Skip to main content

Management / Monitoring

Controls

Version:
IDTitleObjective
CCC.Monitor.CN01Rate Limiting on External MonitoringPrevent DoS attacks using External Monitoring tools.
CCC.Monitor.CN02Rate Limiting on Metric GenerationPrevent Malicious Actor or misconfiguration from flooding services with metric data.
CCC.Monitor.CN03Access External MonitoringControl access to Synthetic monitoring solutions using API keys or Certificate based authentication to ensure they don't become an attack path, preventing monitoring systems from forging network requests to gain access to internal systems.
CCC.Monitor.CN04Restrict access to Monitoring DashboardsControl access to Monitoring Dashboards and reports to ensure they don't highlight an attack path.
CCC.Monitor.CN05Restrict access to silence or acknowledge an alertEnsure only a subset of users can silence or acknowledge alerts to prevent attackers hiding their activity.
CCC.Monitor.CN06Metrics pushed for authorised services onlyUse IAM to control which types of metrics or traces can be pushed by different system to avoid a compromised system pushing fabricated metrics about a different service