Skip to main content

Management / Monitoring / Controls / DEV

Access External Monitoring

CCC.Monitor.CN03 · Access

Control access to Synthetic monitoring solutions using API keys or Certificate based authentication to ensure they don't become an attack path, preventing monitoring systems from forging network requests to gain access to internal systems.

Related Capabilities

IDTitleDescription
CCC.Monitoring.CP06CCC.Monitoring.CP06

Related Threats

IDTitleDescription
CCC.Monitor.TH04External Monitoring AccessIf an external monitoring system is compromised, it acts as a trusted external remote service and can then access internal services which would otherwise not be accessible directly.

Assessment Requirements

IDTextApplicability
CCC.Monitor.CN03.AR01When external systems have approved access to internal systems not normally available for public access then they MUST be secured to prevent unauthorised access jumping through to the internal systems and only allow access to specific internal services.tlp-clear, tlp-green, tlp-amber, tlp-red

Guideline Mappings

FrameworkIDRemarks
NIST-CSFDE.CM-06
NIST-CSFPR.IR-01
NIST-CSFPR.AA-05
NIST_800_53AC-3