Skip to main content

Database / Relational / Controls / DEV

Restrict Snapshot Sharing to Authorized Accounts

CCC.RDMS.CN05 · Access

Ensure database snapshots can only be shared with explicitly authorized accounts, thereby minimizing the risk of data exposure or exfiltration.

Related Capabilities

IDTitleDescription
CCC.Core.CP11BackupThe service can generate copies of its data or configurations in the form of automated backups, snapshot-based backups, or incremental backups.

Related Threats

IDTitleDescription
CCC.RDMS.TH05Unauthorized Snapshot SharingSnapshots may be shared with untrusted accounts, which can lead to unauthorized access and potential data exfiltration. This significantly increases the risk of data exposure if sensitive information is contained in the snapshots.

Assessment Requirements

IDTextApplicability
CCC.RDMS.CN05.AR01When an attempt is made to share a snapshot with an unauthorized account, the sharing request must be denied.tlp-red, tlp-amber

Guideline Mappings

FrameworkIDRemarks
NIST-CSFPR.DS-10
NIST_800_53AC-4