Use processes and tools to create, assign, manage, and revoke access credentials and privileges for user, administrator, and service accounts for enterprise assets and software.
| Capability ID | Capability Description | Mapping Type | ATT&CK ID | ATT&CK Name | Notes |
|---|---|---|---|---|---|
| CIS-6.8 | Define and Maintain Role-Based Access Control | mitigates | T1003.006 | DCSync |
Comments
Role-based access control (RBAC) can restrict Active Directory replication permissions, including Replicating Directory Changes rights, to authorized administrative roles. Enforcing these permissions limits which identities can perform the directory replication operations required for DCSync.
References
|
| CIS-6.8 | Define and Maintain Role-Based Access Control | mitigates | T1021.002 | SMB/Windows Admin Shares |
Comments
Role-based access control (RBAC) can restrict local administrator membership and administrative-share access to authorized roles. These enforced permissions limit the accounts that can use SMB and Windows administrative shares for remote administration and lateral movement.
References
|
| CIS-6.8 | Define and Maintain Role-Based Access Control | mitigates | T1021.006 | Windows Remote Management |
Comments
Role-based access control (RBAC) can restrict WinRM accounts and permissions to authorized administrative roles. Enforced WinRM permissions limit which identities can use the service for remote execution and lateral movement.
References
|
| CIS-6.8 | Define and Maintain Role-Based Access Control | mitigates | T1218.007 | Msiexec |
Comments
Role-based access control (RBAC) can restrict execution of Msiexec.exe to privileged accounts or groups with an authorized operational need. Enforcing this entitlement reduces opportunities for adversaries to abuse Windows Installer for proxy execution.
References
|
| CIS-6.8 | Define and Maintain Role-Based Access Control | mitigates | T1525 | Implant Internal Image |
Comments
Role-based access control (RBAC) can limit permissions to create, modify, or publish platform and container images to authorized roles. Enforcing these permissions reduces an adversary's ability to implant malicious images within enterprise repositories.
References
|
| CIS-6.8 | Define and Maintain Role-Based Access Control | mitigates | T1538 | Cloud Service Dashboard |
Comments
Role-based access control (RBAC) can enforce least-privilege dashboard visibility so users can access only the cloud resources required for their assigned roles. This limits the information and resources exposed through a cloud service dashboard when an account is compromised.
References
|
| CIS-6.8 | Define and Maintain Role-Based Access Control | mitigates | T1548.002 | Bypass User Account Control |
Comments
Role-based access control (RBAC) can restrict local administrator membership to authorized roles. Removing unnecessary administrative rights reduces the accounts from which adversaries can leverage UAC bypass techniques to obtain elevated privileges.
References
|
| CIS-6.8 | Define and Maintain Role-Based Access Control | mitigates | T1548.003 | Sudo and Sudo Caching |
Comments
Role-based access control (RBAC) can enforce which users or groups are authorized for sudo privileges and which elevated commands they may run. Restricting these entitlements limits the identities and operations available for privilege elevation through sudo.
References
|
| CIS-6.8 | Define and Maintain Role-Based Access Control | mitigates | T1556.004 | Network Device Authentication |
Comments
Role-based access control (RBAC) can restrict network-device administrator privileges to narrowly scoped authorized roles. Enforcing least-privilege administrative access reduces the identities capable of modifying network-device authentication mechanisms.
References
|
| CIS-6.5 | Require MFA for Administrative Access | mitigates | T1556.008 | Network Provider DLL |
Comments
Integrate multi-factor authentication (MFA) for administrative accounts to reduce the risk of adversaries using compromised privileged credentials to register malicious network provider dynamic link libraries (DLLs) to capture cleartext user credentials during the authentication process.
References
|
| CIS-6.5 | Require MFA for Administrative Access | mitigates | T1556.007 | Hybrid Identity |
Comments
Integrate multi-factor authentication (MFA) for administrative accounts to reduce the risk of adversaries using compromised privileged credentials (e.g., hybrid identity environment admin, synchronization service, cloud tenant) to patch, modify, or otherwise backdoor cloud authentication processes
References
|
| CIS-6.5 | Require MFA for Administrative Access | mitigates | T1556.006 | Multi-Factor Authentication |
Comments
Integrate multi-factor authentication (MFA) for administrative accounts to reduce the risk of adversaries using compromised privileged credentials to disable or modify MFA mechanisms and enable persistent access to compromised accounts.
References
|
| CIS-6.5 | Require MFA for Administrative Access | mitigates | T1556.005 | Reversible Encryption |
Comments
Integrate multi-factor authentication (MFA) for administrative accounts to reduce the risk of adversaries using compromised privileged credentials (e.g., domain/identity policy administrator, local security policy administrator) to abuse Active Directory encryption properties and gain access to credentials on Windows systems.
References
|
| CIS-6.5 | Require MFA for Administrative Access | mitigates | T1556.004 | Network Device Authentication |
Comments
Integrate multi-factor authentication (MFA) for administrative accounts to reduce the risk of adversaries using compromised privileged credentials to bypass of native authentication mechanisms for tenant/device management accounts on network devices.
References
|
| CIS-6.5 | Require MFA for Administrative Access | mitigates | T1556.003 | Pluggable Authentication Modules |
Comments
Integrate multi-factor authentication (MFA) for administrative accounts to reduce the risk of adversaries using compromised privileged credentials to modify pluggable authentication modules (PAM) to access user credentials or enable otherwise unwarranted access to accounts.
References
|
| CIS-6.5 | Require MFA for Administrative Access | mitigates | T1556.002 | Password Filter DLL |
Comments
Integrate multi-factor authentication (MFA) for administrative accounts to reduce the risk of adversaries using compromised privileged credentials to register malicious password filter dynamic link libraries (DLLs) into the authentication process.
References
|
| CIS-6.5 | Require MFA for Administrative Access | mitigates | T1556.001 | Domain Controller Authentication |
Comments
Integrate multi-factor authentication (MFA) for administrative accounts to reduce the risk of adversaries using compromised privileged credentials to patch the authentication process on a domain controller to bypass the typical authentication mechanisms and enable access to accounts.
References
|
| CIS-6.5 | Require MFA for Administrative Access | mitigates | T1556 | Modify Authentication Process |
Comments
Integrate multi-factor authentication (MFA) for administrative accounts to reduce the risk of adversaries using compromised privileged credentials to modify authentication processes or mechanisms.
References
|
| CIS-6.5 | Require MFA for Administrative Access | mitigates | T1110.004 | Credential Stuffing |
Comments
Implement multi-factor authentication (MFA) for administrative accounts to help prevent adversaries from using credentials obtained from breach dumps to gain access to admin accounts through credential overlap.
References
|
| CIS-6.5 | Require MFA for Administrative Access | mitigates | T1110.003 | Password Spraying |
Comments
Implement multi-factor authentication (MFA) for administrative accounts to help prevent adversaries from using commonly used passwords to attempt to acquire valid admin credentials.
References
|
| CIS-6.5 | Require MFA for Administrative Access | mitigates | T1110.002 | Password Cracking |
Comments
Implement multi-factor authentication (MFA) for administrative accounts to help prevent adversaries from using password cracking to recover admin credentials.
References
|
| CIS-6.5 | Require MFA for Administrative Access | mitigates | T1110.001 | Password Guessing |
Comments
Implement multi-factor authentication (MFA) for administrative accounts to help prevent adversaries from using password guessing to access admin accounts.
References
|
| CIS-6.5 | Require MFA for Administrative Access | mitigates | T1110 | Brute Force |
Comments
Implement multi-factor authentication (MFA) for administrative accounts to help prevent adversaries from brute forcing admin credentials.
References
|
| CIS-6.5 | Require MFA for Administrative Access | mitigates | T1072 | Software Deployment Tools |
Comments
Implement multi-factor authentication (MFA) for administrative accounts to provide system and access isolation for critical network systems.
References
|
| CIS-6.5 | Require MFA for Administrative Access | mitigates | T1556.009 | Conditional Access Policies |
Comments
Integrate multi-factor authentication (MFA) for administrative accounts to reduce the risk of adversaries using compromised privileged credentials to disable or modify conditional access policies.
References
|
| CIS-6.8 | Define and Maintain Role-Based Access Control | mitigates | T1550.003 | Pass the Ticket |
Comments
Using role-based access control (RBAC) to prevent domain users from being local administrators on multiple systems can help limit adversaries’ ability to reuse Kerberos tickets for lateral movement.
References
|
| CIS-6.8 | Define and Maintain Role-Based Access Control | mitigates | T1550.002 | Pass the Hash |
Comments
Using role-based access control (RBAC) to prevent domain users from being local administrators on multiple systems can help limit adversaries’ ability to reuse NTLM hashes for lateral movement.
References
|
| CIS-6.8 | Define and Maintain Role-Based Access Control | mitigates | T1550 | Use Alternate Authentication Material |
Comments
Using role-based access control (RBAC) to enforce least privilege and prevent domain users from holding local-administrator rights across multiple systems can help limit an adversary’s ability to use alternate authentication material for lateral movement.
References
|
| CIS-6.8 | Define and Maintain Role-Based Access Control | mitigates | T1552.007 | Container API |
Comments
Enforce authentication and role-based access control (RBAC) on the container API to restrict users to the least privileges required to help prevent adversaries from gathering credentials via APIs within a containers environment.
References
|
| CIS-6.8 | Define and Maintain Role-Based Access Control | mitigates | T1537 | Transfer Data to Cloud Account |
Comments
Using role-based access control (RBAC) to limit user-account and identity access management (IAM) permissions to the least privileges required can help prevent adversaries from transferring organizational data to cloud accounts they control.
References
|
| CIS-6.8 | Define and Maintain Role-Based Access Control | mitigates | T1199 | Trusted Relationship |
Comments
Implement role-based access control (RBAC) to manage accounts and permissions used by parties in trusted relationships to minimize potential abuse by the party or if the party is compromised by an adversary.
References
|
| CIS-6.8 | Define and Maintain Role-Based Access Control | mitigates | T1569.003 | Systemctl |
Comments
Implement role-based access control (RBAC) to ensure lower-privileged users cannot create or interact with higher-privileged system services to help prevent adversaries from abusing systemctl to execute commands or programs.
References
|
| CIS-6.8 | Define and Maintain Role-Based Access Control | mitigates | T1569.001 | Launchctl |
Comments
Implement role-based access control (RBAC) to ensure lower-privileged users cannot create or interact with higher-privileged system services to help prevent adversaries from abusing launchctl to execute commands or programs.
References
|
| CIS-6.8 | Define and Maintain Role-Based Access Control | mitigates | T1047 | Windows Management Instrumentation |
Comments
Using role-based access control (RBAC) to restrict remote WMI access to authorized administrative roles can help prevent adversaries from abusing Windows Management Instrumentation (WMI) to execute malicious commands and payloads.
References
|
| CIS-6.8 | Define and Maintain Role-Based Access Control | mitigates | T1195 | Supply Chain Compromise |
Comments
Implement role-based access control (RBAC) to ensure software and development tools run with the lowest necessary privileges to help limit an adversary’s ability to propagate or perform unauthorized actions in the event of a supply chain compromise.
References
|
| CIS-6.8 | Define and Maintain Role-Based Access Control | mitigates | T1528 | Steal Application Access Token |
Comments
Enforce role-based access control (RBAC) to limit accounts to the least privileges they require to help prevent adversaries from obtaining or abusing application access tokens.
References
|
| CIS-6.8 | Define and Maintain Role-Based Access Control | mitigates | T1489 | Service Stop |
Comments
Using role-based access control (RBAC) to limit user accounts and groups so that only authorized administrators can interact with service changes and service configurations can help prevent adversaries from stopping or disabling services.
References
|
| CIS-6.8 | Define and Maintain Role-Based Access Control | mitigates | T1648 | Serverless Execution |
Comments
Using role-based access control (RBAC) to limit permissions to create, modify, or run serverless resources only to users that explicitly require them can help prevent adversaries from abusing serverless computing, integration, and automation services to execute arbitrary code in cloud environments.
References
|
| CIS-6.8 | Define and Maintain Role-Based Access Control | mitigates | T1505.003 | Web Shell |
Comments
Using role-based access control (RBAC) to limit permissions to upload, create, or modify content in web-server application directories to users with a legitimate need can help prevent adversaries from backdooring web servers with web shells.
References
|
| CIS-6.8 | Define and Maintain Role-Based Access Control | mitigates | T1505 | Server Software Component |
Comments
Using role-based access control (RBAC) to limit permissions to add or modify server software components to users with a legitimate need can help prevent adversaries from abusing legitimate extensible development features of servers.
References
|
| CIS-6.8 | Define and Maintain Role-Based Access Control | mitigates | T1021.001 | Remote Desktop Protocol |
Comments
Using role-based access control (RBAC) to limit Remote Desktop Users group membership and Remote Desktop Protocol (RDP) permissions to users with a legitimate need can help prevent adversaries from using RDP for lateral movement.
References
|
| CIS-6.8 | Define and Maintain Role-Based Access Control | mitigates | T1053.006 | Systemd Timers |
Comments
Using role-based access control (RBAC) to limit permissions to create or modify scheduled tasks via system utilities to authorized administrator roles to help prevent adversaries from abusing task scheduling functionality.
References
|
| CIS-6.8 | Define and Maintain Role-Based Access Control | mitigates | T1053.003 | Cron |
Comments
Using role-based access control (RBAC) to limit permissions to create or modify scheduled tasks via the cron utility to authorized administrator roles to help prevent adversaries from abusing task scheduling functionality.
References
|
| CIS-6.8 | Define and Maintain Role-Based Access Control | mitigates | T1053 | Scheduled Task/Job |
Comments
Using role-based access control (RBAC) to limit permissions to create or modify scheduled tasks and jobs on remote systems to authorized administrator roles to help prevent adversaries from abusing task scheduling functionality.
References
|
| CIS-6.8 | Define and Maintain Role-Based Access Control | mitigates | T1053.002 | At |
Comments
Using role-based access control (RBAC) to limit permissions to create or modify scheduled tasks via the at utility to authorized administrator roles to help prevent adversaries from abusing task scheduling functionality.
References
|
| CIS-6.8 | Define and Maintain Role-Based Access Control | mitigates | T1053.005 | Scheduled Task |
Comments
Using role-based access control (RBAC) to limit permissions to create or modify scheduled tasks on remote systems to authorized administrator roles to help prevent adversaries from abusing task scheduling functionality.
References
|
| CIS-6.8 | Define and Maintain Role-Based Access Control | mitigates | T1021.004 | SSH |
Comments
Using role-based access control (RBAC) to limit SSH access and permitted commands to users with a legitimate need can help prevent adversaries from using SSH for lateral movement.
References
|
| CIS-6.8 | Define and Maintain Role-Based Access Control | mitigates | T1053.007 | Container Orchestration Job |
Comments
Using role-based access control (RBAC) to limit permissions to create or modify scheduled tasks via container orchestration tools to authorized administrator roles to help prevent adversaries from abusing task scheduling functionality.
References
|
| CIS-6.8 | Define and Maintain Role-Based Access Control | mitigates | T1072 | Software Deployment Tools |
Comments
Using role-based access control (RBAC) to limit access to and use of centralized software suites to a limited number of authorized administrators with a verified business need can help prevent adversaries from accessing and abusing software deployment tools.
References
|
| CIS-6.8 | Define and Maintain Role-Based Access Control | mitigates | T1021 | Remote Services |
Comments
Using role-based access control (RBAC) to limit which accounts can use remote services and restrict the commands or resources available to those accounts to help prevent adversaries from using remote services for lateral movement.
References
|
| CIS-6.8 | Define and Maintain Role-Based Access Control | mitigates | T1563.001 | SSH Hijacking |
Comments
Using role-based access control (RBAC) to limit remote user permissions to necessary users to help prevent adversaries from commandeering these sessions.
References
|
| CIS-6.8 | Define and Maintain Role-Based Access Control | mitigates | T1563.002 | RDP Hijacking |
Comments
Using role-based access control (RBAC) to limit remote user permissions to necessary users to help prevent adversaries from commandeering these sessions.
References
|
| CIS-6.8 | Define and Maintain Role-Based Access Control | mitigates | T1563 | Remote Service Session Hijacking |
Comments
Using role-based access control (RBAC) to limit remote user permissions to necessary users to help prevent adversaries from commandeering these sessions.
References
|
| CIS-6.8 | Define and Maintain Role-Based Access Control | mitigates | T1677 | Poisoned Pipeline Execution |
Comments
Using role-based access control (RBAC) to limit write access to internal repositories and CI/CD pipeline permissions to users and services with a legitimate need can help prevent adversaries from modifying pipelines to execute malicious code.
References
|
| CIS-6.8 | Define and Maintain Role-Based Access Control | mitigates | T1566.003 | Spearphishing via Service |
Comments
Using role-based access control (RBAC) to limit third-party messaging and collaboration-service account privileges to users with a legitimate need can help prevent adversaries from abusing compromised service accounts for spearphishing.
References
|
| CIS-6.8 | Define and Maintain Role-Based Access Control | mitigates | T1566.002 | Spearphishing Link |
Comments
Using role-based access control (RBAC) to apply limitations on which roles can grant consent to third-party applications can help prevent users from granting consent to unfamiliar or unverified third-party applications through spearphishing links.
References
|
| CIS-6.8 | Define and Maintain Role-Based Access Control | mitigates | T1566.001 | Spearphishing Attachment |
Comments
Using role-based access control (RBAC) to limit file-opening and execution permissions to only the accounts that require them can help reduce the impact of malicious email attachments by preventing unauthorized execution or spread of malware.
References
|
| CIS-6.8 | Define and Maintain Role-Based Access Control | mitigates | T1040 | Network Sniffing |
Comments
In cloud environments, using role-based access control (RBAC) to ensure that users are not granted permissions to create or modify traffic mirrors unless explicitly required can help prevent adversaries from capturing network traffic.
References
|
| CIS-6.8 | Define and Maintain Role-Based Access Control | mitigates | T1666 | Modify Cloud Resource Hierarchy |
Comments
Using role-based access control (RBAC) to limit permissions to add, delete, or modify cloud resource groups and hierarchy structures to authorized roles can help prevent adversaries from evading organizational guardrails and cloud security policies.
References
|
| CIS-6.8 | Define and Maintain Role-Based Access Control | mitigates | T1578.005 | Modify Cloud Compute Configurations |
Comments
Using role-based access control (RBAC) to limit permissions to modify cloud compute settings, quotas, and tenant-level configurations to authorized roles can help prevent adversaries from altering infrastructure resources or bypassing restrictions.
References
|
| CIS-6.8 | Define and Maintain Role-Based Access Control | mitigates | T1578.003 | Delete Cloud Instance |
Comments
Using role-based access control (RBAC) to limit permissions to delete cloud instances to authorized roles can help prevent adversaries from removing instances to destroy evidence of malicious activity.
References
|
| CIS-6.8 | Define and Maintain Role-Based Access Control | mitigates | T1578.002 | Create Cloud Instance |
Comments
Using role-based access control (RBAC) to limit permissions to create cloud instances to authorized roles can help prevent adversaries from deploying new instances to evade defenses or conduct unauthorized activity.
References
|
| CIS-6.8 | Define and Maintain Role-Based Access Control | mitigates | T1578.001 | Create Snapshot |
Comments
Using role-based access control (RBAC) to limit permissions to create cloud snapshots and backups to authorized roles can help prevent adversaries from creating copies of cloud resources for unauthorized access or data collection.
References
|
| CIS-6.8 | Define and Maintain Role-Based Access Control | mitigates | T1578 | Modify Cloud Compute Infrastructure |
Comments
Using role-based access control (RBAC) to limit permissions to create, delete, and modify cloud compute infrastructure to authorized roles can help prevent adversaries from altering cloud resources to evade defenses or gain unauthorized access.
References
|
| CIS-6.8 | Define and Maintain Role-Based Access Control | mitigates | T1021.008 | Direct Cloud VM Connections |
Comments
Using role-based access control (RBAC) to limit direct cloud-native VM connection permissions to users with a legitimate need can help prevent adversaries from accessing cloud compute infrastructure for lateral movement.
References
|
| CIS-6.8 | Define and Maintain Role-Based Access Control | mitigates | T1556.006 | Multi-Factor Authentication |
Comments
Using role-based access control (RBAC) to limit permissions to enroll, disable, or modify multi-factor authentication (MFA) methods and policies to authorized administrative roles can help prevent adversaries from weakening MFA protections on compromised accounts.
References
|
| CIS-6.8 | Define and Maintain Role-Based Access Control | mitigates | T1556 | Modify Authentication Process |
Comments
Using role-based access control (RBAC) to limit permissions to modify authentication processes and identity-provider settings to authorized administrative roles can help prevent adversaries from altering authentication controls to gain unauthorized access.
References
|
| CIS-6.8 | Define and Maintain Role-Based Access Control | mitigates | T1654 | Log Enumeration |
Comments
Using role-based access control (RBAC) to limit permissions to access and export sensitive system and service logs to privileged roles can help prevent adversaries from enumerating logs for valuable information.
References
|
| CIS-6.8 | Define and Maintain Role-Based Access Control | mitigates | T1490 | Inhibit System Recovery |
Comments
Using role-based access control (RBAC) to limit permissions to backups to only required users with a legitimate need can help prevent adversaries from deleting or removing built-in data and turning off services designed to aid in the recovery of a corrupted system.
References
|
| CIS-6.8 | Define and Maintain Role-Based Access Control | mitigates | T1574.012 | COR_PROFILER |
Comments
Using role-based access control (RBAC) to limit permissions to modify COR_PROFILER environment variables and related .NET configuration settings to users with a legitimate need can help prevent adversaries from loading malicious DLLs into .NET processes.
References
|
| CIS-6.8 | Define and Maintain Role-Based Access Control | mitigates | T1574.010 | Services File Permissions Weakness |
Comments
Using role-based access control (RBAC) to limit permissions to modify service executables and their file paths to users with a legitimate need can help prevent adversaries from replacing service binaries with malicious payloads.
References
|
| CIS-6.8 | Define and Maintain Role-Based Access Control | mitigates | T1574.005 | Executable Installer File Permissions Weakness |
Comments
Using role-based access control (RBAC) to limit permissions to modify installer executables and their file paths to users with a legitimate need can help prevent adversaries from replacing installer binaries with malicious payloads.
References
|
| CIS-6.8 | Define and Maintain Role-Based Access Control | mitigates | T1574 | Hijack Execution Flow |
Comments
Using role-based access control (RBAC) to limit permissions to modify service configurations, registry settings, and protected file paths to users with a legitimate need can help prevent adversaries from hijacking execution flow.
References
|
| CIS-6.8 | Define and Maintain Role-Based Access Control | mitigates | T1530 | Data from Cloud Storage |
Comments
Using role-based access control (RBAC) to limit user groups and roles for access to cloud storage to only users with a legitimate need can help prevent adversaries from accessing and collecting data from cloud storage solutions.
References
|
| CIS-6.8 | Define and Maintain Role-Based Access Control | mitigates | T1606 | Forge Web Credentials |
Comments
Using role-based access control (RBAC) to limit access to identity infrastructure and token-issuance permissions to narrowly scoped privileged roles reduces opportunities to forge credential materials.
References
|
| CIS-6.8 | Define and Maintain Role-Based Access Control | mitigates | T1657 | Financial Theft |
Comments
Using role-based access control (RBAC) to limit sensitive financial transactions and approval privileges to narrowly scoped roles can mitigate use of a compromised account to initiate or authorize unauthorized payments.
References
|
| CIS-6.8 | Define and Maintain Role-Based Access Control | mitigates | T1556.009 | Conditional Access Policies |
Comments
Using role-based access control (RBAC) to limit permissions to modify conditional access policies to authorized administrative roles can help prevent adversaries from removing multi-factor authentication (MFA) requirements or adding exclusions that enable persistent access.
References
|
| CIS-6.8 | Define and Maintain Role-Based Access Control | mitigates | T1606.002 | SAML Tokens |
Comments
Using role-based access control (RBAC) to limit access to identity infrastructure and token-issuance permissions to narrowly scoped privileged roles reduces opportunities to forge SAML tokens.
References
|
| CIS-6.8 | Define and Maintain Role-Based Access Control | mitigates | T1048 | Exfiltration Over Alternative Protocol |
Comments
Using role-based access control (RBAC) to limit user groups and roles for access to cloud storage systems and objects to only users with a legitimate need can help prevent adversaries from exfiltrating data from cloud storage.
References
|
| CIS-6.8 | Define and Maintain Role-Based Access Control | mitigates | T1484.001 | Group Policy Modification |
Comments
Role-based access control (RBAC) can be used to limit which users and computers can access Group Policy Objects (GPOs), helping to prevent adversaries from modifying GPOs.
References
|
| CIS-6.8 | Define and Maintain Role-Based Access Control | mitigates | T1484 | Domain or Tenant Policy Modification |
Comments
Role-based access control (RBAC) can be used to limit which users and computers can access domain and identity tenant settings, helping to prevent adversaries from modifying their configuration settings.
References
|
| CIS-6.8 | Define and Maintain Role-Based Access Control | mitigates | T1610 | Deploy Container |
Comments
Enforcing role-based access control (RBAC) to limit container dashboard access to only necessary users can prevent adversaries from deploying a container into an environment.
References
|
| CIS-6.8 | Define and Maintain Role-Based Access Control | mitigates | T1213.006 | Databases |
Comments
Using role-based access control (RBAC) to limit database access to only authorized users helps prevent adversaries from leveraging these databases to mine valuable information.
References
|
| CIS-6.8 | Define and Maintain Role-Based Access Control | mitigates | T1213.001 | Confluence |
Comments
Using role-based access control (RBAC) to limit Confluence repository access to only authorized users helps prevent adversaries from leveraging these repositories to mine valuable information.
References
|
| CIS-6.8 | Define and Maintain Role-Based Access Control | mitigates | T1484.002 | Trust Modification |
Comments
In cloud environments, role-based access control (RBAC) can be used to limit permissions to create new identity providers to only those accounts that require them. This can prevent adversaries from adding new domain trusts, modifying the properties of existing domain trusts, or otherwise changing the configuration of trust relationships between domains and tenants.
References
|
| CIS-6.8 | Define and Maintain Role-Based Access Control | mitigates | T1213.004 | Customer Relationship Management Software |
Comments
Using role-based access control (RBAC) to limit Customer Relationship Management (CRM) software access to only authorized users helps prevent adversaries from leveraging CRM software to mine valuable information.
References
|
| CIS-6.8 | Define and Maintain Role-Based Access Control | mitigates | T1213.003 | Code Repositories |
Comments
Using role-based access control (RBAC) to limit code repository access to only authorized users helps prevent adversaries from leveraging these repositories to mine valuable information.
References
|
| CIS-6.8 | Define and Maintain Role-Based Access Control | mitigates | T1213 | Data from Information Repositories |
Comments
Using role-based access control (RBAC) to limit information repository access to only authorized users helps prevent adversaries from leveraging these repositories to mine valuable information.
References
|
| CIS-6.8 | Define and Maintain Role-Based Access Control | mitigates | T1543 | Create or Modify System Process |
Comments
Using role-based access control (RBAC) to ensure only authorized administrator roles can interact with system-level process changes and service configurations helps prevent adversaries from leveraging this functionality to establish persistence or escalate privileges.
References
|
| CIS-6.8 | Define and Maintain Role-Based Access Control | mitigates | T1485.001 | Lifecycle-Triggered Deletion |
Comments
In cloud environments, using role-based access control (RBAC) to limit user permissions to modify cloud bucket lifecycle policies to only users with a legitimate need can help prevent adversaries from destroying all objects stored within buckets.
References
|
| CIS-6.8 | Define and Maintain Role-Based Access Control | mitigates | T1485 | Data Destruction |
Comments
In cloud environments, using role-based access control (RBAC) to limit user permissions to modify cloud bucket lifecycle policies to only users with a legitimate need can help prevent adversaries from destroying data and files.
References
|
| CIS-6.8 | Define and Maintain Role-Based Access Control | mitigates | T1543.005 | Container Service |
Comments
Using role-based access control (RBAC) to limit user access to utilities such as docker to only users with a legitimate need helps prevent adversaries from creating or modifying container or cluster management tools to establish persistence or escalate privileges.
References
|
| CIS-6.8 | Define and Maintain Role-Based Access Control | mitigates | T1543.004 | Launch Daemon |
Comments
Using role-based access control (RBAC) to ensure only authorized administrator roles can create new Launch Daemons helps prevent adversaries from creating or modifying Launch Daemons to establish persistence or escalate privileges.
References
|
| CIS-6.8 | Define and Maintain Role-Based Access Control | mitigates | T1543.003 | Windows Service |
Comments
Using role-based access control (RBAC) to ensure only authorized administrator roles can interact with service changes and service configurations helps prevent adversaries from leveraging this functionality to establish persistence or escalate privileges.
References
|
| CIS-6.8 | Define and Maintain Role-Based Access Control | mitigates | T1543.002 | Systemd Service |
Comments
Using role-based access control (RBAC) to limit user access to system utilities to only users with a legitimate need helps prevent adversaries from creating or modifying systemd services to establish persistence or escalate privileges.
References
|
| CIS-6.8 | Define and Maintain Role-Based Access Control | mitigates | T1213.002 | Sharepoint |
Comments
Using role-based access control (RBAC) to limit SharePoint repository access to only authorized users helps prevent adversaries from leveraging these repositories to mine valuable information.
References
|
| CIS-6.8 | Define and Maintain Role-Based Access Control | mitigates | T1134.002 | Create Process with Token |
Comments
Role-based access control (RBAC) can help mitigate access token manipulation by restricting which roles are allowed to create new processes with tokens and limiting privileges to a small set of tightly controlled roles.
References
|
| CIS-6.8 | Define and Maintain Role-Based Access Control | mitigates | T1609 | Container Administration Command |
Comments
Enforcing authentication and role-based access control (RBAC) on the container administration service to restrict users to the least privileges required can help prevent adversaries from abusing the service to execute commands within the container.
References
|
| CIS-6.8 | Define and Maintain Role-Based Access Control | mitigates | T1059.008 | Network Device CLI |
Comments
Role-based access control (RBAC) helps mitigate this technique by enforcing least privilege and command authorization on network device CLI access, limiting which roles can run perform authorization changes.
References
|
| CIS-6.8 | Define and Maintain Role-Based Access Control | mitigates | T1619 | Cloud Storage Object Discovery |
Comments
Role-based access control (RBAC) can help mitigate discovery of cloud storage objects by limiting cloud storage list permissions to narrowly scoped roles, reducing who can enumerate storage objects for discovery.
References
|
| CIS-6.8 | Define and Maintain Role-Based Access Control | mitigates | T1580 | Cloud Infrastructure Discovery |
Comments
Role-based access control (RBAC) can help mitigate discovery of cloud infrastructure and resources by limiting which roles can access, manage, or query cloud infrastructure metadata and enforcing who can see and do what in cloud service dashboards.
References
|
| CIS-6.8 | Define and Maintain Role-Based Access Control | mitigates | T1185 | Browser Session Hijacking |
Comments
Role-based access control (RBAC) can help mitigate browser session hijacking techniques by enforcing least privilege so that hijacked browser sessions are associated with minimally scoped roles, limiting what an adversary can do with a captured session.
References
|
| CIS-6.8 | Define and Maintain Role-Based Access Control | mitigates | T1547.012 | Print Processors |
Comments
Role-based access control (RBAC) can help mitigate this technique by limiting which roles can load or unload device drivers by disabling SeLoadDriverPrivilege.
References
|
| CIS-6.8 | Define and Maintain Role-Based Access Control | mitigates | T1613 | Container and Resource Discovery |
Comments
Role-based access control (RBAC) can help mitigate this technique by tightly controlling which roles can view or query container APIs and dashboards and restricting discovery of cluster resources to narrowly scoped roles.
References
|
| CIS-6.8 | Define and Maintain Role-Based Access Control | mitigates | T1547.009 | Shortcut Modification |
Comments
Role-based access control (RBAC) can help mitigate this technique by limiting shortcut creation and modification to narrowly scoped roles.
References
|
| CIS-6.8 | Define and Maintain Role-Based Access Control | mitigates | T1547.006 | Kernel Modules and Extensions |
Comments
Role-based access control (RBAC) can help mitigate this technique by limiting which roles can load or configure kernel modules and extensions to tightly controlled admin roles.
References
|
| CIS-6.8 | Define and Maintain Role-Based Access Control | mitigates | T1547.004 | Winlogon Helper DLL |
Comments
Role-based access control (RBAC) can help mitigate this technique by restricting Winlogon configuration changes to a small set of tightly controlled admin roles.
References
|
| CIS-6.8 | Define and Maintain Role-Based Access Control | mitigates | T1547.013 | XDG Autostart Entries |
Comments
Role-based access control (RBAC) can help mitigate this technique by limiting which roles can can create and modify XDG autostart entries to narrowly scoped privileged roles.
References
|
| CIS-6.8 | Define and Maintain Role-Based Access Control | mitigates | T1098.004 | SSH Authorized Keys |
Comments
Role-based access control (RBAC) can help mitigate account manipulation by limiting which roles in cloud environments are allowed to modify SSH authorized_keys files and ensuring that only users who explicitly require the permissions to update instance metadata or configurations can do so.
References
|
| CIS-6.8 | Define and Maintain Role-Based Access Control | mitigates | T1197 | BITS Jobs |
Comments
Role-based access control (RBAC) can help mitigate abuse of BITS jobs by limiting access to the BITS interface to specific user roles or groups.
References
|
| CIS-6.8 | Define and Maintain Role-Based Access Control | mitigates | T1098.003 | Additional Cloud Roles |
Comments
Role-based access control (RBAC) can help mitigate account manipulation by limiting which roles are allowed to create or modify accounts and ensuring that low-privileged users do not have permissions to add permissions to accounts or update IAM policies.
References
|
| CIS-6.8 | Define and Maintain Role-Based Access Control | mitigates | T1098.001 | Additional Cloud Credentials |
Comments
Role-based access control (RBAC) can help mitigate account manipulation by limiting which roles are allowed to create or modify accounts and ensuring that low-privileged users do not have permissions to add access keys to accounts.
References
|
| CIS-6.8 | Define and Maintain Role-Based Access Control | mitigates | T1098 | Account Manipulation |
Comments
Role-based access control (RBAC) can help mitigate account manipulation by limiting which roles are allowed to create or modify accounts and ensuring that low-privileged users do not have permissions to modify accounts or account-related policies.
References
|
| CIS-6.8 | Define and Maintain Role-Based Access Control | mitigates | T1087.004 | Cloud Account |
Comments
Role-based access control (RBAC) can help mitigate account discovery by limiting what each role can see or query.
References
|
| CIS-6.8 | Define and Maintain Role-Based Access Control | mitigates | T1087 | Account Discovery |
Comments
Role-based access control (RBAC) can help mitigate account discovery by limiting what each role can see or query.
References
|
| CIS-6.8 | Define and Maintain Role-Based Access Control | mitigates | T1098.006 | Additional Container Cluster Roles |
Comments
Role-based access control (RBAC) can help mitigate account manipulation by limiting which roles are allowed to add additional roles or permissions and ensuring that low-privileged accounts do not have permissions to add permissions to accounts or to update container cluster roles.
References
|
| CIS-6.8 | Define and Maintain Role-Based Access Control | mitigates | T1546.003 | Windows Management Instrumentation Event Subscription |
Comments
Using role-based access control (RBAC) to restrict or disallow user groups allowed to connect to WMI can help prevent adversaries from maliciously using WMI event subscription capabilities.
References
|
| CIS-6.8 | Define and Maintain Role-Based Access Control | mitigates | T1134.001 | Token Impersonation/Theft |
Comments
Role-based access control (RBAC) can help mitigate access token manipulation by restricting which roles are allowed to create or impersonate tokens and limiting privileges to a small set of tightly controlled roles.
References
|
| CIS-6.8 | Define and Maintain Role-Based Access Control | mitigates | T1134 | Access Token Manipulation |
Comments
Role-based access control (RBAC) can help mitigate access token manipulation by restricting which roles are allowed to create or modify tokens and limiting privileges to a small set of tightly controlled roles.
References
|
| CIS-6.8 | Define and Maintain Role-Based Access Control | mitigates | T1548.005 | Temporary Elevated Cloud Access |
Comments
Role-based access control (RBAC), implemented under least privilege and access enforcement controls, helps mitigate this technique by limiting which identities can use elevation mechanisms and what they can elevate to.
References
|
| CIS-6.8 | Define and Maintain Role-Based Access Control | mitigates | T1548 | Abuse Elevation Control Mechanism |
Comments
Role-based access control (RBAC), implemented under least privilege and access enforcement controls, helps mitigate this technique by limiting which identities can use elevation mechanisms and what they can elevate to.
References
|
| CIS-6.8 | Define and Maintain Role-Based Access Control | mitigates | T1134.003 | Make and Impersonate Token |
Comments
Role-based access control (RBAC) can help mitigate access token manipulation by restricting which roles are allowed to create and impersonate tokens and limiting privileges to a small set of tightly controlled roles.
References
|
| CIS-6.5 | Require MFA for Administrative Access | mitigates | T1078.004 | Cloud Accounts |
Comments
Implement multi-factor authentication (MFA) for administrative accounts to help prevent unauthorized access, even if credentials are compromised.
References
|
| CIS-6.5 | Require MFA for Administrative Access | mitigates | T1078.003 | Local Accounts |
Comments
Implement multi-factor authentication (MFA) for administrative accounts to help prevent unauthorized access, even if credentials are compromised.
References
|
| CIS-6.5 | Require MFA for Administrative Access | mitigates | T1078 | Valid Accounts |
Comments
Implement multi-factor authentication (MFA) for administrative accounts to help prevent unauthorized access, even if credentials are compromised.
References
|
| CIS-6.5 | Require MFA for Administrative Access | mitigates | T1078.002 | Domain Accounts |
Comments
Implement multi-factor authentication (MFA) for administrative accounts to help prevent unauthorized access, even if credentials are compromised.
References
|
| CIS-6.2 | Establish an Access Revoking Process | mitigates | T1078 | Valid Accounts |
Comments
Disabling accounts that are no longer needed immediately upon termination, rights revocation, or role change prevents adversaries from gaining and using those accounts.
References
|
| CIS-6.5 | Require MFA for Administrative Access | mitigates | T1098 | Account Manipulation |
Comments
Using multi-factor authentication for privileged administrative access reduces the success of adversary attempts to maintain or elevate access using compromised credentials.
References
|
| CIS-6.5 | Require MFA for Administrative Access | mitigates | T1599 | Network Boundary Bridging |
Comments
Using multi-factor authentication on accounts that administer network devices helps prevent adversaries from using compromised credentials to reconfigure or bypass network boundaries by limiting their ability to log in.
References
|
| CIS-6.5 | Require MFA for Administrative Access | mitigates | T1601.002 | Downgrade System Image |
Comments
Using multi-factor authentication on administrator accounts helps prevent adversaries from using compromised credentials to install older operating systems by limiting their ability to log in.
References
|
| CIS-6.5 | Require MFA for Administrative Access | mitigates | T1601.001 | Patch System Image |
Comments
Using multi-factor authentication on administrator accounts helps prevent adversaries from using compromised credentials to modify system images and introduce new capabilities or weaken defenses by limiting their ability to log in.
References
|
| CIS-6.5 | Require MFA for Administrative Access | mitigates | T1601 | Modify System Image |
Comments
Using multi-factor authentication on administrator accounts helps prevent adversaries from using compromised credentials to modify system images by limiting their ability to log in.
References
|
| CIS-6.5 | Require MFA for Administrative Access | mitigates | T1556.004 | Network Device Authentication |
Comments
Requiring multi-factor authentication on administrator accounts ensures that adversaries cannot rely on a single implanted or backdoor password to gain access to network devices without also satisfying an independent second factor.
References
|
| CIS-6.2 | Establish an Access Revoking Process | mitigates | T1555.005 | Password Managers |
Comments
Inactive accounts may be targeted by attackers to gain unauthorized access. Disabling inactive accounts can prevent attackers from obtaining the user credentials from third-party password managers.
References
|
| CIS-6.5 | Require MFA for Administrative Access | mitigates | T1098.005 | Device Registration |
Comments
Requiring multi-factor authentication (MFA) to register devices in Entra ID, configuring MFA systems to disallow enrolling new devices for inactive accounts, and using conditional access policies to restrict initial MFA device enrollment to trusted locations or devices reduces the success of adversary attempts to add additional devices to an adversary-controlled account.
References
|
| CIS-6.5 | Require MFA for Administrative Access | mitigates | T1136.002 | Domain Account |
Comments
Using multi-factor authentication for administrative accounts reduces the likelihood that adversaries can use a compromised admin credential to sign in and create additional accounts by preventing access at login.
References
|
| CIS-6.5 | Require MFA for Administrative Access | mitigates | T1136.001 | Local Account |
Comments
Using multi-factor authentication for administrative accounts reduces the likelihood that adversaries can use a compromised admin credential to sign in and create additional accounts by preventing access at login.
References
|
| CIS-6.5 | Require MFA for Administrative Access | mitigates | T1136 | Create Account |
Comments
Using multi-factor authentication for administrative accounts reduces the likelihood that adversaries can use a compromised admin credential to sign in and create additional accounts by preventing access at login.
References
|
| CIS-6.5 | Require MFA for Administrative Access | mitigates | T1199 | Trusted Relationship |
Comments
Using multi-factor authentication for administrative accounts reduces the success of adversaries breaching trusted third party relationships to compromise those networks and gain access to intended victims.
References
|
| CIS-6.4 | Require MFA for Remote Network Access | mitigates | T1021.004 | SSH |
Comments
Enabling multi-factor authentication for SSH connections helps minimize the adversary's ability to leverage stolen credentials.
References
|
| CIS-6.4 | Require MFA for Remote Network Access | mitigates | T1021.001 | Remote Desktop Protocol |
Comments
Enabling multi-factor authentication for remote logins helps minimize the adversary's ability to leverage stolen credentials.
References
|
| CIS-6.4 | Require MFA for Remote Network Access | mitigates | T1021 | Remote Services |
Comments
Enabling multi-factor authentication for remote service logons helps minimize the adversary's ability to leverage stolen credentials.
References
|
| CIS-6.4 | Require MFA for Remote Network Access | mitigates | T1133 | External Remote Services |
Comments
Enabling multi-factor authentication for external-facing remote service accounts to helps minimize the adversary's ability to leverage stolen credentials.
References
|
| CIS-6.3 | Require MFA for Externally-Exposed Applications | mitigates | T1114.002 | Remote Email Collection |
Comments
Enabling multi-factor authentication for public-facing webmail servers helps minimize the usefulness of email usernames and passwords collected by adversaries.
References
|
| CIS-6.3 | Require MFA for Externally-Exposed Applications | mitigates | T1114 | Email Collection |
Comments
Enabling multi-factor authentication for public-facing webmail servers helps minimize the usefulness of email usernames and passwords collected by adversaries.
References
|
| CIS-6.4 | Require MFA for Remote Network Access | mitigates | T1021.007 | Cloud Services |
Comments
Enabling multi-factor authentication on cloud services helps minimize the adversary's ability to leverage stolen credentials.
References
|
| CIS-6.3 | Require MFA for Externally-Exposed Applications | mitigates | T1110.003 | Password Spraying |
Comments
Enabling multi-factor authentication can prevent adversaries from gaining access through brute force password spraying attacks against authentication interfaces on externally facing services.
References
|
| CIS-6.3 | Require MFA for Externally-Exposed Applications | mitigates | T1110.002 | Password Cracking |
Comments
Enabling multi-factor authentication can prevent adversaries from gaining access through brute force password cracking attacks against authentication interfaces on externally facing services.
References
|
| CIS-6.3 | Require MFA for Externally-Exposed Applications | mitigates | T1110.001 | Password Guessing |
Comments
Enabling multi-factor authentication can prevent adversaries from gaining access through brute force password guessing attacks against authentication interfaces on externally facing services.
References
|
| CIS-6.3 | Require MFA for Externally-Exposed Applications | mitigates | T1110 | Brute Force |
Comments
Enabling multi-factor authentication can prevent adversaries from gaining access through brute force attacks against authentication interfaces on externally facing services.
References
|
| CIS-6.3 | Require MFA for Externally-Exposed Applications | mitigates | T1110.004 | Credential Stuffing |
Comments
Enabling multi-factor authentication can prevent adversaries from gaining access through brute force credential stuffing attacks against authentication interfaces on externally facing services.
References
|
| CIS-6.2 | Establish an Access Revoking Process | mitigates | T1555.003 | Credentials from Web Browsers |
Comments
Inactive accounts may be targeted by attackers to gain unauthorized access. Disabling inactive accounts can prevent attackers from acquiring credentials from web browsers.
References
|
| CIS-6.2 | Establish an Access Revoking Process | mitigates | T1556.006 | Multi-Factor Authentication |
Comments
Removing accounts that are no longer needed helps to accounts that adversaries could abuse to disable or modify MFA and maintain persistent access.
References
|
| CIS-6.2 | Establish an Access Revoking Process | mitigates | T1078.004 | Cloud Accounts |
Comments
Disabling accounts that are no longer needed immediately upon termination, rights revocation, or role change prevents adversaries from gaining and using those accounts.
References
|
| CIS-6.5 | Require MFA for Administrative Access | mitigates | T1078.001 | Default Accounts |
Comments
Implement multi-factor authentication (MFA) for administrative accounts to help prevent unauthorized access, even if credentials are compromised.
References
|
| CIS-6.2 | Establish an Access Revoking Process | mitigates | T1078.003 | Local Accounts |
Comments
Disabling accounts that are no longer needed immediately upon termination, rights revocation, or role change prevents adversaries from gaining and using those accounts.
References
|
| CIS-6.2 | Establish an Access Revoking Process | mitigates | T1078.002 | Domain Accounts |
Comments
Disabling accounts that are no longer needed immediately upon termination, rights revocation, or role change prevents adversaries from gaining and using those accounts.
References
|
| CIS-6.5 | Require MFA for Administrative Access | mitigates | T1098.003 | Additional Cloud Roles |
Comments
Using multi-factor authentication for privileged administrative access reduces the success of adversary attempts to add additional roles or permissions to an adversary-controlled cloud account to maintain or elevate access.
References
|
| CIS-6.5 | Require MFA for Administrative Access | mitigates | T1098.002 | Additional Email Delegate Permissions |
Comments
Using multi-factor authentication for privileged administrative access reduces the success of adversary attempts to grant additional permission levels to an adversary-controlled email account.
References
|
| CIS-6.5 | Require MFA for Administrative Access | mitigates | T1098.001 | Additional Cloud Credentials |
Comments
Using multi-factor authentication for privileged administrative access reduces the success of adversary attempts to add adversary-owned credentials to a cloud account to maintain or elevate access.
References
|
| CIS-6.5 | Require MFA for Administrative Access | mitigates | T1136.003 | Cloud Account |
Comments
Using multi-factor authentication for administrative accounts reduces the likelihood that adversaries can use a compromised admin credential to sign in and create additional accounts by preventing access at login.
References
|
| CIS-6.5 | Require MFA for Administrative Access | mitigates | T1599.001 | Network Address Translation Traversal |
Comments
Using multi-factor authentication on accounts that administer network devices helps prevent adversaries from using compromised credentials to modify a network device’s Network Address Translation (NAT) configuration by limiting their ability to log in.
References
|
| Capability ID | Capability Name | Number of Mappings |
|---|---|---|
| CIS-6.8 | Define and Maintain Role-Based Access Control | 106 |
| CIS-6.5 | Require MFA for Administrative Access | 37 |
| CIS-6.4 | Require MFA for Remote Network Access | 5 |
| CIS-6.3 | Require MFA for Externally-Exposed Applications | 7 |
| CIS-6.2 | Establish an Access Revoking Process | 7 |