Azure azure_dedicated_hsm Mappings

"Azure Dedicated HSM is an Azure service that provides cryptographic key storage in Azure ... for customers who require FIPS 140-2 Level 3-validated devices and complete and exclusive control of the HSM appliance."

Mappings

Capability ID Capability Description Category Value ATT&CK ID ATT&CK Name Notes
azure_dedicated_hsm Azure Dedicated HSM protect minimal T1552 Unsecured Credentials
Comments
This control's protection is specific to a minority of this technique's sub-techniques and procedure examples resulting in a Minimal Coverage score and consequently an overall score of Minimal.
References
azure_dedicated_hsm Azure Dedicated HSM protect significant T1552.004 Private Keys
Comments
Provides significant protection of private keys.
References
    azure_dedicated_hsm Azure Dedicated HSM protect partial T1588 Obtain Capabilities
    Comments
    Provides protection against sub-techniques involved with stealing credentials / certificates / keys from the organization.
    References
    azure_dedicated_hsm Azure Dedicated HSM protect partial T1588.004 Digital Certificates
    Comments
    Certificate credentials can be vaulted in an HSM thereby reducing its attack surface.
    References
      azure_dedicated_hsm Azure Dedicated HSM protect partial T1588.003 Code Signing Certificates
      Comments
      Certificate credentials can be vaulted in an HSM thereby reducing its attack surface.
      References
        azure_dedicated_hsm Azure Dedicated HSM protect partial T1553 Subvert Trust Controls
        Comments
        Provides protection against sub-techniques involved with stealing credentials / certificates / keys from the organization.
        References
        azure_dedicated_hsm Azure Dedicated HSM protect partial T1553.004 Install Root Certificate
        Comments
        Certificate credentials can be vaulted in an HSM thereby reducing its attack surface.
        References
          azure_dedicated_hsm Azure Dedicated HSM protect partial T1553.002 Code Signing
          Comments
          Certificate credentials can be vaulted in an HSM thereby reducing its attack surface.
          References