systemctl
Comments
Implement role-based access control (RBAC) to ensure lower-privileged users cannot create or interact with higher-privileged system services to help prevent adversaries from abusing systemctl to execute commands or programs.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1569.001 Launchctl
Comments
Implement role-based access control (RBAC) to ensure lower-privileged users cannot create or interact with higher-privileged system services to help prevent adversaries from abusing launchctl to execute commands or programs.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1047 Windows Management Instrumentation
Comments
Using role-based access control (RBAC) to restrict remote WMI access to authorized administrative roles can help prevent adversaries from abusing Windows Management Instrumentation (WMI) to execute malicious commands and payloads.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1195 Supply Chain Compromise
Comments
Implement role-based access control (RBAC) to ensure software and development tools run with the lowest necessary privileges to help limit an adversary’s ability to propagate or perform unauthorized actions in the event of a supply chain compromise.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1528 Steal Application Access Token
Comments
Enforce role-based access control (RBAC) to limit accounts to the least privileges they require to help prevent adversaries from obtaining or abusing application access tokens.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1489 Service Stop
Comments
Using role-based access control (RBAC) to limit user accounts and groups so that only authorized administrators can interact with service changes and service configurations can help prevent adversaries from stopping or disabling services.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1648 Serverless Execution
Comments
Using role-based access control (RBAC) to limit permissions to create, modify, or run serverless resources only to users that explicitly require them can help prevent adversaries from abusing serverless computing, integration, and automation services to execute arbitrary code in cloud environments.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1505.003 Web Shell
Comments
Using role-based access control (RBAC) to limit permissions to upload, create, or modify content in web-server application directories to users with a legitimate need can help prevent adversaries from backdooring web servers with web shells.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1505 Server Software Component
Comments
Using role-based access control (RBAC) to limit permissions to add or modify server software components to users with a legitimate need can help prevent adversaries from abusing legitimate extensible development features of servers.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1021.001 Remote Desktop Protocol
Comments
Using role-based access control (RBAC) to limit Remote Desktop Users group membership and Remote Desktop Protocol (RDP) permissions to users with a legitimate need can help prevent adversaries from using RDP for lateral movement.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1053.006 Systemd Timers
Comments
Using role-based access control (RBAC) to limit permissions to create or modify scheduled tasks via system utilities to authorized administrator roles to help prevent adversaries from abusing task scheduling functionality.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1053.003 Cron
Comments
Using role-based access control (RBAC) to limit permissions to create or modify scheduled tasks via the cron utility to authorized administrator roles to help prevent adversaries from abusing task scheduling functionality.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1053 Scheduled Task/Job
Comments
Using role-based access control (RBAC) to limit permissions to create or modify scheduled tasks and jobs on remote systems to authorized administrator roles to help prevent adversaries from abusing task scheduling functionality.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1053.002 At
Comments
Using role-based access control (RBAC) to limit permissions to create or modify scheduled tasks via the at utility to authorized administrator roles to help prevent adversaries from abusing task scheduling functionality.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1053.005 Scheduled Task
Comments
Using role-based access control (RBAC) to limit permissions to create or modify scheduled tasks on remote systems to authorized administrator roles to help prevent adversaries from abusing task scheduling functionality.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1021.004 SSH
Comments
Using role-based access control (RBAC) to limit SSH access and permitted commands to users with a legitimate need can help prevent adversaries from using SSH for lateral movement.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1053.007 Container Orchestration Job
Comments
Using role-based access control (RBAC) to limit permissions to create or modify scheduled tasks via container orchestration tools to authorized administrator roles to help prevent adversaries from abusing task scheduling functionality.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1072 Software Deployment Tools
Comments
Using role-based access control (RBAC) to limit access to and use of centralized software suites to a limited number of authorized administrators with a verified business need can help prevent adversaries from accessing and abusing software deployment tools.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1021 Remote Services
Comments
Using role-based access control (RBAC) to limit which accounts can use remote services and restrict the commands or resources available to those accounts to help prevent adversaries from using remote services for lateral movement.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1563.001 SSH Hijacking
Comments
Using role-based access control (RBAC) to limit remote user permissions to necessary users to help prevent adversaries from commandeering these sessions.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1563.002 RDP Hijacking
Comments
Using role-based access control (RBAC) to limit remote user permissions to necessary users to help prevent adversaries from commandeering these sessions.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1563 Remote Service Session Hijacking
Comments
Using role-based access control (RBAC) to limit remote user permissions to necessary users to help prevent adversaries from commandeering these sessions.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1677 Poisoned Pipeline Execution
Comments
Using role-based access control (RBAC) to limit write access to internal repositories and CI/CD pipeline permissions to users and services with a legitimate need can help prevent adversaries from modifying pipelines to execute malicious code.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1566.003 Spearphishing via Service
Comments
Using role-based access control (RBAC) to limit third-party messaging and collaboration-service account privileges to users with a legitimate need can help prevent adversaries from abusing compromised service accounts for spearphishing.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1566.002 Spearphishing Link
Comments
Using role-based access control (RBAC) to apply limitations on which roles can grant consent to third-party applications can help prevent users from granting consent to unfamiliar or unverified third-party applications through spearphishing links.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1566.001 Spearphishing Attachment
Comments
Using role-based access control (RBAC) to limit file-opening and execution permissions to only the accounts that require them can help reduce the impact of malicious email attachments by preventing unauthorized execution or spread of malware.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1040 Network Sniffing
Comments
In cloud environments, using role-based access control (RBAC) to ensure that users are not granted permissions to create or modify traffic mirrors unless explicitly required can help prevent adversaries from capturing network traffic.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1666 Modify Cloud Resource Hierarchy
Comments
Using role-based access control (RBAC) to limit permissions to add, delete, or modify cloud resource groups and hierarchy structures to authorized roles can help prevent adversaries from evading organizational guardrails and cloud security policies.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1578.005 Modify Cloud Compute Configurations
Comments
Using role-based access control (RBAC) to limit permissions to modify cloud compute settings, quotas, and tenant-level configurations to authorized roles can help prevent adversaries from altering infrastructure resources or bypassing restrictions.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1578.003 Delete Cloud Instance
Comments
Using role-based access control (RBAC) to limit permissions to delete cloud instances to authorized roles can help prevent adversaries from removing instances to destroy evidence of malicious activity.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1578.002 Create Cloud Instance
Comments
Using role-based access control (RBAC) to limit permissions to create cloud instances to authorized roles can help prevent adversaries from deploying new instances to evade defenses or conduct unauthorized activity.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1578.001 Create Snapshot
Comments
Using role-based access control (RBAC) to limit permissions to create cloud snapshots and backups to authorized roles can help prevent adversaries from creating copies of cloud resources for unauthorized access or data collection.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1578 Modify Cloud Compute Infrastructure
Comments
Using role-based access control (RBAC) to limit permissions to create, delete, and modify cloud compute infrastructure to authorized roles can help prevent adversaries from altering cloud resources to evade defenses or gain unauthorized access.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1021.008 Direct Cloud VM Connections
Comments
Using role-based access control (RBAC) to limit direct cloud-native VM connection permissions to users with a legitimate need can help prevent adversaries from accessing cloud compute infrastructure for lateral movement.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1556.006 Multi-Factor Authentication
Comments
Using role-based access control (RBAC) to limit permissions to enroll, disable, or modify multi-factor authentication (MFA) methods and policies to authorized administrative roles can help prevent adversaries from weakening MFA protections on compromised accounts.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1556 Modify Authentication Process
Comments
Using role-based access control (RBAC) to limit permissions to modify authentication processes and identity-provider settings to authorized administrative roles can help prevent adversaries from altering authentication controls to gain unauthorized access.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1654 Log Enumeration
Comments
Using role-based access control (RBAC) to limit permissions to access and export sensitive system and service logs to privileged roles can help prevent adversaries from enumerating logs for valuable information.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1490 Inhibit System Recovery
Comments
Using role-based access control (RBAC) to limit permissions to backups to only required users with a legitimate need can help prevent adversaries from deleting or removing built-in data and turning off services designed to aid in the recovery of a corrupted system.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1574.012 COR_PROFILER
Comments
Using role-based access control (RBAC) to limit permissions to modify COR_PROFILER environment variables and related .NET configuration settings to users with a legitimate need can help prevent adversaries from loading malicious DLLs into .NET processes.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1574.010 Services File Permissions Weakness
Comments
Using role-based access control (RBAC) to limit permissions to modify service executables and their file paths to users with a legitimate need can help prevent adversaries from replacing service binaries with malicious payloads.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1574.005 Executable Installer File Permissions Weakness
Comments
Using role-based access control (RBAC) to limit permissions to modify installer executables and their file paths to users with a legitimate need can help prevent adversaries from replacing installer binaries with malicious payloads.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1574 Hijack Execution Flow
Comments
Using role-based access control (RBAC) to limit permissions to modify service configurations, registry settings, and protected file paths to users with a legitimate need can help prevent adversaries from hijacking execution flow.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1530 Data from Cloud Storage
Comments
Using role-based access control (RBAC) to limit user groups and roles for access to cloud storage to only users with a legitimate need can help prevent adversaries from accessing and collecting data from cloud storage solutions.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1606 Forge Web Credentials
Comments
Using role-based access control (RBAC) to limit access to identity infrastructure and token-issuance permissions to narrowly scoped privileged roles reduces opportunities to forge credential materials.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1657 Financial Theft
Comments
Using role-based access control (RBAC) to limit sensitive financial transactions and approval privileges to narrowly scoped roles can mitigate use of a compromised account to initiate or authorize unauthorized payments.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1556.009 Conditional Access Policies
Comments
Using role-based access control (RBAC) to limit permissions to modify conditional access policies to authorized administrative roles can help prevent adversaries from removing multi-factor authentication (MFA) requirements or adding exclusions that enable persistent access.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1606.002 SAML Tokens
Comments
Using role-based access control (RBAC) to limit access to identity infrastructure and token-issuance permissions to narrowly scoped privileged roles reduces opportunities to forge SAML tokens.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1048 Exfiltration Over Alternative Protocol
Comments
Using role-based access control (RBAC) to limit user groups and roles for access to cloud storage systems and objects to only users with a legitimate need can help prevent adversaries from exfiltrating data from cloud storage.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1484.001 Group Policy Modification
Comments
Role-based access control (RBAC) can be used to limit which users and computers can access Group Policy Objects (GPOs), helping to prevent adversaries from modifying GPOs.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1484 Domain or Tenant Policy Modification
Comments
Role-based access control (RBAC) can be used to limit which users and computers can access domain and identity tenant settings, helping to prevent adversaries from modifying their configuration settings.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1610 Deploy Container
Comments
Enforcing role-based access control (RBAC) to limit container dashboard access to only necessary users can prevent adversaries from deploying a container into an environment.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1213.006 Databases
Comments
Using role-based access control (RBAC) to limit database access to only authorized users helps prevent adversaries from leveraging these databases to mine valuable information.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1213.001 Confluence
Comments
Using role-based access control (RBAC) to limit Confluence repository access to only authorized users helps prevent adversaries from leveraging these repositories to mine valuable information.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1484.002 Trust Modification
Comments
In cloud environments, role-based access control (RBAC) can be used to limit permissions to create new identity providers to only those accounts that require them. This can prevent adversaries from adding new domain trusts, modifying the properties of existing domain trusts, or otherwise changing the configuration of trust relationships between domains and tenants.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1213.004 Customer Relationship Management Software
Comments
Using role-based access control (RBAC) to limit Customer Relationship Management (CRM) software access to only authorized users helps prevent adversaries from leveraging CRM software to mine valuable information.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1213.003 Code Repositories
Comments
Using role-based access control (RBAC) to limit code repository access to only authorized users helps prevent adversaries from leveraging these repositories to mine valuable information.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1213 Data from Information Repositories
Comments
Using role-based access control (RBAC) to limit information repository access to only authorized users helps prevent adversaries from leveraging these repositories to mine valuable information.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1543 Create or Modify System Process
Comments
Using role-based access control (RBAC) to ensure only authorized administrator roles can interact with system-level process changes and service configurations helps prevent adversaries from leveraging this functionality to establish persistence or escalate privileges.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1485.001 Lifecycle-Triggered Deletion
Comments
In cloud environments, using role-based access control (RBAC) to limit user permissions to modify cloud bucket lifecycle policies to only users with a legitimate need can help prevent adversaries from destroying all objects stored within buckets.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1485 Data Destruction
Comments
In cloud environments, using role-based access control (RBAC) to limit user permissions to modify cloud bucket lifecycle policies to only users with a legitimate need can help prevent adversaries from destroying data and files.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1543.005 Container Service
Comments
Using role-based access control (RBAC) to limit user access to utilities such as docker to only users with a legitimate need helps prevent adversaries from creating or modifying container or cluster management tools to establish persistence or escalate privileges.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1543.004 Launch Daemon
Comments
Using role-based access control (RBAC) to ensure only authorized administrator roles can create new Launch Daemons helps prevent adversaries from creating or modifying Launch Daemons to establish persistence or escalate privileges.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1543.003 Windows Service
Comments
Using role-based access control (RBAC) to ensure only authorized administrator roles can interact with service changes and service configurations helps prevent adversaries from leveraging this functionality to establish persistence or escalate privileges.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1543.002 Systemd Service
Comments
Using role-based access control (RBAC) to limit user access to system utilities to only users with a legitimate need helps prevent adversaries from creating or modifying systemd services to establish persistence or escalate privileges.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1213.002 Sharepoint
Comments
Using role-based access control (RBAC) to limit SharePoint repository access to only authorized users helps prevent adversaries from leveraging these repositories to mine valuable information.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1134.002 Create Process with Token
Comments
Role-based access control (RBAC) can help mitigate access token manipulation by restricting which roles are allowed to create new processes with tokens and limiting privileges to a small set of tightly controlled roles.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1609 Container Administration Command
Comments
Enforcing authentication and role-based access control (RBAC) on the container administration service to restrict users to the least privileges required can help prevent adversaries from abusing the service to execute commands within the container.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1059.008 Network Device CLI
Comments
Role-based access control (RBAC) helps mitigate this technique by enforcing least privilege and command authorization on network device CLI access, limiting which roles can run perform authorization changes.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1619 Cloud Storage Object Discovery
Comments
Role-based access control (RBAC) can help mitigate discovery of cloud storage objects by limiting cloud storage list permissions to narrowly scoped roles, reducing who can enumerate storage objects for discovery.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1580 Cloud Infrastructure Discovery
Comments
Role-based access control (RBAC) can help mitigate discovery of cloud infrastructure and resources by limiting which roles can access, manage, or query cloud infrastructure metadata and enforcing who can see and do what in cloud service dashboards.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1185 Browser Session Hijacking
Comments
Role-based access control (RBAC) can help mitigate browser session hijacking techniques by enforcing least privilege so that hijacked browser sessions are associated with minimally scoped roles, limiting what an adversary can do with a captured session.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1547.012 Print Processors
Comments
Role-based access control (RBAC) can help mitigate this technique by limiting which roles can load or unload device drivers by disabling SeLoadDriverPrivilege.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1613 Container and Resource Discovery
Comments
Role-based access control (RBAC) can help mitigate this technique by tightly controlling which roles can view or query container APIs and dashboards and restricting discovery of cluster resources to narrowly scoped roles.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1547.009 Shortcut Modification
Comments
Role-based access control (RBAC) can help mitigate this technique by limiting shortcut creation and modification to narrowly scoped roles.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1547.006 Kernel Modules and Extensions
Comments
Role-based access control (RBAC) can help mitigate this technique by limiting which roles can load or configure kernel modules and extensions to tightly controlled admin roles.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1547.004 Winlogon Helper DLL
Comments
Role-based access control (RBAC) can help mitigate this technique by restricting Winlogon configuration changes to a small set of tightly controlled admin roles.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1547.013 XDG Autostart Entries
Comments
Role-based access control (RBAC) can help mitigate this technique by limiting which roles can can create and modify XDG autostart entries to narrowly scoped privileged roles.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1098.004 SSH Authorized Keys
Comments
Role-based access control (RBAC) can help mitigate account manipulation by limiting which roles in cloud environments are allowed to modify SSH authorized_keys files and ensuring that only users who explicitly require the permissions to update instance metadata or configurations can do so.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1197 BITS Jobs
Comments
Role-based access control (RBAC) can help mitigate abuse of BITS jobs by limiting access to the BITS interface to specific user roles or groups.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1098.003 Additional Cloud Roles
Comments
Role-based access control (RBAC) can help mitigate account manipulation by limiting which roles are allowed to create or modify accounts and ensuring that low-privileged users do not have permissions to add permissions to accounts or update IAM policies.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1098.001 Additional Cloud Credentials
Comments
Role-based access control (RBAC) can help mitigate account manipulation by limiting which roles are allowed to create or modify accounts and ensuring that low-privileged users do not have permissions to add access keys to accounts.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1098 Account Manipulation
Comments
Role-based access control (RBAC) can help mitigate account manipulation by limiting which roles are allowed to create or modify accounts and ensuring that low-privileged users do not have permissions to modify accounts or account-related policies.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1087.004 Cloud Account
Comments
Role-based access control (RBAC) can help mitigate account discovery by limiting what each role can see or query.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1087 Account Discovery
Comments
Role-based access control (RBAC) can help mitigate account discovery by limiting what each role can see or query.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1098.006 Additional Container Cluster Roles
Comments
Role-based access control (RBAC) can help mitigate account manipulation by limiting which roles are allowed to add additional roles or permissions and ensuring that low-privileged accounts do not have permissions to add permissions to accounts or to update container cluster roles.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1546.003 Windows Management Instrumentation Event Subscription
Comments
Using role-based access control (RBAC) to restrict or disallow user groups allowed to connect to WMI can help prevent adversaries from maliciously using WMI event subscription capabilities.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1134.001 Token Impersonation/Theft
Comments
Role-based access control (RBAC) can help mitigate access token manipulation by restricting which roles are allowed to create or impersonate tokens and limiting privileges to a small set of tightly controlled roles.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1134 Access Token Manipulation
Comments
Role-based access control (RBAC) can help mitigate access token manipulation by restricting which roles are allowed to create or modify tokens and limiting privileges to a small set of tightly controlled roles.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1548.005 Temporary Elevated Cloud Access
Comments
Role-based access control (RBAC), implemented under least privilege and access enforcement controls, helps mitigate this technique by limiting which identities can use elevation mechanisms and what they can elevate to.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1548 Abuse Elevation Control Mechanism
Comments
Role-based access control (RBAC), implemented under least privilege and access enforcement controls, helps mitigate this technique by limiting which identities can use elevation mechanisms and what they can elevate to.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1134.003 Make and Impersonate Token
Comments
Role-based access control (RBAC) can help mitigate access token manipulation by restricting which roles are allowed to create and impersonate tokens and limiting privileges to a small set of tightly controlled roles.
References
CIS-6.5 Require MFA for Administrative Access mitigates T1078.004 Cloud Accounts
Comments
Implement multi-factor authentication (MFA) for administrative accounts to help prevent unauthorized access, even if credentials are compromised.
References
CIS-6.5 Require MFA for Administrative Access mitigates T1078.003 Local Accounts
Comments
Implement multi-factor authentication (MFA) for administrative accounts to help prevent unauthorized access, even if credentials are compromised.
References
CIS-6.5 Require MFA for Administrative Access mitigates T1078 Valid Accounts
Comments
Implement multi-factor authentication (MFA) for administrative accounts to help prevent unauthorized access, even if credentials are compromised.
References
CIS-6.5 Require MFA for Administrative Access mitigates T1078.002 Domain Accounts
Comments
Implement multi-factor authentication (MFA) for administrative accounts to help prevent unauthorized access, even if credentials are compromised.
References
CIS-6.2 Establish an Access Revoking Process mitigates T1078 Valid Accounts
Comments
Disabling accounts that are no longer needed immediately upon termination, rights revocation, or role change prevents adversaries from gaining and using those accounts.
References
CIS-6.5 Require MFA for Administrative Access mitigates T1098 Account Manipulation
Comments
Using multi-factor authentication for privileged administrative access reduces the success of adversary attempts to maintain or elevate access using compromised credentials.
References
CIS-6.5 Require MFA for Administrative Access mitigates T1599 Network Boundary Bridging
Comments
Using multi-factor authentication on accounts that administer network devices helps prevent adversaries from using compromised credentials to reconfigure or bypass network boundaries by limiting their ability to log in.
References
CIS-6.5 Require MFA for Administrative Access mitigates T1601.002 Downgrade System Image
Comments
Using multi-factor authentication on administrator accounts helps prevent adversaries from using compromised credentials to install older operating systems by limiting their ability to log in.
References
CIS-6.5 Require MFA for Administrative Access mitigates T1601.001 Patch System Image
Comments
Using multi-factor authentication on administrator accounts helps prevent adversaries from using compromised credentials to modify system images and introduce new capabilities or weaken defenses by limiting their ability to log in.
References
CIS-6.5 Require MFA for Administrative Access mitigates T1601 Modify System Image
Comments
Using multi-factor authentication on administrator accounts helps prevent adversaries from using compromised credentials to modify system images by limiting their ability to log in.
References
CIS-6.5 Require MFA for Administrative Access mitigates T1556.004 Network Device Authentication
Comments
Requiring multi-factor authentication on administrator accounts ensures that adversaries cannot rely on a single implanted or backdoor password to gain access to network devices without also satisfying an independent second factor.
References
CIS-6.2 Establish an Access Revoking Process mitigates T1555.005 Password Managers
Comments
Inactive accounts may be targeted by attackers to gain unauthorized access. Disabling inactive accounts can prevent attackers from obtaining the user credentials from third-party password managers.
References
CIS-6.5 Require MFA for Administrative Access mitigates T1098.005 Device Registration
Comments
Requiring multi-factor authentication (MFA) to register devices in Entra ID, configuring MFA systems to disallow enrolling new devices for inactive accounts, and using conditional access policies to restrict initial MFA device enrollment to trusted locations or devices reduces the success of adversary attempts to add additional devices to an adversary-controlled account.
References
CIS-6.5 Require MFA for Administrative Access mitigates T1136.002 Domain Account
Comments
Using multi-factor authentication for administrative accounts reduces the likelihood that adversaries can use a compromised admin credential to sign in and create additional accounts by preventing access at login.
References
CIS-6.5 Require MFA for Administrative Access mitigates T1136.001 Local Account
Comments
Using multi-factor authentication for administrative accounts reduces the likelihood that adversaries can use a compromised admin credential to sign in and create additional accounts by preventing access at login.
References
CIS-6.5 Require MFA for Administrative Access mitigates T1136 Create Account
Comments
Using multi-factor authentication for administrative accounts reduces the likelihood that adversaries can use a compromised admin credential to sign in and create additional accounts by preventing access at login.
References
CIS-6.5 Require MFA for Administrative Access mitigates T1199 Trusted Relationship
Comments
Using multi-factor authentication for administrative accounts reduces the success of adversaries breaching trusted third party relationships to compromise those networks and gain access to intended victims.
References
CIS-6.4 Require MFA for Remote Network Access mitigates T1021.004 SSH
Comments
Enabling multi-factor authentication for SSH connections helps minimize the adversary's ability to leverage stolen credentials.
References
CIS-6.4 Require MFA for Remote Network Access mitigates T1021.001 Remote Desktop Protocol
Comments
Enabling multi-factor authentication for remote logins helps minimize the adversary's ability to leverage stolen credentials.
References
CIS-6.4 Require MFA for Remote Network Access mitigates T1021 Remote Services
Comments
Enabling multi-factor authentication for remote service logons helps minimize the adversary's ability to leverage stolen credentials.
References
CIS-6.4 Require MFA for Remote Network Access mitigates T1133 External Remote Services
Comments
Enabling multi-factor authentication for external-facing remote service accounts to helps minimize the adversary's ability to leverage stolen credentials.
References
CIS-6.3 Require MFA for Externally-Exposed Applications mitigates T1114.002 Remote Email Collection
Comments
Enabling multi-factor authentication for public-facing webmail servers helps minimize the usefulness of email usernames and passwords collected by adversaries.
References
CIS-6.3 Require MFA for Externally-Exposed Applications mitigates T1114 Email Collection
Comments
Enabling multi-factor authentication for public-facing webmail servers helps minimize the usefulness of email usernames and passwords collected by adversaries.
References
CIS-6.4 Require MFA for Remote Network Access mitigates T1021.007 Cloud Services
Comments
Enabling multi-factor authentication on cloud services helps minimize the adversary's ability to leverage stolen credentials.
References
CIS-6.3 Require MFA for Externally-Exposed Applications mitigates T1110.003 Password Spraying
Comments
Enabling multi-factor authentication can prevent adversaries from gaining access through brute force password spraying attacks against authentication interfaces on externally facing services.
References
CIS-6.3 Require MFA for Externally-Exposed Applications mitigates T1110.002 Password Cracking
Comments
Enabling multi-factor authentication can prevent adversaries from gaining access through brute force password cracking attacks against authentication interfaces on externally facing services.
References
CIS-6.3 Require MFA for Externally-Exposed Applications mitigates T1110.001 Password Guessing
Comments
Enabling multi-factor authentication can prevent adversaries from gaining access through brute force password guessing attacks against authentication interfaces on externally facing services.
References
CIS-6.3 Require MFA for Externally-Exposed Applications mitigates T1110 Brute Force
Comments
Enabling multi-factor authentication can prevent adversaries from gaining access through brute force attacks against authentication interfaces on externally facing services.
References
CIS-6.3 Require MFA for Externally-Exposed Applications mitigates T1110.004 Credential Stuffing
Comments
Enabling multi-factor authentication can prevent adversaries from gaining access through brute force credential stuffing attacks against authentication interfaces on externally facing services.
References
CIS-6.2 Establish an Access Revoking Process mitigates T1555.003 Credentials from Web Browsers
Comments
Inactive accounts may be targeted by attackers to gain unauthorized access. Disabling inactive accounts can prevent attackers from acquiring credentials from web browsers.
References
CIS-6.2 Establish an Access Revoking Process mitigates T1556.006 Multi-Factor Authentication
Comments
Removing accounts that are no longer needed helps to accounts that adversaries could abuse to disable or modify MFA and maintain persistent access.
References
CIS-6.2 Establish an Access Revoking Process mitigates T1078.004 Cloud Accounts
Comments
Disabling accounts that are no longer needed immediately upon termination, rights revocation, or role change prevents adversaries from gaining and using those accounts.
References
CIS-6.5 Require MFA for Administrative Access mitigates T1078.001 Default Accounts
Comments
Implement multi-factor authentication (MFA) for administrative accounts to help prevent unauthorized access, even if credentials are compromised.
References
CIS-6.2 Establish an Access Revoking Process mitigates T1078.003 Local Accounts
Comments
Disabling accounts that are no longer needed immediately upon termination, rights revocation, or role change prevents adversaries from gaining and using those accounts.
References
CIS-6.2 Establish an Access Revoking Process mitigates T1078.002 Domain Accounts
Comments
Disabling accounts that are no longer needed immediately upon termination, rights revocation, or role change prevents adversaries from gaining and using those accounts.
References
CIS-6.5 Require MFA for Administrative Access mitigates T1098.003 Additional Cloud Roles
Comments
Using multi-factor authentication for privileged administrative access reduces the success of adversary attempts to add additional roles or permissions to an adversary-controlled cloud account to maintain or elevate access.
References
CIS-6.5 Require MFA for Administrative Access mitigates T1098.002 Additional Email Delegate Permissions
Comments
Using multi-factor authentication for privileged administrative access reduces the success of adversary attempts to grant additional permission levels to an adversary-controlled email account.
References
CIS-6.5 Require MFA for Administrative Access mitigates T1098.001 Additional Cloud Credentials
Comments
Using multi-factor authentication for privileged administrative access reduces the success of adversary attempts to add adversary-owned credentials to a cloud account to maintain or elevate access.
References
CIS-6.5 Require MFA for Administrative Access mitigates T1136.003 Cloud Account
Comments
Using multi-factor authentication for administrative accounts reduces the likelihood that adversaries can use a compromised admin credential to sign in and create additional accounts by preventing access at login.
References
CIS-6.5 Require MFA for Administrative Access mitigates T1599.001 Network Address Translation Traversal
Comments
Using multi-factor authentication on accounts that administer network devices helps prevent adversaries from using compromised credentials to modify a network device’s Network Address Translation (NAT) configuration by limiting their ability to log in.
References

Capabilities

Capability ID Capability Name Number of Mappings
CIS-6.8 Define and Maintain Role-Based Access Control 106
CIS-6.5 Require MFA for Administrative Access 37
CIS-6.4 Require MFA for Remote Network Access 5
CIS-6.3 Require MFA for Externally-Exposed Applications 7
CIS-6.2 Establish an Access Revoking Process 7