CRI Profile DE.CM-01.04

The organization has policies, procedures, and tools in place to monitor for, detect, and block access from/to devices that are not authorized or do not conform to security policy (e.g., unpatched systems).

Mappings

Capability ID Capability Description Mapping Type ATT&CK ID ATT&CK Name Notes
DE.CM-01.04 Unauthorized device connection Mitigates T1200 Hardware Additions
Comments
This diagnostic statement provides protection from hardware additions through the use of tools to detect and block the use of unauthorized or unknown devices and accessories by endpoint security configuration and monitoring.
DE.CM-01.04 Unauthorized device connection Mitigates T1052 Exfiltration Over Physical Medium
Comments
This diagnostic statement provides protection from exfiltration of data via a physical medium, such as a removable drive by using tools to detect and block the use of unauthorized devices.
DE.CM-01.04 Unauthorized device connection Mitigates T1052.001 Exfiltration over USB
Comments
This diagnostic statement provides protection from exfiltration of data via a physical medium, such as a removable drive by using tools to detect and block the use of unauthorized devices.