Azure azure_dedicated_hsm

Azure Dedicated HSM is an Azure service that provides cryptographic key storage in Azure. Dedicated HSM meets security requirements for FIPS 140-2 Level 3-validated devices and provides users with complete and exclusive control of the HSM appliance.

Mappings

Capability ID Capability Description Category Value ATT&CK ID ATT&CK Name Notes
azure_dedicated_hsm Azure Dedicated HSM protect minimal T1552 Unsecured Credentials
Comments
This control's protection is specific to a minority of this technique's sub-techniques and procedure examples resulting in a Minimal Coverage score and consequently an overall score of Minimal.
References
azure_dedicated_hsm Azure Dedicated HSM protect partial T1553 Subvert Trust Controls
Comments
Provides protection against sub-techniques involved with stealing credentials / certificates / keys from the organization.
References
azure_dedicated_hsm Azure Dedicated HSM protect partial T1553.002 Code Signing
Comments
Certificate credentials can be vaulted in an HSM thereby reducing its attack surface.
References
azure_dedicated_hsm Azure Dedicated HSM protect partial T1553.004 Install Root Certificate
Comments
Certificate credentials can be vaulted in an HSM thereby reducing its attack surface.
References
azure_dedicated_hsm Azure Dedicated HSM protect partial T1588 Obtain Capabilities
Comments
Provides protection against sub-techniques involved with stealing credentials / certificates / keys from the organization.
References
azure_dedicated_hsm Azure Dedicated HSM protect partial T1588.003 Code Signing Certificates
Comments
Certificate credentials can be vaulted in an HSM thereby reducing its attack surface.
References
azure_dedicated_hsm Azure Dedicated HSM protect partial T1588.004 Digital Certificates
Comments
Certificate credentials can be vaulted in an HSM thereby reducing its attack surface.
References
azure_dedicated_hsm Azure Dedicated HSM protect significant T1552.004 Private Keys
Comments
Provides significant protection of private keys.
References