CRI Profile Protect: Identity Management, Authentication, Access Control Capability Group

All Mappings

Capability ID Capability Description Mapping Type ATT&CK ID ATT&CK Name Notes
PR.AA-05.03 Service accounts Mitigates T1558.001 Golden Ticket
Comments
This diagnostic statement describes security controls implemented for service accounts (i.e., accounts used by systems to access other systems). Limit service accounts to minimal required privileges to mitigate attempts to steal or forge Kerberos tickets.
PR.AA-05.03 Service accounts Mitigates T1563 Remote Service Session Hijacking
Comments
This diagnostic statement is for the implementation of security controls for service accounts (i.e., accounts used by systems to access other systems), such as granting service accounts only the minimum necessary permissions.
PR.AA-05.03 Service accounts Mitigates T1563.002 RDP Hijacking
Comments
This diagnostic statement is for the implementation of security controls for service accounts (i.e., accounts used by systems to access other systems), such as granting service accounts only the minimum necessary permissions.
PR.AA-05.03 Service accounts Mitigates T1559 Inter-Process Communication
Comments
This diagnostic statement is for the implementation of security controls for service accounts (i.e., accounts used by systems to access other systems). Set service account access restrictions to grant only the minimum necessary permissions to mitigate abuse of inter-process communication (IPC) mechanisms.
PR.AA-05.03 Service accounts Mitigates T1021 Remote Services
Comments
This diagnostic statement is for the implementation of security controls for service accounts (i.e., accounts used by systems to access other systems). Minimize service account permissions and access for the service to mitigate exploitation via remote services that use service accounts.
PR.AA-05.03 Service accounts Mitigates T1021.007 Cloud Services
Comments
This diagnostic statement is for the implementation of security controls for service accounts (i.e., accounts used by systems to access other systems). Minimize service account permissions and access for the service to mitigate exploitation via cloud services service accounts.
PR.AA-05.03 Service accounts Mitigates T1021.002 SMB/Windows Admin Shares
Comments
This diagnostic statement is for the implementation of security controls for service accounts (i.e., accounts used by systems to access other systems). Block the SMB/Windows Admin Shares service account to mitigate exploitation.
PR.AA-05.03 Service accounts Mitigates T1021.006 Windows Remote Management
Comments
This diagnostic statement is for the implementation of security controls for service accounts (i.e., accounts used by systems to access other systems). Minimize service account permissions and access for the service to mitigate exploitation via the WinRM service account.
PR.AA-05.03 Service accounts Mitigates T1190 Exploit Public-Facing Application
Comments
This diagnostic statement is for the implementation of security controls for service accounts (i.e., accounts used by systems to access other systems). Use least privilege for service accounts to limit what permissions the exploited process gets on the rest of the system.
PR.AA-05.03 Service accounts Mitigates T1484 Domain or Tenant Policy Modification
Comments
This diagnostic statement is for the implementation of security controls for service accounts (i.e., accounts used by systems to access other systems). Restrict administrative privileges to mitigate this technique.
PR.AA-05.04 Third-party access management Mitigates T1078.004 Cloud Accounts
Comments
This diagnostic statement includes implementation of controls for third-party access to an organization’s systems. Conditional access policies can be used to block logins from non-compliant devices or from outside defined IP ranges.
PR.AA-05.04 Third-party access management Mitigates T1110.001 Password Guessing
Comments
This diagnostic statement includes implementation of controls for third-party access to an organization’s systems. Enforcing third-party account use policies to include account lockout policies after a certain number of failed login attempts mitigates the risk of brute-force attacks.
PR.AA-05.04 Third-party access management Mitigates T1110.003 Password Spraying
Comments
This diagnostic statement includes implementation of controls for third-party access to an organization’s systems. Enforcing third-party account use policies to include account lockout policies after a certain number of failed login attempts mitigates the risk of brute-force attacks.
PR.AA-05.04 Third-party access management Mitigates T1110.004 Credential Stuffing
Comments
This diagnostic statement includes implementation of controls for third-party access to an organization’s systems. Enforcing third-party account use policies to include account lockout policies after a certain number of failed login attempts mitigates the risk of brute-force attacks.
PR.AA-05.02 Privileged system access Mitigates T1003.006 DCSync
Comments
This diagnostic statement protects against DCSync through the use of privileged account management and the use of multi-factor authentication.
PR.AA-05.02 Privileged system access Mitigates T1003.007 Proc Filesystem
Comments
This diagnostic statement protects against Proc Filesystem through the use of privileged account management and the use of multi-factor authentication.
PR.AA-05.02 Privileged system access Mitigates T1003.008 /etc/passwd and /etc/shadow
Comments
This diagnostic statement protects against /etc/passwd and /etc/shadow through the use of privileged account management and the use of multi-factor authentication.
PR.AA-05.02 Privileged system access Mitigates T1021 Remote Services
Comments
This diagnostic statement protects against Remote Services through the use of privileged account management and the use of multi-factor authentication.
PR.AA-05.02 Privileged system access Mitigates T1021.001 Remote Desktop Protocol
Comments
This diagnostic statement protects against Remote Desktop Protocol through the use of privileged account management and the use of multi-factor authentication.
PR.AA-05.02 Privileged system access Mitigates T1021.002 SMB/Windows Admin Shares
Comments
This diagnostic statement protects against SMB/Windows Admin Shares through the use of privileged account management and the use of multi-factor authentication.
PR.AA-05.02 Privileged system access Mitigates T1021.003 Distributed Component Object Model
Comments
This diagnostic statement protects against Distributed Component Object Model through the use of privileged account management and the use of multi-factor authentication.
PR.AA-05.02 Privileged system access Mitigates T1021.004 SSH
Comments
This diagnostic statement protects against SSH through the use of privileged account management and the use of multi-factor authentication.
PR.AA-05.02 Privileged system access Mitigates T1021.006 Windows Remote Management
Comments
This diagnostic statement protects against Windows Remote Management through the use of privileged account management and the use of multi-factor authentication.
PR.AA-05.02 Privileged system access Mitigates T1021.007 Cloud Services
Comments
This diagnostic statement protects against Cloud Services through the use of privileged account management and the use of multi-factor authentication.
PR.AA-05.02 Privileged system access Mitigates T1040 Network Sniffing
Comments
This diagnostic statement protects against Network Sniffing through the use of privileged account management and the use of multi-factor authentication.
PR.AA-05.02 Privileged system access Mitigates T1047 Windows Management Instrumentation
Comments
This diagnostic statement protects against Windows Management Instrumentation through the use of privileged account management and the use of multi-factor authentication.
PR.AA-05.02 Privileged system access Mitigates T1053 Scheduled Task/Job
Comments
This diagnostic statement protects against Scheduled Task/Job through the use of privileged account management and the use of multi-factor authentication.
PR.AA-05.02 Privileged system access Mitigates T1053.002 At
Comments
This diagnostic statement protects against At through the use of privileged account management and the use of multi-factor authentication.
PR.AA-05.02 Privileged system access Mitigates T1053.005 Scheduled Task
Comments
This diagnostic statement protects against Scheduled Task through the use of privileged account management and the use of multi-factor authentication.
PR.AA-05.02 Privileged system access Mitigates T1053.006 Systemd Timers
Comments
This diagnostic statement protects against Systemd Timers through the use of privileged account management and the use of multi-factor authentication.
PR.AA-05.02 Privileged system access Mitigates T1053.007 Container Orchestration Job
Comments
This diagnostic statement protects against Container Orchestration Job through the use of privileged account management and the use of multi-factor authentication.
PR.AA-05.02 Privileged system access Mitigates T1055 Process Injection
Comments
This diagnostic statement protects against Process Injection through the use of privileged account management and the use of multi-factor authentication.
PR.AA-05.02 Privileged system access Mitigates T1055.008 Ptrace System Calls
Comments
This diagnostic statement protects against Ptrace System Calls through the use of privileged account management and the use of multi-factor authentication.
PR.AA-05.02 Privileged system access Mitigates T1056 Input Capture
Comments
This diagnostic statement protects against Input Capture through the use of privileged account management and the use of multi-factor authentication.
PR.AA-05.02 Privileged system access Mitigates T1056.003 Web Portal Capture
Comments
This diagnostic statement protects against Web Portal Capture through the use of privileged account management and the use of multi-factor authentication.
PR.AA-05.02 Privileged system access Mitigates T1059 Command and Scripting Interpreter
Comments
This diagnostic statement protects against Command and Scripting Interpreter through the use of privileged account management and the use of multi-factor authentication.
PR.AA-05.02 Privileged system access Mitigates T1059.001 PowerShell
Comments
This diagnostic statement protects against PowerShell through the use of privileged account management and the use of multi-factor authentication.
PR.AA-05.02 Privileged system access Mitigates T1059.008 Network Device CLI
Comments
This diagnostic statement protects against Network Device CLI through the use of privileged account management and the use of multi-factor authentication.
PR.AA-05.02 Privileged system access Mitigates T1059.009 Cloud API
Comments
This diagnostic statement protects against Cloud API through the use of privileged account management and the use of multi-factor authentication.
PR.AA-05.02 Privileged system access Mitigates T1072 Software Deployment Tools
Comments
This diagnostic statement protects against Software Deployment Tools through the use of privileged account management and the use of multi-factor authentication.
PR.AA-05.02 Privileged system access Mitigates T1078 Valid Accounts
Comments
This diagnostic statement protects against Valid Accounts through the use of privileged account management and the use of multi-factor authentication.
PR.AA-05.02 Privileged system access Mitigates T1078.001 Default Accounts
Comments
This diagnostic statement protects against Default Accounts through the use of privileged account management and the use of multi-factor authentication.
PR.AA-05.02 Privileged system access Mitigates T1078.002 Domain Accounts
Comments
This diagnostic statement protects against Domain Accounts through the use of privileged account management and the use of multi-factor authentication.
PR.AA-05.02 Privileged system access Mitigates T1078.003 Local Accounts
Comments
This diagnostic statement protects against Local Accounts through the use of privileged account management and the use of multi-factor authentication.
PR.AA-05.02 Privileged system access Mitigates T1078.004 Cloud Accounts
Comments
This diagnostic statement protects against Cloud Accounts through the use of privileged account management and the use of multi-factor authentication.
PR.AA-05.02 Privileged system access Mitigates T1098 Account Manipulation
Comments
This diagnostic statement protects against Account Manipulation through the use of privileged account management and the use of multi-factor authentication.
PR.AA-05.02 Privileged system access Mitigates T1098.001 Additional Cloud Credentials
Comments
This diagnostic statement protects against Additional Cloud Credentials through the use of privileged account management and the use of multi-factor authentication.
PR.AA-05.02 Privileged system access Mitigates T1098.002 Additional Email Delegate Permissions
Comments
This diagnostic statement protects against Additional Email Delegate Permissions through the use of privileged account management and the use of multi-factor authentication.
PR.AA-05.02 Privileged system access Mitigates T1098.003 Additional Cloud Roles
Comments
This diagnostic statement protects against Additional Cloud Roles through the use of privileged account management and the use of multi-factor authentication.
PR.AA-05.02 Privileged system access Mitigates T1098.005 Device Registration
Comments
This diagnostic statement protects against Device Registration through the use of privileged account management and the use of multi-factor authentication.
PR.AA-05.02 Privileged system access Mitigates T1098.006 Additional Container Cluster Roles
Comments
This diagnostic statement protects against Additional Container Cluster Roles through the use of privileged account management and the use of multi-factor authentication.
PR.AA-05.02 Privileged system access Mitigates T1110 Brute Force
Comments
This diagnostic statement protects against Brute Force through the use of privileged account management and the use of multi-factor authentication.
PR.AA-05.02 Privileged system access Mitigates T1110.001 Password Guessing
Comments
This diagnostic statement protects against Password Guessing through the use of privileged account management and the use of multi-factor authentication.
PR.AA-05.02 Privileged system access Mitigates T1110.002 Password Cracking
Comments
This diagnostic statement protects against Password Cracking through the use of privileged account management and the use of multi-factor authentication.
PR.AA-05.02 Privileged system access Mitigates T1110.003 Password Spraying
Comments
This diagnostic statement protects against Password Spraying through the use of privileged account management and the use of multi-factor authentication.
PR.AA-05.02 Privileged system access Mitigates T1110.004 Credential Stuffing
Comments
This diagnostic statement protects against Credential Stuffing through the use of privileged account management and the use of multi-factor authentication.
PR.AA-05.02 Privileged system access Mitigates T1114 Email Collection
Comments
This diagnostic statement protects against Email Collection through the use of privileged account management and the use of multi-factor authentication.
PR.AA-05.02 Privileged system access Mitigates T1114.002 Remote Email Collection
Comments
This diagnostic statement protects against Remote Email Collection through the use of privileged account management and the use of multi-factor authentication.
PR.AA-05.02 Privileged system access Mitigates T1133 External Remote Services
Comments
This diagnostic statement protects against External Remote Services through the use of privileged account management and the use of multi-factor authentication.
PR.AA-05.02 Privileged system access Mitigates T1134 Access Token Manipulation
Comments
This diagnostic statement protects against Access Token Manipulation through the use of privileged account management and the use of multi-factor authentication.
PR.AA-05.02 Privileged system access Mitigates T1134.001 Token Impersonation/Theft
Comments
This diagnostic statement protects against Token Impersonation/Theft through the use of privileged account management and the use of multi-factor authentication.
PR.AA-05.02 Privileged system access Mitigates T1134.002 Create Process with Token
Comments
This diagnostic statement protects against Create Process with Token through the use of privileged account management and the use of multi-factor authentication.
PR.AA-05.02 Privileged system access Mitigates T1134.003 Make and Impersonate Token
Comments
This diagnostic statement protects against Make and Impersonate Token through the use of privileged account management and the use of multi-factor authentication.
PR.AA-05.02 Privileged system access Mitigates T1136 Create Account
Comments
This diagnostic statement protects against Create Account through the use of privileged account management and the use of multi-factor authentication.
PR.AA-05.02 Privileged system access Mitigates T1136.001 Local Account
Comments
This diagnostic statement protects against Local Account through the use of privileged account management and the use of multi-factor authentication.
PR.AA-05.02 Privileged system access Mitigates T1136.002 Domain Account
Comments
This diagnostic statement protects against Domain Account through the use of privileged account management and the use of multi-factor authentication.
PR.AA-05.02 Privileged system access Mitigates T1136.003 Cloud Account
Comments
This diagnostic statement protects against Cloud Account through the use of privileged account management and the use of multi-factor authentication.
PR.AA-05.02 Privileged system access Mitigates T1190 Exploit Public-Facing Application
Comments
This diagnostic statement protects against Exploit Public-Facing Application through the use of privileged account management and the use of multi-factor authentication.
PR.AA-05.02 Privileged system access Mitigates T1199 Trusted Relationship
Comments
This diagnostic statement protects against Trusted Relationship through the use of privileged account management and the use of multi-factor authentication.
PR.AA-05.02 Privileged system access Mitigates T1210 Exploitation of Remote Services
Comments
This diagnostic statement protects against Exploitation of Remote Services through the use of privileged account management and the use of multi-factor authentication.
PR.AA-05.02 Privileged system access Mitigates T1213 Data from Information Repositories
Comments
This diagnostic statement protects against Data from Information Repositories through the use of privileged account management and the use of multi-factor authentication.
PR.AA-05.02 Privileged system access Mitigates T1213.003 Code Repositories
Comments
This diagnostic statement protects against Code Repositories through the use of privileged account management and the use of multi-factor authentication.
PR.AA-05.02 Privileged system access Mitigates T1218 System Binary Proxy Execution
Comments
This diagnostic statement protects against System Binary Proxy Execution through the use of privileged account management and the use of multi-factor authentication.
PR.AA-05.02 Privileged system access Mitigates T1218.007 Msiexec
Comments
This diagnostic statement protects against Msiexec through the use of privileged account management and the use of multi-factor authentication.
PR.AA-05.02 Privileged system access Mitigates T1222 File and Directory Permissions Modification
Comments
This diagnostic statement protects against File and Directory Permissions Modification through the use of privileged account management and the use of multi-factor authentication.
PR.AA-05.02 Privileged system access Mitigates T1222.001 Windows File and Directory Permissions Modification
Comments
This diagnostic statement protects against Windows File and Directory Permissions Modification through the use of privileged account management and the use of multi-factor authentication.
PR.AA-05.02 Privileged system access Mitigates T1222.002 Linux and Mac File and Directory Permissions Modification
Comments
This diagnostic statement protects against Linux and Mac File and Directory Permissions Modification through the use of privileged account management and the use of multi-factor authentication.
PR.AA-05.02 Privileged system access Mitigates T1484 Domain or Tenant Policy Modification
Comments
This diagnostic statement protects against Domain or Tenant Policy Modification through the use of privileged account management and the use of multi-factor authentication.
PR.AA-05.02 Privileged system access Mitigates T1484.002 Trust Modification
Comments
This diagnostic statement protects against Trust Modification through the use of privileged account management and the use of multi-factor authentication.
PR.AA-05.02 Privileged system access Mitigates T1485 Data Destruction
Comments
This diagnostic statement protects against Data Destruction through the use of privileged account management and the use of multi-factor authentication.
PR.AA-05.02 Privileged system access Mitigates T1495 Firmware Corruption
Comments
This diagnostic statement protects against Firmware Corruption through the use of privileged account management and the use of multi-factor authentication.
PR.AA-05.02 Privileged system access Mitigates T1505 Server Software Component
Comments
This diagnostic statement protects against Server Software Component through the use of privileged account management and the use of multi-factor authentication.
PR.AA-05.02 Privileged system access Mitigates T1505.001 SQL Stored Procedures
Comments
This diagnostic statement protects against SQL Stored Procedures through the use of privileged account management and the use of multi-factor authentication.
PR.AA-05.02 Privileged system access Mitigates T1505.002 Transport Agent
Comments
This diagnostic statement protects against Transport Agent through the use of privileged account management and the use of multi-factor authentication.
PR.AA-05.02 Privileged system access Mitigates T1505.004 IIS Components
Comments
This diagnostic statement protects against IIS Components through the use of privileged account management and the use of multi-factor authentication.
PR.AA-05.02 Privileged system access Mitigates T1525 Implant Internal Image
Comments
This diagnostic statement protects against Implant Internal Image through the use of privileged account management and the use of multi-factor authentication.
PR.AA-05.02 Privileged system access Mitigates T1530 Data from Cloud Storage
Comments
This diagnostic statement protects against Data from Cloud Storage through the use of privileged account management and the use of multi-factor authentication.
PR.AA-05.02 Privileged system access Mitigates T1539 Steal Web Session Cookie
Comments
This diagnostic statement protects against Steal Web Session Cookie through the use of privileged account management and the use of multi-factor authentication.
PR.AA-05.02 Privileged system access Mitigates T1542 Pre-OS Boot
Comments
This diagnostic statement protects against Pre-OS Boot through the use of privileged account management and the use of multi-factor authentication.
PR.AA-05.02 Privileged system access Mitigates T1542.001 System Firmware
Comments
This diagnostic statement protects against System Firmware through the use of privileged account management and the use of multi-factor authentication.
PR.AA-05.02 Privileged system access Mitigates T1542.003 Bootkit
Comments
This diagnostic statement protects against Bootkit through the use of privileged account management and the use of multi-factor authentication.
PR.AA-05.02 Privileged system access Mitigates T1542.005 TFTP Boot
Comments
This diagnostic statement protects against TFTP Boot through the use of privileged account management and the use of multi-factor authentication.
PR.AA-05.02 Privileged system access Mitigates T1543 Create or Modify System Process
Comments
This diagnostic statement protects against Create or Modify System Process through the use of privileged account management and the use of multi-factor authentication.
PR.AA-05.02 Privileged system access Mitigates T1543.002 Systemd Service
Comments
This diagnostic statement protects against Systemd Service through the use of privileged account management and the use of multi-factor authentication.
PR.AA-05.02 Privileged system access Mitigates T1546 Event Triggered Execution
Comments
This diagnostic statement protects against Event Triggered Execution through the use of privileged account management and the use of multi-factor authentication.
PR.AA-05.02 Privileged system access Mitigates T1546.003 Windows Management Instrumentation Event Subscription
Comments
This diagnostic statement protects against Windows Management Instrumentation Event Subscription through the use of privileged account management and the use of multi-factor authentication.
PR.AA-05.02 Privileged system access Mitigates T1547 Boot or Logon Autostart Execution
Comments
This diagnostic statement protects against Boot or Logon Autostart Execution through the use of privileged account management and the use of multi-factor authentication.
PR.AA-05.02 Privileged system access Mitigates T1547.006 Kernel Modules and Extensions
Comments
This diagnostic statement protects against Kernel Modules and Extensions through the use of privileged account management and the use of multi-factor authentication.
PR.AA-05.02 Privileged system access Mitigates T1548 Abuse Elevation Control Mechanism
Comments
This diagnostic statement protects against Abuse Elevation Control Mechanism through the use of privileged account management and the use of multi-factor authentication.
PR.AA-05.02 Privileged system access Mitigates T1548.002 Bypass User Account Control
Comments
This diagnostic statement protects against Bypass User Account Control through the use of privileged account management and the use of multi-factor authentication.
PR.AA-05.02 Privileged system access Mitigates T1548.003 Sudo and Sudo Caching
Comments
This diagnostic statement protects against Sudo and Sudo Caching through the use of privileged account management and the use of multi-factor authentication.
PR.AA-05.02 Privileged system access Mitigates T1548.006 TCC Manipulation
Comments
This diagnostic statement protects against TCC Manipulation through the use of privileged account management and the use of multi-factor authentication.
PR.AA-05.02 Privileged system access Mitigates T1550 Use Alternate Authentication Material
Comments
This diagnostic statement protects against Use Alternate Authentication Material through the use of privileged account management and the use of multi-factor authentication.
PR.AA-05.02 Privileged system access Mitigates T1550.002 Pass the Hash
Comments
This diagnostic statement protects against Pass the Hash through the use of privileged account management and the use of multi-factor authentication.
PR.AA-05.02 Privileged system access Mitigates T1550.003 Pass the Ticket
Comments
This diagnostic statement protects against Pass the Ticket through the use of privileged account management and the use of multi-factor authentication.
PR.AA-05.02 Privileged system access Mitigates T1552 Unsecured Credentials
Comments
This diagnostic statement protects against Unsecured Credentials through the use of privileged account management and the use of multi-factor authentication.
PR.AA-05.02 Privileged system access Mitigates T1552.002 Credentials in Registry
Comments
This diagnostic statement protects against Credentials in Registry through the use of privileged account management and the use of multi-factor authentication.
PR.AA-05.02 Privileged system access Mitigates T1552.007 Container API
Comments
This diagnostic statement protects against Container API through the use of privileged account management and the use of multi-factor authentication.
PR.AA-05.02 Privileged system access Mitigates T1553 Subvert Trust Controls
Comments
This diagnostic statement protects against Subvert Trust Controls through the use of privileged account management and the use of multi-factor authentication.
PR.AA-05.02 Privileged system access Mitigates T1553.006 Code Signing Policy Modification
Comments
This diagnostic statement protects against Code Signing Policy Modification through the use of privileged account management and the use of multi-factor authentication.
PR.AA-05.02 Privileged system access Mitigates T1555 Credentials from Password Stores
Comments
This diagnostic statement protects against Credentials from Password Stores through the use of privileged account management and the use of multi-factor authentication.
PR.AA-05.02 Privileged system access Mitigates T1555.006 Cloud Secrets Management Stores
Comments
This diagnostic statement protects against Cloud Secrets Management Stores through the use of privileged account management and the use of multi-factor authentication.
PR.AA-05.02 Privileged system access Mitigates T1556 Modify Authentication Process
Comments
This diagnostic statement protects against Modify Authentication Process through the use of privileged account management and the use of multi-factor authentication.
PR.AA-05.02 Privileged system access Mitigates T1556.001 Domain Controller Authentication
Comments
This diagnostic statement protects against Domain Controller Authentication through the use of privileged account management and the use of multi-factor authentication.
PR.AA-05.02 Privileged system access Mitigates T1556.003 Pluggable Authentication Modules
Comments
This diagnostic statement protects against Pluggable Authentication Modules through the use of privileged account management and the use of multi-factor authentication.
PR.AA-05.02 Privileged system access Mitigates T1556.004 Network Device Authentication
Comments
This diagnostic statement protects against Network Device Authentication through the use of privileged account management and the use of multi-factor authentication.
PR.AA-05.02 Privileged system access Mitigates T1556.005 Reversible Encryption
Comments
This diagnostic statement protects against Reversible Encryption through the use of privileged account management and the use of multi-factor authentication.
PR.AA-05.02 Privileged system access Mitigates T1556.006 Multi-Factor Authentication
Comments
This diagnostic statement protects against Multi-Factor Authentication through the use of privileged account management and the use of multi-factor authentication.
PR.AA-05.02 Privileged system access Mitigates T1556.007 Hybrid Identity
Comments
This diagnostic statement protects against Hybrid Identity through the use of privileged account management and the use of multi-factor authentication.
PR.AA-05.02 Privileged system access Mitigates T1558 Steal or Forge Kerberos Tickets
Comments
This diagnostic statement protects against Steal or Forge Kerberos Tickets through the use of privileged account management and the use of multi-factor authentication.
PR.AA-05.02 Privileged system access Mitigates T1558.001 Golden Ticket
Comments
This diagnostic statement protects against Golden Ticket through the use of privileged account management and the use of multi-factor authentication.
PR.AA-05.02 Privileged system access Mitigates T1558.002 Silver Ticket
Comments
This diagnostic statement protects against Silver Ticket through the use of privileged account management and the use of multi-factor authentication.
PR.AA-05.02 Privileged system access Mitigates T1558.003 Kerberoasting
Comments
This diagnostic statement protects against Kerberoasting through the use of privileged account management and the use of multi-factor authentication.
PR.AA-05.02 Privileged system access Mitigates T1559 Inter-Process Communication
Comments
This diagnostic statement protects against Inter-Process Communication through the use of privileged account management and the use of multi-factor authentication.
PR.AA-05.02 Privileged system access Mitigates T1559.001 Component Object Model
Comments
This diagnostic statement protects against Component Object Model through the use of privileged account management and the use of multi-factor authentication.
PR.AA-05.02 Privileged system access Mitigates T1562 Impair Defenses
Comments
This diagnostic statement protects against Impair Defenses through the use of privileged account management and the use of multi-factor authentication.
PR.AA-05.02 Privileged system access Mitigates T1562.009 Safe Mode Boot
Comments
This diagnostic statement protects against Safe Mode Boot through the use of privileged account management and the use of multi-factor authentication.
PR.AA-05.02 Privileged system access Mitigates T1563 Remote Service Session Hijacking
Comments
This diagnostic statement protects against Remote Service Session Hijacking through the use of privileged account management and the use of multi-factor authentication.
PR.AA-05.02 Privileged system access Mitigates T1563.001 SSH Hijacking
Comments
This diagnostic statement protects against SSH Hijacking through the use of privileged account management and the use of multi-factor authentication.
PR.AA-05.02 Privileged system access Mitigates T1563.002 RDP Hijacking
Comments
This diagnostic statement protects against RDP Hijacking through the use of privileged account management and the use of multi-factor authentication.
PR.AA-05.02 Privileged system access Mitigates T1569 System Services
Comments
This diagnostic statement protects against System Services through the use of privileged account management and the use of multi-factor authentication.
PR.AA-05.02 Privileged system access Mitigates T1569.002 Service Execution
Comments
This diagnostic statement protects against Service Execution through the use of privileged account management and the use of multi-factor authentication.
PR.AA-05.02 Privileged system access Mitigates T1599 Network Boundary Bridging
Comments
This diagnostic statement protects against Network Boundary Bridging through the use of privileged account management and the use of multi-factor authentication.
PR.AA-05.02 Privileged system access Mitigates T1599.001 Network Address Translation Traversal
Comments
This diagnostic statement protects against Network Address Translation Traversal through the use of privileged account management and the use of multi-factor authentication.
PR.AA-05.02 Privileged system access Mitigates T1601 Modify System Image
Comments
This diagnostic statement protects against Modify System Image through the use of privileged account management and the use of multi-factor authentication.
PR.AA-05.02 Privileged system access Mitigates T1601.001 Patch System Image
Comments
This diagnostic statement protects against Patch System Image through the use of privileged account management and the use of multi-factor authentication.
PR.AA-05.02 Privileged system access Mitigates T1601.002 Downgrade System Image
Comments
This diagnostic statement protects against Downgrade System Image through the use of privileged account management and the use of multi-factor authentication.
PR.AA-05.02 Privileged system access Mitigates T1606 Forge Web Credentials
Comments
This diagnostic statement protects against Forge Web Credentials through the use of privileged account management and the use of multi-factor authentication.
PR.AA-05.02 Privileged system access Mitigates T1606.002 SAML Tokens
Comments
This diagnostic statement protects against SAML Tokens through the use of privileged account management and the use of multi-factor authentication.
PR.AA-05.02 Privileged system access Mitigates T1609 Container Administration Command
Comments
This diagnostic statement protects against Container Administration Command through the use of privileged account management and the use of multi-factor authentication.
PR.AA-05.02 Privileged system access Mitigates T1611 Escape to Host
Comments
This diagnostic statement protects against Escape to Host through the use of privileged account management and the use of multi-factor authentication.
PR.AA-05.02 Privileged system access Mitigates T1612 Build Image on Host
Comments
This diagnostic statement protects against Build Image on Host through the use of privileged account management and the use of multi-factor authentication.
PR.AA-05.02 Privileged system access Mitigates T1621 Multi-Factor Authentication Request Generation
Comments
This diagnostic statement protects against Multi-Factor Authentication Request Generation through the use of privileged account management and the use of multi-factor authentication.
PR.AA-05.02 Privileged system access Mitigates T1651 Cloud Administration Command
Comments
This diagnostic statement protects against Cloud Administration Command through the use of privileged account management and the use of multi-factor authentication.
PR.AA-02.01 Authentication of identity Mitigates T1021.007 Cloud Services
Comments
This diagnostic statement provides protection from Remote Services through the implementation of authentication and identity management controls to limit lateral movement. Employing control limitations to specific accounts, access control mechanisms, and auditing the attribution logs provides protection against adversaries attempting to move laterally in the cloud environment.
PR.AA-02.01 Authentication of identity Mitigates T1021.004 SSH
Comments
This diagnostic statement provides protection from Remote Services through the implementation of authentication and identity management controls to limit lateral movement. Employing limitations to specific accounts, access control mechanisms, and auditing the attribution logs provides protection against adversaries attempting to move laterally.
PR.AA-02.01 Authentication of identity Mitigates T1021.001 Remote Desktop Protocol
Comments
This diagnostic statement provides protection from Remote Services through the implementation of authentication and identity management controls to limit lateral movement. Employing limitations to specific accounts, access control mechanisms, and auditing the attribution logs provides protection against adversaries attempting to move laterally.
PR.AA-02.01 Authentication of identity Mitigates T1021 Remote Services
Comments
This diagnostic statement provides protection from Remote Services through the implementation of authentication and identity management controls to limit lateral movement. Employing limitations to specific accounts, access control mechanisms, and auditing the attribution logs provides protection against adversaries attempting to move laterally.
PR.AA-02.01 Authentication of identity Mitigates T1556.001 Domain Controller Authentication
Comments
This diagnostic statement provides protection from Modify Authentication Process through the implementation of privileged account management controls to limit credential access. Employing limitations to specific accounts, access control mechanisms, and auditing the attribution logs provides protection against adversaries attempting to modify credentials.
PR.AA-02.01 Authentication of identity Mitigates T1556 Modify Authentication Process
Comments
This diagnostic statement provides protection from Modify Authentication Process through the implementation of privileged account management controls to limit credential access. Employing limitations to specific accounts, access control mechanisms, and auditing the attribution logs provides protection against adversaries attempting to modify credentials.
PR.AA-02.01 Authentication of identity Mitigates T1110.004 Credential Stuffing
Comments
This diagnostic statement provides protection from Brute Force through the implementation of authentication controls and privileged account management controls to limit credential access. Employing limitations to specific accounts, access control mechanisms, and auditing the attribution logs provides protection against adversaries attempting to brute force credentials.
PR.AA-02.01 Authentication of identity Mitigates T1110.003 Password Spraying
Comments
This diagnostic statement provides protection from Brute Force through the implementation of authentication controls and privileged account management controls to limit credential access. Employing limitations to specific accounts, access control mechanisms, and auditing the attribution logs provides protection against adversaries attempting to brute force credentials.
PR.AA-02.01 Authentication of identity Mitigates T1110.001 Password Guessing
Comments
This diagnostic statement provides protection from Brute Force through the implementation of authentication controls and privileged account management controls to limit credential access. Employing limitations to specific accounts, access control mechanisms, and auditing the attribution logs provides protection against adversaries attempting to brute force credentials.
PR.AA-02.01 Authentication of identity Mitigates T1110 Brute Force
Comments
This diagnostic statement provides protection from Brute Force through the implementation of authentication controls and privileged account management controls to limit credential access. Employing limitations to specific accounts, access control mechanisms, and auditing the attribution logs provides protection against adversaries attempting to brute force credentials.
PR.AA-02.01 Authentication of identity Mitigates T1136.003 Cloud Account
Comments
This diagnostic statement provides protection from Create Account through the implementation of privileged account management controls to limit credential access. Employing limitations to specific accounts, access control mechanisms, and auditing the attribution logs provides protection against adversaries attempting to create accounts.
PR.AA-02.01 Authentication of identity Mitigates T1136.002 Domain Account
Comments
This diagnostic statement provides protection from Create Account through the implementation of privileged account management controls to limit credential access. Employing limitations to specific accounts, access control mechanisms, and auditing the attribution logs provides protection against adversaries attempting to create accounts.
PR.AA-02.01 Authentication of identity Mitigates T1136.001 Local Account
Comments
This diagnostic statement provides protection from Create Account through the implementation of privileged account management controls to limit credential access. Employing limitations to specific accounts, access control mechanisms, and auditing the attribution logs provides protection against adversaries attempting to create accounts.
PR.AA-02.01 Authentication of identity Mitigates T1098.006 Additional Container Cluster Roles
Comments
This diagnostic statement provides protection from Account Manipulation through the implementation of privileged account management controls to limit credential access. Employing limitations to specific accounts, access control mechanisms, and auditing the attribution logs provides protection against adversaries attempting to modify accounts.
PR.AA-02.01 Authentication of identity Mitigates T1098.005 Device Registration
Comments
This diagnostic statement provides protection from Account Manipulation through the implementation of privileged account management controls to limit credential access. Employing limitations to specific accounts, access control mechanisms, and auditing the attribution logs provides protection against adversaries attempting to modify accounts.
PR.AA-02.01 Authentication of identity Mitigates T1098.003 Additional Cloud Roles
Comments
This diagnostic statement provides protection from Account Manipulation through the implementation of privileged account management controls to limit credential access. Employing limitations to specific accounts, access control mechanisms, and auditing the attribution logs provides protection against adversaries attempting to modify accounts.
PR.AA-02.01 Authentication of identity Mitigates T1098.001 Additional Cloud Credentials
Comments
This diagnostic statement provides protection from Account Manipulation through the implementation of privileged account management controls to limit credential access. Employing limitations to specific accounts, access control mechanisms, and auditing the attribution logs provides protection against adversaries attempting to modify accounts.
PR.AA-02.01 Authentication of identity Mitigates T1586.003 Cloud Accounts
Comments
This diagnostic statement provides protection from Compromise Accounts through the implementation of privileged account management controls to limit credential access. Employing limitations to specific accounts, access control mechanisms, and auditing the attribution logs provides protection against adversaries attempting to modify accounts.
PR.AA-02.01 Authentication of identity Mitigates T1087.001 Local Account
Comments
This diagnostic statement provides protection from Create Account through the implementation of privileged account management controls to limit account access. Employing limitations to specific accounts, access control mechanisms, and auditing the attribution logs provides protection against adversaries attempting to create accounts.
PR.AA-02.01 Authentication of identity Mitigates T1087.002 Domain Account
Comments
This diagnostic statement provides protection from Create Account through the implementation of privileged account management controls to limit account access. Employing limitations to specific accounts, access control mechanisms, and auditing the attribution logs provides protection against adversaries attempting to create accounts.
PR.AA-02.01 Authentication of identity Mitigates T1078.001 Default Accounts
Comments
This diagnostic statement provides protection from Valid Accounts through the implementation of privileged account management controls to limit account access. Employing limitations to specific accounts, provisioning accounts, access control mechanisms, and auditing the attribution logs provides protection against adversaries attempting to use default accounts.
PR.AA-02.01 Authentication of identity Mitigates T1136 Create Account
Comments
This diagnostic statement provides protection from Create Account through the implementation of privileged account management controls to limit credential access. Employing limitations to specific accounts, access control mechanisms, and auditing the attribution logs provides protection against adversaries attempting to create accounts.
PR.AA-02.01 Authentication of identity Mitigates T1098 Account Manipulation
Comments
This diagnostic statement provides protection from Account Manipulation through the implementation of privileged account management controls to limit credential access. Employing limitations to specific accounts, access control mechanisms, and auditing the attribution logs provides protection against adversaries attempting to modify accounts.
PR.AA-02.01 Authentication of identity Mitigates T1078 Valid Accounts
Comments
This diagnostic statement provides protection from Valid Accounts through the implementation of privileged account management controls to limit account access. Employing limitations to specific accounts, provisioning accounts, access control mechanisms, and auditing the attribution logs provides protection against adversaries attempting to use existing accounts.
PR.AA-04.01 Access control within and across security perimeters Mitigates T1548 Abuse Elevation Control Mechanism
Comments
This diagnostic statement provides protection from Abuse Elevation Control Mechanism through the implementation of privileged account management controls to limit credential access. Employing limitations to specific accounts such as removing accounts from the Adminstrators group, access control mechanisms, and auditing the attribution logs provides some protection against adversaries attempting to abuse the elevation control mechanism.
PR.AA-04.01 Access control within and across security perimeters Mitigates T1565 Data Manipulation
Comments
This diagnostic statement provides protection from Data Manipulation through the implementation of privileged account management controls to limit credential access. Employing limitations to specific accounts, access control mechanisms, and auditing the attribution logs provides protection against adversaries attempting to modify data without being observed.
PR.AA-04.01 Access control within and across security perimeters Mitigates T1213 Data from Information Repositories
Comments
This diagnostic statement provides protection from Data from Information Repositories through the implementation of privileged account management controls to limit credential access. Employing limitations to specific accounts, access control mechanisms, and auditing the attribution logs provides protection against adversaries attempting to access sensitive data in information repositories.
PR.AA-04.01 Access control within and across security perimeters Mitigates T1098 Account Manipulation
Comments
This diagnostic statement provides protection from Account Manipulation through the implementation of privileged account management controls to limit credential access. Employing limitations to specific accounts, access control mechanisms, and auditing the attribution logs provides protection against adversaries attempting to modify accounts.
PR.AA-04.01 Access control within and across security perimeters Mitigates T1087.004 Cloud Account
Comments
This diagnostic statement provides protection from Cloud Account through the implementation of privileged account management controls to limit credential access. Employing limitations to specific accounts, access control mechanisms, and auditing the attribution logs provides protection against adversaries attempting to modify accounts.
PR.AA-03.03 Email verification mechanisms Mitigates T1114.003 Email Forwarding Rule
Comments
This diagnostic statement provides protection from adversaries that try to gain sensitive information and data from users via email. Utilizing methods such as encryption is recommended to minimize the risk of adversaries collecting user's credentials via email forwarding rules to collect credentials and other sensitive information.
PR.AA-03.03 Email verification mechanisms Mitigates T1114.002 Remote Email Collection
Comments
This diagnostic statement provides protection from adversaries that try to gain sensitive information and data from users via email. Utilizing methods such as encryption and MFA are recommended to minimize the risk of adversaries collecting user's credentials via exchange servers from within a network.
PR.AA-03.03 Email verification mechanisms Mitigates T1114.001 Local Email Collection
Comments
This diagnostic statement provides protection from adversaries that try to gain sensitive information and data from users via email. Utilizing methods such as encryption and using public cryptic keys are recommended to minimize the risk of adversaries collecting information from files saved on email servers and caches.
PR.AA-03.03 Email verification mechanisms Mitigates T1114 Email Collection
Comments
This diagnostic statement provides protection from adversaries that try to gain sensitive information and data from users via email. Utilizing methods such as MFA is recommended to minimize the risk of adversaries collecting usernames and passwords.
PR.AA-03.03 Email verification mechanisms Mitigates T1598 Phishing for Information
Comments
This diagnostic statement provides protection from phishing attacks through the implementation of software configuration methods, such as anti-spoofing and email authentication. Enabling mechanisms like, SPF and DKIM, add protection against adversaries that may send phishing messages through the form of emails, instant messages, etc. to gain sensitive information.
PR.AA-03.03 Email verification mechanisms Mitigates T1598.002 Spearphishing Attachment
Comments
This diagnostic statement provides protection from phishing attacks through the implementation of software configuration methods, such as anti-spoofing and email authentication. Enabling mechanisms like, SPF and DKIM, add protection against adversaries that may send spearphishing emails with a malicious attachment to gain elicit sensitive information.
PR.AA-03.03 Email verification mechanisms Mitigates T1598.003 Spearphishing Link
Comments
This diagnostic statement provides protection from phishing attacks through the implementation of software configuration methods, such as anti-spoofing and email authentication. Enabling mechanisms like, SPF and DKIM, add protection against adversaries that may send spearphishing emails with a malicious link to gain elicit sensitive information.
PR.AA-03.03 Email verification mechanisms Mitigates T1566.002 Spearphishing Link
Comments
This diagnostic statement provides protection from phishing attacks through the implementation of software configuration methods, such as anti-spoofing and email authentication. Enabling mechanisms like, SPF and DKIM, add protection against adversaries that may send spearphishing emails with a malicious link.
PR.AA-03.03 Email verification mechanisms Mitigates T1566.001 Spearphishing Attachment
Comments
This diagnostic statement provides protection from phishing attacks through the implementation of software configuration methods, such as anti-spoofing and email authentication. Enabling mechanisms like, SPF and DKIM, add protection against adversaries that may send spearphishing emails with a malicious attachment.
PR.AA-03.03 Email verification mechanisms Mitigates T1566 Phishing
Comments
This diagnostic statement provides protection from phishing attacks through the implementation of software configuration methods, such as anti-spoofing and email authentication.
PR.AA-05.01 Access privilege limitation Mitigates T1552.007 Container API
Comments
This diagnostic statement describes the implementation of least privilege principle, which can be applied to limiting permissions through role-based access controls, file and directory permissions, and the execution of systems and services. An adversary must already have high-level, admin or root level access on a local system to make full use of these ATT&CK techniques. Restrict users and accounts to the least privileges they require can help mitigate these techniques.
PR.AA-05.01 Access privilege limitation Mitigates T1505 Server Software Component
Comments
This diagnostic statement describes the implementation of least privilege principle, which can be applied to limiting permissions through role-based access controls, file and directory permissions, and the execution of systems and services. An adversary must already have high-level, admin or root level access on a local system to make full use of these ATT&CK techniques. Restrict users and accounts to the least privileges they require can help mitigate these techniques.
PR.AA-05.01 Access privilege limitation Mitigates T1578 Modify Cloud Compute Infrastructure
Comments
This diagnostic statement describes the implementation of least privilege principle, which can be applied to limiting permissions through role-based access controls, file and directory permissions, and the execution of systems and services. An adversary must already have high-level, admin or root level access on a local system to make full use of these ATT&CK techniques. Restrict users and accounts to the least privileges they require can help mitigate these techniques.
PR.AA-05.01 Access privilege limitation Mitigates T1562.012 Disable or Modify Linux Audit System
Comments
This diagnostic statement describes the implementation of least privilege principle, which can be applied to limiting permissions through role-based access controls, file and directory permissions, and the execution of systems and services. An adversary must already have high-level, admin or root level access on a local system to make full use of these ATT&CK techniques. Restrict users and accounts to the least privileges they require can help mitigate these techniques.
PR.AA-05.01 Access privilege limitation Mitigates T1610 Deploy Container
Comments
This diagnostic statement describes the implementation of least privilege principle, which can be applied to limiting permissions through role-based access controls, file and directory permissions, and the execution of systems and services. An adversary must already have high-level, admin or root level access on a local system to make full use of these ATT&CK techniques. Restrict users and accounts to the least privileges they require can help mitigate these techniques.
PR.AA-05.01 Access privilege limitation Mitigates T1613 Container and Resource Discovery
Comments
This diagnostic statement describes the implementation of least privilege principle, which can be applied to limiting permissions through role-based access controls, file and directory permissions, and the execution of systems and services. An adversary must already have high-level, admin or root level access on a local system to make full use of these ATT&CK techniques. Restrict users and accounts to the least privileges they require can help mitigate these techniques.
PR.AA-05.01 Access privilege limitation Mitigates T1609 Container Administration Command
Comments
This diagnostic statement describes the implementation of least privilege principle, which can be applied to limiting permissions through role-based access controls, file and directory permissions, and the execution of systems and services. An adversary must already have high-level, admin or root level access on a local system to make full use of these ATT&CK techniques. Restrict users and accounts to the least privileges they require can help mitigate these techniques.
PR.AA-05.01 Access privilege limitation Mitigates T1580 Cloud Infrastructure Discovery
Comments
This diagnostic statement describes the implementation of least privilege principle, which can be applied to limiting permissions through role-based access controls, file and directory permissions, and the execution of systems and services. An adversary must already have high-level, admin or root level access on a local system to make full use of these ATT&CK techniques. Restrict users and accounts to the least privileges they require can help mitigate these techniques.
PR.AA-05.01 Access privilege limitation Mitigates T1547.009 Shortcut Modification
Comments
This diagnostic statement describes the implementation of least privilege principle, which can be applied to limiting permissions through role-based access controls, file and directory permissions, and the execution of systems and services. An adversary must already have high-level, admin or root level access on a local system to make full use of these ATT&CK techniques. Restrict users and accounts to the least privileges they require can help mitigate these techniques.
PR.AA-05.01 Access privilege limitation Mitigates T1087.004 Cloud Account
Comments
This diagnostic statement describes the implementation of least privilege principle, which can be applied to limiting permissions through role-based access controls, file and directory permissions, and the execution of systems and services. An adversary must already have high-level, admin or root level access on a local system to make full use of these ATT&CK techniques. Restrict users and accounts to the least privileges they require can help mitigate these techniques.
PR.AA-05.01 Access privilege limitation Mitigates T1134.003 Make and Impersonate Token
Comments
This diagnostic statement describes the implementation of least privilege principle, which can be applied to limiting permissions through role-based access controls, file and directory permissions, and the execution of systems and services. An adversary must already have high-level, admin or root level access on a local system to make full use of these ATT&CK techniques. Restrict users and accounts to the least privileges they require can help mitigate these techniques.
PR.AA-05.01 Access privilege limitation Mitigates T1134.002 Create Process with Token
Comments
This diagnostic statement describes the implementation of least privilege principle, which can be applied to limiting permissions through role-based access controls, file and directory permissions, and the execution of systems and services. An adversary must already have high-level, admin or root level access on a local system to make full use of these ATT&CK techniques. Restrict users and accounts to the least privileges they require can help mitigate these techniques.
PR.AA-05.01 Access privilege limitation Mitigates T1134.001 Token Impersonation/Theft
Comments
This diagnostic statement describes the implementation of least privilege principle, which can be applied to limiting permissions through role-based access controls, file and directory permissions, and the execution of systems and services. An adversary must already have high-level, admin or root level access on a local system to make full use of these ATT&CK techniques. Restrict users and accounts to the least privileges they require can help mitigate these techniques.
PR.AA-05.01 Access privilege limitation Mitigates T1098 Account Manipulation
Comments
This diagnostic statement describes the implementation of least privilege principle, which can be applied to limiting permissions through role-based access controls, file and directory permissions, and the execution of systems and services. An adversary must already have high-level, admin or root level access on a local system to make full use of these ATT&CK techniques. Restrict users and accounts to the least privileges they require can help mitigate these techniques
PR.AA-05.01 Access privilege limitation Mitigates T1134 Access Token Manipulation
Comments
This diagnostic statement describes the implementation of least privilege principle, which can be applied to limiting permissions through role-based access controls, file and directory permissions, and the execution of systems and services. An adversary must already have high-level, admin or root level access on a local system to make full use of these ATT&CK techniques. Restrict users and accounts to the least privileges they require can help mitigate these techniques.
PR.AA-05.01 Access privilege limitation Mitigates T1574.012 COR_PROFILER
Comments
This diagnostic statement describes the implementation of least privilege principle, which can be applied to limiting permissions through role-based access controls, file and directory permissions, and the execution of systems and services. Ensure proper permissions are set for Registry hives to prevent users from modifying keys associated with COR_PROFILER.
PR.AA-05.01 Access privilege limitation Mitigates T1574.011 Services Registry Permissions Weakness
Comments
This diagnostic statement describes the implementation of least privilege principle, which can be applied to limiting permissions through role-based access controls, file and directory permissions, and the execution of systems and services. Ensure proper permissions are set for Registry hives to prevent users from modifying keys for logon scripts that may lead to persistence.
PR.AA-05.01 Access privilege limitation Mitigates T1574 Hijack Execution Flow
Comments
This diagnostic statement describes the implementation of least privilege principle, which can be applied to limiting permissions through role-based access controls, file and directory permissions, and the execution of systems and services. Ensure proper permissions are set for Registry hives to prevent users from modifying keys for logon scripts that may lead to persistence.
PR.AA-05.01 Access privilege limitation Mitigates T1037.001 Logon Script (Windows)
Comments
This diagnostic statement describes the implementation of least privilege principle, which can be applied to limiting permissions through role-based access controls, file and directory permissions, and the execution of systems and services. Ensure proper permissions are set for Registry hives to prevent users from modifying keys for logon scripts that may lead to persistence.
PR.AA-05.01 Access privilege limitation Mitigates T1037 Boot or Logon Initialization Scripts
Comments
This diagnostic statement describes the implementation of least privilege principle, which can be applied to limiting permissions through role-based access controls, file and directory permissions, and the execution of systems and services. Ensure proper permissions are set for Registry hives to prevent users from modifying keys for logon scripts that may lead to persistence.
PR.AA-05.01 Access privilege limitation Mitigates T1565 Data Manipulation
Comments
This diagnostic statement describes the implementation of least privilege principle, which can be applied to limiting permissions through role-based access controls, file and directory permissions, and the execution of systems and services. Ensure least privilege principles are applied to important information resources to reduce exposure to data manipulation risk.
PR.AA-05.01 Access privilege limitation Mitigates T1601 Modify System Image
Comments
This diagnostic statement describes the implementation of least privilege principle, which can be applied to limiting permissions through role-based access controls, file and directory permissions, and the execution of systems and services. Limit permissions associated with creating and modifying platform images or containers based on the principle of least privilege
PR.AA-05.01 Access privilege limitation Mitigates T1525 Implant Internal Image
Comments
This diagnostic statement describes the implementation of least privilege principle, which can be applied to limiting permissions through role-based access controls, file and directory permissions, and the execution of systems and services. Limit permissions associated with creating and modifying platform images or containers based on the principle of least privilege
PR.AA-05.01 Access privilege limitation Mitigates T1562.009 Safe Mode Boot
Comments
This diagnostic statement describes the implementation of least privilege principle, which can be applied to limiting permissions through role-based access controls, file and directory permissions, and the execution of systems and services. Restrict administrator accounts to as few individuals as possible, following least privilege principles, that may be abused to remotely boot a machine in safe mode.
PR.AA-05.01 Access privilege limitation Mitigates T1484.002 Trust Modification
Comments
This diagnostic statement describes the implementation of least privilege principle, which can be applied to limiting permissions through role-based access controls, file and directory permissions, and the execution of systems and services. Use the principal of least privilege and protect administrative access to domain trusts and identity tenants.
PR.AA-05.01 Access privilege limitation Mitigates T1484 Domain or Tenant Policy Modification
Comments
This diagnostic statement describes the implementation of least privilege principle, which can be applied to limiting permissions through role-based access controls, file and directory permissions, and the execution of systems and services. Use least privilege and protect administrative access to the Domain Controller and Active Directory Federation Services (AD FS) server.
PR.AA-05.01 Access privilege limitation Mitigates T1021 Remote Services
Comments
This diagnostic statement describes the implementation of least privilege principle, which can be applied to limiting permissions through role-based access controls, file and directory permissions, and the execution of systems and services. Limiting users' access to resources over network can help mitigate these techniques. Limiting access to file shares, remote access to systems, unnecessary services.
PR.AA-05.01 Access privilege limitation Mitigates T1200 Hardware Additions
Comments
This diagnostic statement describes the implementation of least privilege principle, which can be applied to limiting permissions through role-based access controls, file and directory permissions, and the execution of systems and services. Limiting users' access to resources over network can help mitigate these techniques. Establish network access control policies, such as using device certificates and the 802.1x standard. Restrict use of DHCP to registered devices to prevent unregistered devices from communicating with trusted systems.
PR.AA-05.01 Access privilege limitation Mitigates T1133 External Remote Services
Comments
This diagnostic statement describes the implementation of least privilege principle, which can be applied to limiting permissions through role-based access controls, file and directory permissions, and the execution of systems and services. Limiting users' access to resources over network can help mitigate these techniques. Limit access to remote services through centrally managed concentrators such as VPNs and other managed remote access systems.
PR.AA-05.01 Access privilege limitation Mitigates T1557 Adversary-in-the-Middle
Comments
This diagnostic statement describes the implementation of least privilege principle, which can be applied to limiting permissions through role-based access controls, file and directory permissions, and the execution of systems and services. Limiting users' access to resources over network can help mitigate these techniques. Limit access to network infrastructure and resources that can be used to reshape traffic or otherwise produce AiTM conditions.
PR.AA-05.01 Access privilege limitation Mitigates T1562 Impair Defenses
Comments
This diagnostic statement describes the implementation of least privilege principle, which can be applied to limiting permissions through role-based access controls, file and directory permissions, and the execution of systems and services. Ensure proper Registry permissions are in place to prevent unnecessary users and adversaries from disabling or interfering with security/logging services.
PR.AA-05.03 Service accounts Mitigates T1484.002 Trust Modification
Comments
This diagnostic statement is for the implementation of security controls for service accounts (i.e., accounts used by systems to access other systems). Protect administrative access to domain trusts and identity tenants to mitigate this technique.
PR.AA-05.03 Service accounts Mitigates T1021.003 Distributed Component Object Model
Comments
This diagnostic statement is for the implementation of security controls for service accounts (i.e., accounts used by systems to access other systems). Minimize service account permissions and access for the service to mitigate exploitation via Distributed Component Object Model (DCOM).
PR.AA-05.03 Service accounts Mitigates T1558.003 Kerberoasting
Comments
This diagnostic statement describes security controls implemented for service accounts (i.e., accounts used by systems to access other systems). Limit service accounts to minimal required privileges to mitigate attempts to steal or forge Kerberos tickets.
PR.AA-05.03 Service accounts Mitigates T1558.002 Silver Ticket
Comments
This diagnostic statement describes security controls implemented for service accounts (i.e., accounts used by systems to access other systems). Limit service accounts to minimal required privileges to mitigate attempts to steal or forge Kerberos tickets.
PR.AA-05.03 Service accounts Mitigates T1563.001 SSH Hijacking
Comments
This diagnostic statement is for the implementation of security controls for service accounts (i.e., accounts used by systems to access other systems), such as granting service accounts only the minimum necessary permissions.
PR.AA-05.03 Service accounts Mitigates T1078.002 Domain Accounts
Comments
This diagnostic statement describes how the organization establishes security standards based on industry guidelines to institute strict controls over service account (i.e., accounts used by systems to access other systems).
PR.AA-05.03 Service accounts Mitigates T1558 Steal or Forge Kerberos Tickets
Comments
This diagnostic statement describes security controls implemented for service accounts (i.e., accounts used by systems to access other systems). Limit service accounts to minimal required privileges to mitigate attempts to steal or forge Kerberos tickets.
PR.AA-05.03 Service accounts Mitigates T1548 Abuse Elevation Control Mechanism
Comments
This diagnostic statement describes how the organization establishes security standards based on industry guidelines to institute strict controls over service account (i.e., accounts used by systems to access other systems). Minimize permissions and access for service accounts to mitigate this technique.
PR.AA-05.03 Service accounts Mitigates T1559.001 Component Object Model
Comments
This diagnostic statement is for the implementation of security controls for service accounts (i.e., accounts used by systems to access other systems). Set service account access restrictions to grant only the minimum necessary permissions to mitigate abuse of inter-process communication (IPC) mechanisms.
PR.AA-05.03 Service accounts Mitigates T1078 Valid Accounts
Comments
This diagnostic statement describes how the organization establishes security standards based on industry guidelines to institute strict controls over service account (i.e., accounts used by systems to access other systems).
PR.AA-05.03 Service accounts Mitigates T1210 Exploitation of Remote Services
Comments
This diagnostic statement is for the implementation of security controls for service accounts (i.e., accounts used by systems to access other systems). Minimize permissions and access for service accounts to limit impact of exploitation.
PR.AA-05.03 Service accounts Mitigates T1098 Account Manipulation
Comments
This diagnostic statement describes how the organization establishes security standards based on industry guidelines to institute strict controls over service account (i.e., accounts used by systems to access other systems).
PR.AA-01.02 Physical and logical access Mitigates T1537 Transfer Data to Cloud Account
Comments
This diagnostic statement describes how the organization ensures users are identified and authenticated before accessing systems, applications, and hardware, with logical access controls permitting access only to authorized individuals with legitimate business needs. Logical access controls in relation to systems can refer to the use of MFA, user account management, and other role-based access control mechanisms to enforce policies for authentication and authorization of user accounts.
PR.AA-01.02 Physical and logical access Mitigates T1078.004 Cloud Accounts
Comments
This diagnostic statement describes how the organization ensures users are identified and authenticated before accessing systems, applications, and hardware, with logical access controls permitting access only to authorized individuals with legitimate business needs. Logical access controls in relation to systems can refer to the use of MFA, user account management, and other role-based access control mechanisms to enforce policies for authentication and authorization of user accounts.
PR.AA-01.02 Physical and logical access Mitigates T1078.003 Local Accounts
Comments
This diagnostic statement describes how the organization ensures users are identified and authenticated before accessing systems, applications, and hardware, with logical access controls permitting access only to authorized individuals with legitimate business needs. Logical access controls in relation to systems can refer to the use of MFA, user account management, and other role-based access control mechanisms to enforce policies for authentication and authorization of user accounts.
PR.AA-01.02 Physical and logical access Mitigates T1078.002 Domain Accounts
Comments
This diagnostic statement describes how the organization ensures users are identified and authenticated before accessing systems, applications, and hardware, with logical access controls permitting access only to authorized individuals with legitimate business needs. Logical access controls in relation to systems can refer to the use of MFA, user account management, and other role-based access control mechanisms to enforce policies for authentication and authorization of user accounts.
PR.AA-01.02 Physical and logical access Mitigates T1078.001 Default Accounts
Comments
This diagnostic statement describes how the organization ensures users are identified and authenticated before accessing systems, applications, and hardware, with logical access controls permitting access only to authorized individuals with legitimate business needs. Logical access controls in relation to systems can refer to the use of MFA, user account management, and other role-based access control mechanisms to enforce policies for authentication and authorization of user accounts.
PR.AA-01.02 Physical and logical access Mitigates T1563 Remote Service Session Hijacking
Comments
This diagnostic statement describes how the organization ensures users are identified and authenticated before accessing systems, applications, and hardware, with logical access controls permitting access only to authorized individuals with legitimate business needs. Logical access controls in relation to systems can refer to the use of MFA, user account management, and other role-based access control mechanisms to enforce policies for authentication and authorization of user accounts.
PR.AA-01.02 Physical and logical access Mitigates T1003 OS Credential Dumping
Comments
This diagnostic statement describes how the organization ensures users are identified and authenticated before accessing systems, applications, and hardware, with logical access controls permitting access only to authorized individuals with legitimate business needs. Logical access controls in relation to systems can refer to the use of MFA, user account management, and other role-based access control mechanisms to enforce policies for authentication and authorization of user accounts.
PR.AA-01.02 Physical and logical access Mitigates T1558 Steal or Forge Kerberos Tickets
Comments
This diagnostic statement describes how the organization ensures users are identified and authenticated before accessing systems, applications, and hardware, with logical access controls permitting access only to authorized individuals with legitimate business needs. Logical access controls in relation to systems can refer to the use of MFA, user account management, and other role-based access control mechanisms to enforce policies for authentication and authorization of user accounts.
PR.AA-01.02 Physical and logical access Mitigates T1047 Windows Management Instrumentation
Comments
This diagnostic statement describes how the organization ensures users are identified and authenticated before accessing systems, applications, and hardware, with logical access controls permitting access only to authorized individuals with legitimate business needs. Logical access controls in relation to systems can refer to the use of MFA, user account management, and other role-based access control mechanisms to enforce policies for authentication and authorization of user accounts.
PR.AA-01.02 Physical and logical access Mitigates T1072 Software Deployment Tools
Comments
This diagnostic statement describes how the organization ensures users are identified and authenticated before accessing systems, applications, and hardware, with logical access controls permitting access only to authorized individuals with legitimate business needs. Logical access controls in relation to systems can refer to the use of MFA, user account management, and other role-based access control mechanisms to enforce policies for authentication and authorization of user accounts.
PR.AA-01.02 Physical and logical access Mitigates T1021 Remote Services
Comments
This diagnostic statement describes how the organization ensures users are identified and authenticated before accessing systems, applications, and hardware, with logical access controls permitting access only to authorized individuals with legitimate business needs. Logical access controls in relation to systems can refer to the use of MFA, user account management, and other role-based access control mechanisms to enforce policies for authentication and authorization of user accounts.
PR.AA-01.02 Physical and logical access Mitigates T1578.005 Modify Cloud Compute Configurations
Comments
This diagnostic statement describes how the organization ensures users are identified and authenticated before accessing systems, applications, and hardware, with logical access controls permitting access only to authorized individuals with legitimate business needs. Logical access controls in relation to systems can refer to the use of MFA, user account management, and other role-based access control mechanisms to enforce policies for authentication and authorization of user accounts.
PR.AA-01.02 Physical and logical access Mitigates T1578 Modify Cloud Compute Infrastructure
Comments
This diagnostic statement describes how the organization ensures users are identified and authenticated before accessing systems, applications, and hardware, with logical access controls permitting access only to authorized individuals with legitimate business needs. Logical access controls in relation to systems can refer to the use of MFA, user account management, and other role-based access control mechanisms to enforce policies for authentication and authorization of user accounts.
PR.AA-01.02 Physical and logical access Mitigates T1556 Modify Authentication Process
Comments
This diagnostic statement describes how the organization ensures users are identified and authenticated before accessing systems, applications, and hardware, with logical access controls permitting access only to authorized individuals with legitimate business needs. Logical access controls in relation to systems can refer to the use of MFA, user account management, and other role-based access control mechanisms to enforce policies for authentication and authorization of user accounts.
PR.AA-01.02 Physical and logical access Mitigates T1562 Impair Defenses
Comments
This diagnostic statement describes how the organization ensures users are identified and authenticated before accessing systems, applications, and hardware, with logical access controls permitting access only to authorized individuals with legitimate business needs. Logical access controls in relation to systems can refer to the use of MFA, user account management, and other role-based access control mechanisms to enforce policies for authentication and authorization of user accounts.
PR.AA-01.02 Physical and logical access Mitigates T1657 Financial Theft
Comments
This diagnostic statement describes how the organization ensures users are identified and authenticated before accessing systems, applications, and hardware, with logical access controls permitting access only to authorized individuals with legitimate business needs. Logical access controls in relation to systems can refer to the use of MFA, user account management, and other role-based access control mechanisms to enforce policies for authentication and authorization of user accounts.
PR.AA-01.02 Physical and logical access Mitigates T1006 Direct Volume Access
Comments
This diagnostic statement describes how the organization ensures users are identified and authenticated before accessing systems, applications, and hardware, with logical access controls permitting access only to authorized individuals with legitimate business needs. Logical access controls in relation to systems can refer to the use of MFA, user account management, and other role-based access control mechanisms to enforce policies for authentication and authorization of user accounts.
PR.AA-01.02 Physical and logical access Mitigates T1213 Data from Information Repositories
Comments
This diagnostic statement describes how the organization ensures users are identified and authenticated before accessing systems, applications, and hardware, with logical access controls permitting access only to authorized individuals with legitimate business needs. Logical access controls in relation to systems can refer to the use of MFA, user account management, and other role-based access control mechanisms to enforce policies for authentication and authorization of user accounts.
PR.AA-01.02 Physical and logical access Mitigates T1530 Data from Cloud Storage
Comments
This diagnostic statement describes how the organization ensures users are identified and authenticated before accessing systems, applications, and hardware, with logical access controls permitting access only to authorized individuals with legitimate business needs. Logical access controls in relation to systems can refer to the use of MFA, user account management, and other role-based access control mechanisms to enforce policies for authentication and authorization of user accounts.
PR.AA-01.02 Physical and logical access Mitigates T1555.005 Password Managers
Comments
This diagnostic statement describes how the organization ensures users are identified and authenticated before accessing systems, applications, and hardware, with logical access controls permitting access only to authorized individuals with legitimate business needs. Logical access controls in relation to systems can refer to the use of MFA, user account management, and other role-based access control mechanisms to enforce policies for authentication and authorization of user accounts.
PR.AA-01.02 Physical and logical access Mitigates T1555.003 Credentials from Web Browsers
Comments
This diagnostic statement describes how the organization ensures users are identified and authenticated before accessing systems, applications, and hardware, with logical access controls permitting access only to authorized individuals with legitimate business needs. Logical access controls in relation to systems can refer to the use of MFA, user account management, and other role-based access control mechanisms to enforce policies for authentication and authorization of user accounts.
PR.AA-01.02 Physical and logical access Mitigates T1543.005 Container Service
Comments
This diagnostic statement describes how the organization ensures users are identified and authenticated before accessing systems, applications, and hardware, with logical access controls permitting access only to authorized individuals with legitimate business needs. Logical access controls in relation to systems can refer to the use of MFA, user account management, and other role-based access control mechanisms to enforce policies for authentication and authorization of user accounts.
PR.AA-01.02 Physical and logical access Mitigates T1543.002 Systemd Service
Comments
This diagnostic statement describes how the organization ensures users are identified and authenticated before accessing systems, applications, and hardware, with logical access controls permitting access only to authorized individuals with legitimate business needs. Logical access controls in relation to systems can refer to the use of MFA, user account management, and other role-based access control mechanisms to enforce policies for authentication and authorization of user accounts.
PR.AA-01.02 Physical and logical access Mitigates T1543 Create or Modify System Process
Comments
This diagnostic statement describes how the organization ensures users are identified and authenticated before accessing systems, applications, and hardware, with logical access controls permitting access only to authorized individuals with legitimate business needs. Logical access controls in relation to systems can refer to the use of MFA, user account management, and other role-based access control mechanisms to enforce policies for authentication and authorization of user accounts.
PR.AA-01.02 Physical and logical access Mitigates T1609 Container Administration Command
Comments
This diagnostic statement describes how the organization ensures users are identified and authenticated before accessing systems, applications, and hardware, with logical access controls permitting access only to authorized individuals with legitimate business needs. Logical access controls in relation to systems can refer to the use of MFA, user account management, and other role-based access control mechanisms to enforce policies for authentication and authorization of user accounts.
PR.AA-01.02 Physical and logical access Mitigates T1556.004 Network Device Authentication
Comments
This diagnostic statement describes how the organization ensures users are identified and authenticated before accessing systems, applications, and hardware, with logical access controls permitting access only to authorized individuals with legitimate business needs. Logical access controls in relation to systems can refer to the use of MFA, user account management, and other role-based access control mechanisms to enforce policies for authentication and authorization of user accounts.
PR.AA-01.02 Physical and logical access Mitigates T1059.008 Network Device CLI
Comments
This diagnostic statement describes how the organization ensures users are identified and authenticated before accessing systems, applications, and hardware, with logical access controls permitting access only to authorized individuals with legitimate business needs. Logical access controls in relation to systems can refer to the use of MFA, user account management, and other role-based access control mechanisms to enforce policies for authentication and authorization of user accounts.
PR.AA-01.02 Physical and logical access Mitigates T1619 Cloud Storage Object Discovery
Comments
This diagnostic statement describes how the organization ensures users are identified and authenticated before accessing systems, applications, and hardware, with logical access controls permitting access only to authorized individuals with legitimate business needs. Logical access controls in relation to systems can refer to the use of MFA, user account management, and other role-based access control mechanisms to enforce policies for authentication and authorization of user accounts.
PR.AA-01.02 Physical and logical access Mitigates T1538 Cloud Service Dashboard
Comments
This diagnostic statement describes how the organization ensures users are identified and authenticated before accessing systems, applications, and hardware, with logical access controls permitting access only to authorized individuals with legitimate business needs. Logical access controls in relation to systems can refer to the use of MFA, user account management, and other role-based access control mechanisms to enforce policies for authentication and authorization of user accounts.
PR.AA-01.02 Physical and logical access Mitigates T1580 Cloud Infrastructure Discovery
Comments
This diagnostic statement describes how the organization ensures users are identified and authenticated before accessing systems, applications, and hardware, with logical access controls permitting access only to authorized individuals with legitimate business needs. Logical access controls in relation to systems can refer to the use of MFA, user account management, and other role-based access control mechanisms to enforce policies for authentication and authorization of user accounts.
PR.AA-01.02 Physical and logical access Mitigates T1110 Brute Force
Comments
This diagnostic statement describes how the organization ensures users are identified and authenticated before accessing systems, applications, and hardware, with logical access controls permitting access only to authorized individuals with legitimate business needs. Logical access controls in relation to systems can refer to the use of MFA, user account management, and other role-based access control mechanisms to enforce policies for authentication and authorization of user accounts.
PR.AA-01.02 Physical and logical access Mitigates T1547.013 XDG Autostart Entries
Comments
This diagnostic statement describes how the organization ensures users are identified and authenticated before accessing systems, applications, and hardware, with logical access controls permitting access only to authorized individuals with legitimate business needs. Logical access controls in relation to systems can refer to the use of MFA, user account management, and other role-based access control mechanisms to enforce policies for authentication and authorization of user accounts.
PR.AA-01.02 Physical and logical access Mitigates T1547.012 Print Processors
Comments
This diagnostic statement describes how the organization ensures users are identified and authenticated before accessing systems, applications, and hardware, with logical access controls permitting access only to authorized individuals with legitimate business needs. Logical access controls in relation to systems can refer to the use of MFA, user account management, and other role-based access control mechanisms to enforce policies for authentication and authorization of user accounts.
PR.AA-01.02 Physical and logical access Mitigates T1547.009 Shortcut Modification
Comments
This diagnostic statement describes how the organization ensures users are identified and authenticated before accessing systems, applications, and hardware, with logical access controls permitting access only to authorized individuals with legitimate business needs. Logical access controls in relation to systems can refer to the use of MFA, user account management, and other role-based access control mechanisms to enforce policies for authentication and authorization of user accounts.
PR.AA-01.02 Physical and logical access Mitigates T1547.006 Kernel Modules and Extensions
Comments
This diagnostic statement describes how the organization ensures users are identified and authenticated before accessing systems, applications, and hardware, with logical access controls permitting access only to authorized individuals with legitimate business needs. Logical access controls in relation to systems can refer to the use of MFA, user account management, and other role-based access control mechanisms to enforce policies for authentication and authorization of user accounts.
PR.AA-01.02 Physical and logical access Mitigates T1547.004 Winlogon Helper DLL
Comments
This diagnostic statement describes how the organization ensures users are identified and authenticated before accessing systems, applications, and hardware, with logical access controls permitting access only to authorized individuals with legitimate business needs. Logical access controls in relation to systems can refer to the use of MFA, user account management, and other role-based access control mechanisms to enforce policies for authentication and authorization of user accounts.
PR.AA-01.02 Physical and logical access Mitigates T1197 BITS Jobs
Comments
This diagnostic statement describes how the organization ensures users are identified and authenticated before accessing systems, applications, and hardware, with logical access controls permitting access only to authorized individuals with legitimate business needs. Logical access controls in relation to systems can refer to the use of MFA, user account management, and other role-based access control mechanisms to enforce policies for authentication and authorization of user accounts.
PR.AA-01.02 Physical and logical access Mitigates T1020.001 Traffic Duplication
Comments
This diagnostic statement describes how the organization ensures users are identified and authenticated before accessing systems, applications, and hardware, with logical access controls permitting access only to authorized individuals with legitimate business needs. Logical access controls in relation to systems can refer to the use of MFA, user account management, and other role-based access control mechanisms to enforce policies for authentication and authorization of user accounts.
PR.AA-01.02 Physical and logical access Mitigates T1098.006 Additional Container Cluster Roles
Comments
This diagnostic statement describes how the organization ensures users are identified and authenticated before accessing systems, applications, and hardware, with logical access controls permitting access only to authorized individuals with legitimate business needs. Logical access controls in relation to systems can refer to the use of MFA, user account management, and other role-based access control mechanisms to enforce policies for authentication and authorization of user accounts.
PR.AA-01.02 Physical and logical access Mitigates T1098.004 SSH Authorized Keys
Comments
This diagnostic statement describes how the organization ensures users are identified and authenticated before accessing systems, applications, and hardware, with logical access controls permitting access only to authorized individuals with legitimate business needs. Logical access controls in relation to systems can refer to the use of MFA, user account management, and other role-based access control mechanisms to enforce policies for authentication and authorization of user accounts.
PR.AA-01.02 Physical and logical access Mitigates T1098.003 Additional Cloud Roles
Comments
This diagnostic statement describes how the organization ensures users are identified and authenticated before accessing systems, applications, and hardware, with logical access controls permitting access only to authorized individuals with legitimate business needs. Logical access controls in relation to systems can refer to the use of MFA, user account management, and other role-based access control mechanisms to enforce policies for authentication and authorization of user accounts.
PR.AA-01.02 Physical and logical access Mitigates T1098.001 Additional Cloud Credentials
Comments
This diagnostic statement describes how the organization ensures users are identified and authenticated before accessing systems, applications, and hardware, with logical access controls permitting access only to authorized individuals with legitimate business needs. Logical access controls in relation to systems can refer to the use of MFA, user account management, and other role-based access control mechanisms to enforce policies for authentication and authorization of user accounts.
PR.AA-01.02 Physical and logical access Mitigates T1098 Account Manipulation
Comments
This diagnostic statement describes how the organization ensures users are identified and authenticated before accessing systems, applications, and hardware, with logical access controls permitting access only to authorized individuals with legitimate business needs. Logical access controls in relation to systems can refer to the use of MFA, user account management, and other role-based access control mechanisms to enforce policies for authentication and authorization of user accounts.
PR.AA-01.02 Physical and logical access Mitigates T1087.004 Cloud Account
Comments
This diagnostic statement describes how the organization ensures users are identified and authenticated before accessing systems, applications, and hardware, with logical access controls permitting access only to authorized individuals with legitimate business needs. Logical access controls in relation to systems can refer to the use of MFA, user account management, and other role-based access control mechanisms to enforce policies for authentication and authorization of user accounts.
PR.AA-01.02 Physical and logical access Mitigates T1087 Account Discovery
Comments
This diagnostic statement describes how the organization ensures users are identified and authenticated before accessing systems, applications, and hardware, with logical access controls permitting access only to authorized individuals with legitimate business needs. Logical access controls in relation to systems can refer to the use of MFA, user account management, and other role-based access control mechanisms to enforce policies for authentication and authorization of user accounts.
PR.AA-01.02 Physical and logical access Mitigates T1134.003 Make and Impersonate Token
Comments
This diagnostic statement describes how the organization ensures users are identified and authenticated before accessing systems, applications, and hardware, with logical access controls permitting access only to authorized individuals with legitimate business needs. Logical access controls in relation to systems can refer to the use of MFA, user account management, and other role-based access control mechanisms to enforce policies for authentication and authorization of user accounts.
PR.AA-01.02 Physical and logical access Mitigates T1134.002 Create Process with Token
Comments
This diagnostic statement describes how the organization ensures users are identified and authenticated before accessing systems, applications, and hardware, with logical access controls permitting access only to authorized individuals with legitimate business needs. Logical access controls in relation to systems can refer to the use of MFA, user account management, and other role-based access control mechanisms to enforce policies for authentication and authorization of user accounts.
PR.AA-01.02 Physical and logical access Mitigates T1134.001 Token Impersonation/Theft
Comments
This diagnostic statement describes how the organization ensures users are identified and authenticated before accessing systems, applications, and hardware, with logical access controls permitting access only to authorized individuals with legitimate business needs. Logical access controls in relation to systems can refer to the use of MFA, user account management, and other role-based access control mechanisms to enforce policies for authentication and authorization of user accounts.
PR.AA-01.02 Physical and logical access Mitigates T1134 Access Token Manipulation
Comments
This diagnostic statement describes how the organization ensures users are identified and authenticated before accessing systems, applications, and hardware, with logical access controls permitting access only to authorized individuals with legitimate business needs. Logical access controls in relation to systems can refer to the use of MFA, user account management, and other role-based access control mechanisms to enforce policies for authentication and authorization of user accounts.
PR.AA-01.02 Physical and logical access Mitigates T1548.005 Temporary Elevated Cloud Access
Comments
This diagnostic statement describes how the organization ensures users are identified and authenticated before accessing systems, applications, and hardware, with logical access controls permitting access only to authorized individuals with legitimate business needs. Logical access controls in relation to systems can refer to the use of MFA, user account management, and other role-based access control mechanisms to enforce policies for authentication and authorization of user accounts.
PR.AA-01.02 Physical and logical access Mitigates T1548 Abuse Elevation Control Mechanism
Comments
This diagnostic statement describes how the organization ensures users are identified and authenticated before accessing systems, applications, and hardware, with logical access controls permitting access only to authorized individuals with legitimate business needs. Logical access controls in relation to systems can refer to the use of MFA, user account management, and other role-based access control mechanisms to enforce policies for authentication and authorization of user accounts.
PR.AA-01.02 Physical and logical access Mitigates T1078 Valid Accounts
Comments
This diagnostic statement describes how the organization ensures users are identified and authenticated before accessing systems, applications, and hardware, with logical access controls permitting access only to authorized individuals with legitimate business needs. Logical access controls in relation to systems can refer to the use of MFA, user account management, and other role-based access control mechanisms to enforce policies for authentication and authorization of user accounts.
PR.AA-03.01 Authentication requirements Mitigates T1555.005 Password Managers
Comments
This diagnostic statement describes how the organization implement appropriate authentication requirements, including selecting mechanisms based on risk, utilizing multi-factor authentication where necessary, and safeguarding the storage of authenticators like pins and passwords to protect sensitive access credentials.
PR.AA-03.01 Authentication requirements Mitigates T1609 Container Administration Command
Comments
This diagnostic statement describes how the organization implement appropriate authentication requirements, including selecting mechanisms based on risk, utilizing multi-factor authentication where necessary, and safeguarding the storage of authenticators like pins and passwords to protect sensitive access credentials.
PR.AA-03.01 Authentication requirements Mitigates T1059.008 Network Device CLI
Comments
This diagnostic statement describes how the organization implement appropriate authentication requirements, including selecting mechanisms based on risk, utilizing multi-factor authentication where necessary, and safeguarding the storage of authenticators like pins and passwords to protect sensitive access credentials.
PR.AA-03.01 Authentication requirements Mitigates T1555.005 Password Managers
Comments
This diagnostic statement describes how the organization implement appropriate authentication requirements, including selecting mechanisms based on risk, utilizing multi-factor authentication where necessary, and safeguarding the storage of authenticators like pins and passwords to protect sensitive access credentials.
PR.AA-03.01 Authentication requirements Mitigates T1651 Cloud Administration Command
Comments
This diagnostic statement describes how the organization implement appropriate authentication requirements, including selecting mechanisms based on risk, utilizing multi-factor authentication where necessary, and safeguarding the storage of authenticators like pins and passwords to protect sensitive access credentials.
PR.AA-03.01 Authentication requirements Mitigates T1552 Unsecured Credentials
Comments
This diagnostic statement describes how the organization implement appropriate authentication requirements, including selecting mechanisms based on risk, utilizing multi-factor authentication where necessary, and safeguarding the storage of authenticators like pins and passwords to protect sensitive access credentials.
PR.AA-03.01 Authentication requirements Mitigates T1555 Credentials from Password Stores
Comments
This diagnostic statement describes how the organization implement appropriate authentication requirements, including selecting mechanisms based on risk, utilizing multi-factor authentication where necessary, and safeguarding the storage of authenticators like pins and passwords to protect sensitive access credentials.
PR.AA-03.01 Authentication requirements Mitigates T1649 Steal or Forge Authentication Certificates
Comments
This diagnostic statement describes how the organization implement appropriate authentication requirements, including selecting mechanisms based on risk, utilizing multi-factor authentication where necessary, and safeguarding the storage of authenticators like pins and passwords to protect sensitive access credentials.
PR.AA-03.01 Authentication requirements Mitigates T1556 Modify Authentication Process
Comments
This diagnostic statement describes how the organization implement appropriate authentication requirements, including selecting mechanisms based on risk, utilizing multi-factor authentication where necessary, and safeguarding the storage of authenticators like pins and passwords to protect sensitive access credentials.
PR.AA-03.01 Authentication requirements Mitigates T1558 Steal or Forge Kerberos Tickets
Comments
This diagnostic statement describes how the organization implement appropriate authentication requirements, including selecting mechanisms based on risk, utilizing multi-factor authentication where necessary, and safeguarding the storage of authenticators like pins and passwords to protect sensitive access credentials.
PR.AA-03.01 Authentication requirements Mitigates T1003.001 LSASS Memory
Comments
This diagnostic statement describes how the organization implement appropriate authentication requirements, including selecting mechanisms based on risk, utilizing multi-factor authentication where necessary, and safeguarding the storage of authenticators like pins and passwords to protect sensitive access credentials.
PR.AA-03.01 Authentication requirements Mitigates T1003 OS Credential Dumping
Comments
This diagnostic statement describes how the organization implement appropriate authentication requirements, including selecting mechanisms based on risk, utilizing multi-factor authentication where necessary, and safeguarding the storage of authenticators like pins and passwords to protect sensitive access credentials.
PR.AA-03.01 Authentication requirements Mitigates T1550 Use Alternate Authentication Material
Comments
This diagnostic statement describes how the organization implement appropriate authentication requirements, including selecting mechanisms based on risk, utilizing multi-factor authentication where necessary, and safeguarding the storage of authenticators like pins and passwords to protect sensitive access credentials.
PR.AA-03.01 Authentication requirements Mitigates T1187 Forced Authentication
Comments
This diagnostic statement describes how the organization implement appropriate authentication requirements, including selecting mechanisms based on risk, utilizing multi-factor authentication where necessary, and safeguarding the storage of authenticators like pins and passwords to protect sensitive access credentials.
PR.AA-03.01 Authentication requirements Mitigates T1556 Modify Authentication Process
Comments
This diagnostic statement describes how the organization implement appropriate authentication requirements, including selecting mechanisms based on risk, utilizing multi-factor authentication where necessary, and safeguarding the storage of authenticators like pins and passwords to protect sensitive access credentials.
PR.AA-03.01 Authentication requirements Mitigates T1078.004 Cloud Accounts
Comments
This diagnostic statement describes how the organization implement appropriate authentication requirements, including selecting mechanisms based on risk, utilizing multi-factor authentication where necessary, and safeguarding the storage of authenticators like pins and passwords to protect sensitive access credentials.
PR.AA-03.01 Authentication requirements Mitigates T1078.003 Local Accounts
Comments
This diagnostic statement describes how the organization implement appropriate authentication requirements, including selecting mechanisms based on risk, utilizing multi-factor authentication where necessary, and safeguarding the storage of authenticators like pins and passwords to protect sensitive access credentials.
PR.AA-03.01 Authentication requirements Mitigates T1078.002 Domain Accounts
Comments
This diagnostic statement describes how the organization implement appropriate authentication requirements, including selecting mechanisms based on risk, utilizing multi-factor authentication where necessary, and safeguarding the storage of authenticators like pins and passwords to protect sensitive access credentials.
PR.AA-03.01 Authentication requirements Mitigates T1078.001 Default Accounts
Comments
This diagnostic statement describes how the organization implement appropriate authentication requirements, including selecting mechanisms based on risk, utilizing multi-factor authentication where necessary, and safeguarding the storage of authenticators like pins and passwords to protect sensitive access credentials.
PR.AA-03.01 Authentication requirements Mitigates T1078 Valid Accounts
Comments
This diagnostic statement describes how the organization implement appropriate authentication requirements, including selecting mechanisms based on risk, utilizing multi-factor authentication where necessary, and safeguarding the storage of authenticators like pins and passwords to protect sensitive access credentials.
PR.AA-03.01 Authentication requirements Mitigates T1539 Steal Web Session Cookie
Comments
This diagnostic statement describes how the organization implement appropriate authentication requirements, including selecting mechanisms based on risk, utilizing multi-factor authentication where necessary, and safeguarding the storage of authenticators like pins and passwords to protect sensitive access credentials.
PR.AA-03.01 Authentication requirements Mitigates T1072 Software Deployment Tools
Comments
This diagnostic statement describes how the organization implement appropriate authentication requirements, including selecting mechanisms based on risk, utilizing multi-factor authentication where necessary, and safeguarding the storage of authenticators like pins and passwords to protect sensitive access credentials.
PR.AA-03.01 Authentication requirements Mitigates T1021.007 Cloud Services
Comments
This diagnostic statement describes how the organization implement appropriate authentication requirements, including selecting mechanisms based on risk, utilizing multi-factor authentication where necessary, and safeguarding the storage of authenticators like pins and passwords to protect sensitive access credentials.
PR.AA-03.01 Authentication requirements Mitigates T1021.004 SSH
Comments
This diagnostic statement describes how the organization implement appropriate authentication requirements, including selecting mechanisms based on risk, utilizing multi-factor authentication where necessary, and safeguarding the storage of authenticators like pins and passwords to protect sensitive access credentials.
PR.AA-03.01 Authentication requirements Mitigates T1021.001 Remote Desktop Protocol
Comments
This diagnostic statement describes how the organization implement appropriate authentication requirements, including selecting mechanisms based on risk, utilizing multi-factor authentication where necessary, and safeguarding the storage of authenticators like pins and passwords to protect sensitive access credentials.
PR.AA-03.01 Authentication requirements Mitigates T1021 Remote Services
Comments
This diagnostic statement describes how the organization implement appropriate authentication requirements, including selecting mechanisms based on risk, utilizing multi-factor authentication where necessary, and safeguarding the storage of authenticators like pins and passwords to protect sensitive access credentials.
PR.AA-03.01 Authentication requirements Mitigates T1599.001 Network Address Translation Traversal
Comments
This diagnostic statement describes how the organization implement appropriate authentication requirements, including selecting mechanisms based on risk, utilizing multi-factor authentication where necessary, and safeguarding the storage of authenticators like pins and passwords to protect sensitive access credentials.
PR.AA-03.01 Authentication requirements Mitigates T1599 Network Boundary Bridging
Comments
This diagnostic statement describes how the organization implement appropriate authentication requirements, including selecting mechanisms based on risk, utilizing multi-factor authentication where necessary, and safeguarding the storage of authenticators like pins and passwords to protect sensitive access credentials.
PR.AA-03.01 Authentication requirements Mitigates T1601.002 Downgrade System Image
Comments
This diagnostic statement describes how the organization implement appropriate authentication requirements, including selecting mechanisms based on risk, utilizing multi-factor authentication where necessary, and safeguarding the storage of authenticators like pins and passwords to protect sensitive access credentials.
PR.AA-03.01 Authentication requirements Mitigates T1601.001 Patch System Image
Comments
This diagnostic statement describes how the organization implement appropriate authentication requirements, including selecting mechanisms based on risk, utilizing multi-factor authentication where necessary, and safeguarding the storage of authenticators like pins and passwords to protect sensitive access credentials.
PR.AA-03.01 Authentication requirements Mitigates T1601 Modify System Image
Comments
This diagnostic statement describes how the organization implement appropriate authentication requirements, including selecting mechanisms based on risk, utilizing multi-factor authentication where necessary, and safeguarding the storage of authenticators like pins and passwords to protect sensitive access credentials.
PR.AA-03.01 Authentication requirements Mitigates T1556.007 Hybrid Identity
Comments
This diagnostic statement describes how the organization implement appropriate authentication requirements, including selecting mechanisms based on risk, utilizing multi-factor authentication where necessary, and safeguarding the storage of authenticators like pins and passwords to protect sensitive access credentials.
PR.AA-03.01 Authentication requirements Mitigates T1556.006 Multi-Factor Authentication
Comments
This diagnostic statement describes how the organization implement appropriate authentication requirements, including selecting mechanisms based on risk, utilizing multi-factor authentication where necessary, and safeguarding the storage of authenticators like pins and passwords to protect sensitive access credentials.
PR.AA-03.01 Authentication requirements Mitigates T1556.004 Network Device Authentication
Comments
This diagnostic statement describes how the organization implement appropriate authentication requirements, including selecting mechanisms based on risk, utilizing multi-factor authentication where necessary, and safeguarding the storage of authenticators like pins and passwords to protect sensitive access credentials.
PR.AA-03.01 Authentication requirements Mitigates T1556.001 Domain Controller Authentication
Comments
This diagnostic statement describes how the organization implement appropriate authentication requirements, including selecting mechanisms based on risk, utilizing multi-factor authentication where necessary, and safeguarding the storage of authenticators like pins and passwords to protect sensitive access credentials.
PR.AA-03.01 Authentication requirements Mitigates T1556 Modify Authentication Process
Comments
This diagnostic statement describes how the organization implement appropriate authentication requirements, including selecting mechanisms based on risk, utilizing multi-factor authentication where necessary, and safeguarding the storage of authenticators like pins and passwords to protect sensitive access credentials.
PR.AA-03.01 Authentication requirements Mitigates T1133 External Remote Services
Comments
This diagnostic statement describes how the organization implement appropriate authentication requirements, including selecting mechanisms based on risk, utilizing multi-factor authentication where necessary, and safeguarding the storage of authenticators like pins and passwords to protect sensitive access credentials.
PR.AA-03.01 Authentication requirements Mitigates T1114 Email Collection
Comments
This diagnostic statement describes how the organization implement appropriate authentication requirements, including selecting mechanisms based on risk, utilizing multi-factor authentication where necessary, and safeguarding the storage of authenticators like pins and passwords to protect sensitive access credentials.
PR.AA-03.01 Authentication requirements Mitigates T1593.003 Code Repositories
Comments
This diagnostic statement describes how the organization implement appropriate authentication requirements, including selecting mechanisms based on risk, utilizing multi-factor authentication where necessary, and safeguarding the storage of authenticators like pins and passwords to protect sensitive access credentials.
PR.AA-03.01 Authentication requirements Mitigates T1213 Data from Information Repositories
Comments
This diagnostic statement describes how the organization implement appropriate authentication requirements, including selecting mechanisms based on risk, utilizing multi-factor authentication where necessary, and safeguarding the storage of authenticators like pins and passwords to protect sensitive access credentials.
PR.AA-03.01 Authentication requirements Mitigates T1530 Data from Cloud Storage
Comments
This diagnostic statement describes how the organization implement appropriate authentication requirements, including selecting mechanisms based on risk, utilizing multi-factor authentication where necessary, and safeguarding the storage of authenticators like pins and passwords to protect sensitive access credentials.
PR.AA-03.01 Authentication requirements Mitigates T1136.003 Cloud Account
Comments
This diagnostic statement describes how the organization implement appropriate authentication requirements, including selecting mechanisms based on risk, utilizing multi-factor authentication where necessary, and safeguarding the storage of authenticators like pins and passwords to protect sensitive access credentials.
PR.AA-03.01 Authentication requirements Mitigates T1136.002 Domain Account
Comments
This diagnostic statement describes how the organization implement appropriate authentication requirements, including selecting mechanisms based on risk, utilizing multi-factor authentication where necessary, and safeguarding the storage of authenticators like pins and passwords to protect sensitive access credentials.
PR.AA-03.01 Authentication requirements Mitigates T1136.001 Local Account
Comments
This diagnostic statement describes how the organization implement appropriate authentication requirements, including selecting mechanisms based on risk, utilizing multi-factor authentication where necessary, and safeguarding the storage of authenticators like pins and passwords to protect sensitive access credentials.
PR.AA-03.01 Authentication requirements Mitigates T1136 Create Account
Comments
This diagnostic statement describes how the organization implement appropriate authentication requirements, including selecting mechanisms based on risk, utilizing multi-factor authentication where necessary, and safeguarding the storage of authenticators like pins and passwords to protect sensitive access credentials.
PR.AA-03.01 Authentication requirements Mitigates T1110.002 Password Cracking
Comments
This diagnostic statement describes how the organization implement appropriate authentication requirements, including selecting mechanisms based on risk, utilizing multi-factor authentication where necessary, and safeguarding the storage of authenticators like pins and passwords to protect sensitive access credentials.
PR.AA-03.01 Authentication requirements Mitigates T1110.004 Credential Stuffing
Comments
This diagnostic statement describes how the organization implement appropriate authentication requirements, including selecting mechanisms based on risk, utilizing multi-factor authentication where necessary, and safeguarding the storage of authenticators like pins and passwords to protect sensitive access credentials.
PR.AA-03.01 Authentication requirements Mitigates T1110.003 Password Spraying
Comments
This diagnostic statement describes how the organization implement appropriate authentication requirements, including selecting mechanisms based on risk, utilizing multi-factor authentication where necessary, and safeguarding the storage of authenticators like pins and passwords to protect sensitive access credentials.
PR.AA-03.01 Authentication requirements Mitigates T1110.001 Password Guessing
Comments
This diagnostic statement describes how the organization implement appropriate authentication requirements, including selecting mechanisms based on risk, utilizing multi-factor authentication where necessary, and safeguarding the storage of authenticators like pins and passwords to protect sensitive access credentials.
PR.AA-03.01 Authentication requirements Mitigates T1110 Brute Force
Comments
This diagnostic statement describes how the organization implement appropriate authentication requirements, including selecting mechanisms based on risk, utilizing multi-factor authentication where necessary, and safeguarding the storage of authenticators like pins and passwords to protect sensitive access credentials.
PR.AA-03.01 Authentication requirements Mitigates T1098.006 Additional Container Cluster Roles
Comments
This diagnostic statement describes how the organization implement appropriate authentication requirements, including selecting mechanisms based on risk, utilizing multi-factor authentication where necessary, and safeguarding the storage of authenticators like pins and passwords to protect sensitive access credentials.
PR.AA-03.01 Authentication requirements Mitigates T1098.005 Device Registration
Comments
This diagnostic statement describes how the organization implement appropriate authentication requirements, including selecting mechanisms based on risk, utilizing multi-factor authentication where necessary, and safeguarding the storage of authenticators like pins and passwords to protect sensitive access credentials.
PR.AA-03.01 Authentication requirements Mitigates T1098.003 Additional Cloud Roles
Comments
This diagnostic statement describes how the organization implement appropriate authentication requirements, including selecting mechanisms based on risk, utilizing multi-factor authentication where necessary, and safeguarding the storage of authenticators like pins and passwords to protect sensitive access credentials.
PR.AA-03.01 Authentication requirements Mitigates T1098.001 Additional Cloud Credentials
Comments
This diagnostic statement describes how the organization implement appropriate authentication requirements, including selecting mechanisms based on risk, utilizing multi-factor authentication where necessary, and safeguarding the storage of authenticators like pins and passwords to protect sensitive access credentials.
PR.AA-03.01 Authentication requirements Mitigates T1098 Account Manipulation
Comments
This diagnostic statement describes how the organization implement appropriate authentication requirements, including selecting mechanisms based on risk, utilizing multi-factor authentication where necessary, and safeguarding the storage of authenticators like pins and passwords to protect sensitive access credentials.
PR.AA-05.04 Third-party access management Mitigates T1078 Valid Accounts
Comments
This diagnostic statement includes implementation of controls for third-party access to an organization’s systems. Conditional access policies can be used to block logins from non-compliant devices or from outside defined IP ranges.
PR.AA-05.04 Third-party access management Mitigates T1110 Brute Force
Comments
This diagnostic statement includes implementation of controls for third-party access to an organization’s systems. Enforcing third-party account use policies to include account lockout policies after a certain number of failed login attempts mitigates the risk of brute-force attacks.
PR.AA-05.04 Third-party access management Mitigates T1199 Trusted Relationship
Comments
This diagnostic statement includes implementation of controls for third-party access to an organization’s systems. Manage accounts and permissions used by parties in trusted relationships to minimize potential abuse by the party or if the party is compromised by an adversary.
PR.AA-01.01 Identity and credential management Mitigates T1003 OS Credential Dumping
Comments
This diagnostic statement protects against OS Credential Dumping through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1003.001 LSASS Memory
Comments
This diagnostic statement protects against LSASS Memory through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1003.002 Security Account Manager
Comments
This diagnostic statement protects against Security Account Manager through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1003.003 NTDS
Comments
This diagnostic statement protects against NTDS through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1003.004 LSA Secrets
Comments
This diagnostic statement protects against LSA Secrets through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1003.005 Cached Domain Credentials
Comments
This diagnostic statement protects against Cached Domain Credentials through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1003.006 DCSync
Comments
This diagnostic statement protects against DCSync through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1003.007 Proc Filesystem
Comments
This diagnostic statement protects against Proc Filesystem through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1003.008 /etc/passwd and /etc/shadow
Comments
This diagnostic statement protects against /etc/passwd and /etc/shadow through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1006 Direct Volume Access
Comments
This diagnostic statement protects against Direct Volume Access through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1020.001 Traffic Duplication
Comments
This diagnostic statement protects against Traffic Duplication through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1021 Remote Services
Comments
This diagnostic statement protects against Remote Services through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1021.001 Remote Desktop Protocol
Comments
This diagnostic statement protects against Remote Desktop Protocol through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1021.002 SMB/Windows Admin Shares
Comments
This diagnostic statement protects against SMB/Windows Admin Shares through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1021.004 SSH
Comments
This diagnostic statement protects against SSH through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1021.007 Cloud Services
Comments
This diagnostic statement protects against Cloud Services through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1021.008 Direct Cloud VM Connections
Comments
This diagnostic statement protects against Direct Cloud VM Connections through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1036 Masquerading
Comments
This diagnostic statement protects against Masquerading through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1036.010 Masquerade Account Name
Comments
This diagnostic statement protects against Masquerade Account Name through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1040 Network Sniffing
Comments
This diagnostic statement protects against Network Sniffing through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1047 Windows Management Instrumentation
Comments
This diagnostic statement protects against Windows Management Instrumentation through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1048 Exfiltration Over Alternative Protocol
Comments
This diagnostic statement protects against Exfiltration Over Alternative Protocol through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1053 Scheduled Task/Job
Comments
This diagnostic statement protects against Scheduled Task/Job through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1053.002 At
Comments
This diagnostic statement protects against At through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1053.003 Cron
Comments
This diagnostic statement protects against Cron through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1053.005 Scheduled Task
Comments
This diagnostic statement protects against Scheduled Task through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1053.006 Systemd Timers
Comments
This diagnostic statement protects against Systemd Timers through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1053.007 Container Orchestration Job
Comments
This diagnostic statement protects against Container Orchestration Job through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1059 Command and Scripting Interpreter
Comments
This diagnostic statement protects against Command and Scripting Interpreter through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1059.008 Network Device CLI
Comments
This diagnostic statement protects against Network Device CLI through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1072 Software Deployment Tools
Comments
This diagnostic statement protects against Software Deployment Tools through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1078 Valid Accounts
Comments
This diagnostic statement protects against Valid Accounts through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1078.001 Default Accounts
Comments
This diagnostic statement protects against Default Accounts through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1078.002 Domain Accounts
Comments
This diagnostic statement protects against Domain Accounts through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1078.003 Local Accounts
Comments
This diagnostic statement protects against Local Accounts through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1078.004 Cloud Accounts
Comments
This diagnostic statement protects against Cloud Accounts through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1087 Account Discovery
Comments
This diagnostic statement protects against Account Discovery through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1087.004 Cloud Account
Comments
This diagnostic statement protects against Cloud Account through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1098 Account Manipulation
Comments
This diagnostic statement protects against Account Manipulation through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1098.001 Additional Cloud Credentials
Comments
This diagnostic statement protects against Additional Cloud Credentials through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1098.002 Additional Email Delegate Permissions
Comments
This diagnostic statement protects against Additional Email Delegate Permissions through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1098.003 Additional Cloud Roles
Comments
This diagnostic statement protects against Additional Cloud Roles through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1098.004 SSH Authorized Keys
Comments
This diagnostic statement protects against SSH Authorized Keys through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1098.005 Device Registration
Comments
This diagnostic statement protects against Device Registration through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1098.006 Additional Container Cluster Roles
Comments
This diagnostic statement protects against Additional Container Cluster Roles through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1110 Brute Force
Comments
This diagnostic statement protects against Brute Force through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1110.001 Password Guessing
Comments
This diagnostic statement protects against Password Guessing through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1110.002 Password Cracking
Comments
This diagnostic statement protects against Password Cracking through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1110.003 Password Spraying
Comments
This diagnostic statement protects against Password Spraying through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1110.004 Credential Stuffing
Comments
This diagnostic statement protects against Credential Stuffing through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1114 Email Collection
Comments
This diagnostic statement protects against Email Collection through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1114.002 Remote Email Collection
Comments
This diagnostic statement protects against Remote Email Collection through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1133 External Remote Services
Comments
This diagnostic statement protects against External Remote Services through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1134 Access Token Manipulation
Comments
This diagnostic statement protects against Access Token Manipulation through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1134.001 Token Impersonation/Theft
Comments
This diagnostic statement protects against Token Impersonation/Theft through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1134.002 Create Process with Token
Comments
This diagnostic statement protects against Create Process with Token through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1134.003 Make and Impersonate Token
Comments
This diagnostic statement protects against Make and Impersonate Token through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1134.005 SID-History Injection
Comments
This diagnostic statement protects against SID-History Injection through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1136 Create Account
Comments
This diagnostic statement protects against Create Account through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1136.001 Local Account
Comments
This diagnostic statement protects against Local Account through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1136.002 Domain Account
Comments
This diagnostic statement protects against Domain Account through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1136.003 Cloud Account
Comments
This diagnostic statement protects against Cloud Account through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1185 Browser Session Hijacking
Comments
This diagnostic statement protects against Browser Session Hijacking through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1187 Forced Authentication
Comments
This diagnostic statement protects against Forced Authentication through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1195 Supply Chain Compromise
Comments
This diagnostic statement protects against Supply Chain Compromise through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1197 BITS Jobs
Comments
This diagnostic statement protects against BITS Jobs through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1199 Trusted Relationship
Comments
This diagnostic statement protects against Trusted Relationship through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1201 Password Policy Discovery
Comments
This diagnostic statement protects against Password Policy Discovery through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1213 Data from Information Repositories
Comments
This diagnostic statement protects against Data from Information Repositories through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1213.001 Confluence
Comments
This diagnostic statement protects against Confluence through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1213.002 Sharepoint
Comments
This diagnostic statement protects against Sharepoint through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1213.003 Code Repositories
Comments
This diagnostic statement protects against Code Repositories through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1213.004 Customer Relationship Management Software
Comments
This diagnostic statement protects against Customer Relationship Management Software through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1484 Domain or Tenant Policy Modification
Comments
This diagnostic statement protects against Domain or Tenant Policy Modification through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1484.001 Group Policy Modification
Comments
This diagnostic statement protects against Group Policy Modification through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1484.002 Trust Modification
Comments
This diagnostic statement protects against Trust Modification through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1485 Data Destruction
Comments
This diagnostic statement protects against Data Destruction through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1485.001 Lifecycle-Triggered Deletion
Comments
This diagnostic statement protects against Lifecycle-Triggered Deletion through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1489 Service Stop
Comments
This diagnostic statement protects against Service Stop through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1490 Inhibit System Recovery
Comments
This diagnostic statement protects against Inhibit System Recovery through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1505 Server Software Component
Comments
This diagnostic statement protects against Server Software Component through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1505.003 Web Shell
Comments
This diagnostic statement protects against Web Shell through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1528 Steal Application Access Token
Comments
This diagnostic statement protects against Steal Application Access Token through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1530 Data from Cloud Storage
Comments
This diagnostic statement protects against Data from Cloud Storage through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1537 Transfer Data to Cloud Account
Comments
This diagnostic statement protects against Transfer Data to Cloud Account through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1538 Cloud Service Dashboard
Comments
This diagnostic statement protects against Cloud Service Dashboard through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1539 Steal Web Session Cookie
Comments
This diagnostic statement protects against Steal Web Session Cookie through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1543 Create or Modify System Process
Comments
This diagnostic statement protects against Create or Modify System Process through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1543.002 Systemd Service
Comments
This diagnostic statement protects against Systemd Service through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1543.003 Windows Service
Comments
This diagnostic statement protects against Windows Service through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1543.004 Launch Daemon
Comments
This diagnostic statement protects against Launch Daemon through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1543.005 Container Service
Comments
This diagnostic statement protects against Container Service through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1546 Event Triggered Execution
Comments
This diagnostic statement protects against Event Triggered Execution through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1546.003 Windows Management Instrumentation Event Subscription
Comments
This diagnostic statement protects against Windows Management Instrumentation Event Subscription through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1546.011 Application Shimming
Comments
This diagnostic statement protects against Application Shimming through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1547 Boot or Logon Autostart Execution
Comments
This diagnostic statement protects against Boot or Logon Autostart Execution through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1547.004 Winlogon Helper DLL
Comments
This diagnostic statement protects against Winlogon Helper DLL through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1547.006 Kernel Modules and Extensions
Comments
This diagnostic statement protects against Kernel Modules and Extensions through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1547.009 Shortcut Modification
Comments
This diagnostic statement protects against Shortcut Modification through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1547.012 Print Processors
Comments
This diagnostic statement protects against Print Processors through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1547.013 XDG Autostart Entries
Comments
This diagnostic statement protects against XDG Autostart Entries through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1548 Abuse Elevation Control Mechanism
Comments
This diagnostic statement protects against Abuse Elevation Control Mechanism through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1548.002 Bypass User Account Control
Comments
This diagnostic statement protects against Bypass User Account Control through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1548.005 Temporary Elevated Cloud Access
Comments
This diagnostic statement protects against Temporary Elevated Cloud Access through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1550 Use Alternate Authentication Material
Comments
This diagnostic statement protects against Use Alternate Authentication Material through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1550.001 Application Access Token
Comments
This diagnostic statement protects against Application Access Token through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1550.002 Pass the Hash
Comments
This diagnostic statement protects against Pass the Hash through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1550.003 Pass the Ticket
Comments
This diagnostic statement protects against Pass the Ticket through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1552 Unsecured Credentials
Comments
This diagnostic statement protects against Unsecured Credentials through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1552.001 Credentials In Files
Comments
This diagnostic statement protects against Credentials In Files through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1552.002 Credentials in Registry
Comments
This diagnostic statement protects against Credentials in Registry through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1552.004 Private Keys
Comments
This diagnostic statement protects against Private Keys through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1552.006 Group Policy Preferences
Comments
This diagnostic statement protects against Group Policy Preferences through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1552.007 Container API
Comments
This diagnostic statement protects against Container API through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1555 Credentials from Password Stores
Comments
This diagnostic statement protects against Credentials from Password Stores through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1555.001 Keychain
Comments
This diagnostic statement protects against Keychain through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1555.003 Credentials from Web Browsers
Comments
This diagnostic statement protects against Credentials from Web Browsers through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1555.005 Password Managers
Comments
This diagnostic statement protects against Password Managers through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1556 Modify Authentication Process
Comments
This diagnostic statement protects against Modify Authentication Process through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1556.001 Domain Controller Authentication
Comments
This diagnostic statement protects against Domain Controller Authentication through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1556.003 Pluggable Authentication Modules
Comments
This diagnostic statement protects against Pluggable Authentication Modules through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1556.004 Network Device Authentication
Comments
This diagnostic statement protects against Network Device Authentication through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1556.005 Reversible Encryption
Comments
This diagnostic statement protects against Reversible Encryption through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1556.006 Multi-Factor Authentication
Comments
This diagnostic statement protects against Multi-Factor Authentication through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1556.007 Hybrid Identity
Comments
This diagnostic statement protects against Hybrid Identity through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1556.009 Conditional Access Policies
Comments
This diagnostic statement protects against Conditional Access Policies through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1558 Steal or Forge Kerberos Tickets
Comments
This diagnostic statement protects against Steal or Forge Kerberos Tickets through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1558.001 Golden Ticket
Comments
This diagnostic statement protects against Golden Ticket through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1558.002 Silver Ticket
Comments
This diagnostic statement protects against Silver Ticket through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1558.003 Kerberoasting
Comments
This diagnostic statement protects against Kerberoasting through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1558.004 AS-REP Roasting
Comments
This diagnostic statement protects against AS-REP Roasting through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1562 Impair Defenses
Comments
This diagnostic statement protects against Impair Defenses through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1562.001 Disable or Modify Tools
Comments
This diagnostic statement protects against Disable or Modify Tools through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1562.002 Disable Windows Event Logging
Comments
This diagnostic statement protects against Disable Windows Event Logging through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1562.004 Disable or Modify System Firewall
Comments
This diagnostic statement protects against Disable or Modify System Firewall through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1562.006 Indicator Blocking
Comments
This diagnostic statement protects against Indicator Blocking through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1562.007 Disable or Modify Cloud Firewall
Comments
This diagnostic statement protects against Disable or Modify Cloud Firewall through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1562.008 Disable or Modify Cloud Logs
Comments
This diagnostic statement protects against Disable or Modify Cloud Logs through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1562.012 Disable or Modify Linux Audit System
Comments
This diagnostic statement protects against Disable or Modify Linux Audit System through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1563 Remote Service Session Hijacking
Comments
This diagnostic statement protects against Remote Service Session Hijacking through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1563.001 SSH Hijacking
Comments
This diagnostic statement protects against SSH Hijacking through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1563.002 RDP Hijacking
Comments
This diagnostic statement protects against RDP Hijacking through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1566 Phishing
Comments
This diagnostic statement protects against Phishing through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1566.001 Spearphishing Attachment
Comments
This diagnostic statement protects against Spearphishing Attachment through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1566.002 Spearphishing Link
Comments
This diagnostic statement protects against Spearphishing Link through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1566.003 Spearphishing via Service
Comments
This diagnostic statement protects against Spearphishing via Service through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1569 System Services
Comments
This diagnostic statement protects against System Services through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1569.001 Launchctl
Comments
This diagnostic statement protects against Launchctl through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1574 Hijack Execution Flow
Comments
This diagnostic statement protects against Hijack Execution Flow through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1574.005 Executable Installer File Permissions Weakness
Comments
This diagnostic statement protects against Executable Installer File Permissions Weakness through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1574.010 Services File Permissions Weakness
Comments
This diagnostic statement protects against Services File Permissions Weakness through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1574.012 COR_PROFILER
Comments
This diagnostic statement protects against COR_PROFILER through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1578 Modify Cloud Compute Infrastructure
Comments
This diagnostic statement protects against Modify Cloud Compute Infrastructure through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1578.001 Create Snapshot
Comments
This diagnostic statement protects against Create Snapshot through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1578.002 Create Cloud Instance
Comments
This diagnostic statement protects against Create Cloud Instance through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1578.003 Delete Cloud Instance
Comments
This diagnostic statement protects against Delete Cloud Instance through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1578.005 Modify Cloud Compute Configurations
Comments
This diagnostic statement protects against Modify Cloud Compute Configurations through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1580 Cloud Infrastructure Discovery
Comments
This diagnostic statement protects against Cloud Infrastructure Discovery through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1599 Network Boundary Bridging
Comments
This diagnostic statement protects against Network Boundary Bridging through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1599.001 Network Address Translation Traversal
Comments
This diagnostic statement protects against Network Address Translation Traversal through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1601 Modify System Image
Comments
This diagnostic statement protects against Modify System Image through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1601.001 Patch System Image
Comments
This diagnostic statement protects against Patch System Image through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1601.002 Downgrade System Image
Comments
This diagnostic statement protects against Downgrade System Image through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1606 Forge Web Credentials
Comments
This diagnostic statement protects against Forge Web Credentials through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1606.002 SAML Tokens
Comments
This diagnostic statement protects against SAML Tokens through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1609 Container Administration Command
Comments
This diagnostic statement protects against Container Administration Command through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1610 Deploy Container
Comments
This diagnostic statement protects against Deploy Container through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1613 Container and Resource Discovery
Comments
This diagnostic statement protects against Container and Resource Discovery through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1619 Cloud Storage Object Discovery
Comments
This diagnostic statement protects against Cloud Storage Object Discovery through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1621 Multi-Factor Authentication Request Generation
Comments
This diagnostic statement protects against Multi-Factor Authentication Request Generation through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1648 Serverless Execution
Comments
This diagnostic statement protects against Serverless Execution through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1649 Steal or Forge Authentication Certificates
Comments
This diagnostic statement protects against Steal or Forge Authentication Certificates through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1654 Log Enumeration
Comments
This diagnostic statement protects against Log Enumeration through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1657 Financial Theft
Comments
This diagnostic statement protects against Financial Theft through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.
PR.AA-01.01 Identity and credential management Mitigates T1666 Modify Cloud Resource Hierarchy
Comments
This diagnostic statement protects against Modify Cloud Resource Hierarchy through the use of hardened access control policies, secure defaults, password complexity requirements, multifactor authentication requirements, and removal of terminated accounts.

Capabilities

Capability ID Capability Name Number of Mappings
PR.AA-05.04 Third-party access management 7
PR.AA-03.01 Authentication requirements 55
PR.AA-01.02 Physical and logical access 52
PR.AA-03.03 Email verification mechanisms 10
PR.AA-01.01 Identity and credential management 175
PR.AA-05.02 Privileged system access 130
PR.AA-05.03 Service accounts 22
PR.AA-02.01 Authentication of identity 24
PR.AA-05.01 Access privilege limitation 31
PR.AA-04.01 Access control within and across security perimeters 5