Skip to main content

Controls

Version:
IDTitleObjectiveControl FamilyThreat MappingsGuideline MappingsAssessment Requirements
CCC.Monitor.CN01Rate Limiting on External MonitoringPrevent DoS attacks using External Monitoring tools.Observability141
CCC.Monitor.CN02Rate Limiting on Metric GenerationPrevent Malicious Actor or misconfiguration from flooding services with metric data.Observability141
CCC.Monitor.CN03Access External MonitoringControl access to Synthetic monitoring solutions using API keys or Certificate based authentication to ensure they don't become an attack path, preventing monitoring systems from forging network requests to gain access to internal systems.Access141
CCC.Monitor.CN04Restrict access to Monitoring DashboardsControl access to Monitoring Dashboards and reports to ensure they don't highlight an attack path.Access141
CCC.Monitor.CN05Restrict access to silence or acknowledge an alertEnsure only a subset of users can silence or acknowledge alerts to prevent attackers hiding their activity.Access131
CCC.Monitor.CN06Metrics pushed for authorised services onlyUse IAM to control which types of metrics or traces can be pushed by different system to avoid a compromised system pushing fabricated metrics about a different serviceAccess121

Imports

IDRemarks
CCC.Core.CN02Ensure Data Encryption at Rest for All Stored Data
CCC.Core.CN03Implement Multi-factor Authentication (MFA) for Access
CCC.Core.CN04Log All Access and Changes
CCC.Core.CN05Prevent Access from Untrusted Entities
CCC.Core.CN07Alert on Unusual Enumeration Activity
CCC.Core.CN09Prevent Tampering, Deletion, or Unauthorized Access to Access Logs
CCC.Core.CN11Enforce Key Management Policies