Skip to main content

Controls

Version:
IDTitleObjectiveControl FamilyThreat MappingsGuideline MappingsAssessment Requirements
CCC.LB.CN01Enforce and Detect Rate LimitingDetect and throttle malicious or excessive requests to prevent downstream resource exhaustion and brute-force activity.Networking262
CCC.LB.CN02Auto-Scale Load Balancer CapacityExpand load-balancer capacity to maintain availability during traffic spikes.Resource121
CCC.LB.CN04Enforce Distribution PoliciesEnsure traffic-splitting weights and algorithms are modified only by trusted identities.Access121
CCC.LB.CN05Validate Session AffinityConfigure session persistence to minimise fixation and hijacking risks.Networking121
CCC.LB.CN06Secure Health-Check TelemetryMonitor health-check endpoints for tampering and alert on abnormal status changes.Observability121
CCC.LB.CN07Scrub Sensitive HeadersRemove headers that disclose internal details or software versions from HTTP responses.Networking121
CCC.LB.CN08Automate Certificate RenewalMaintain valid TLS certificates by automating renewal and deployment before expiry.Encryption121
CCC.LB.CN09Restrict Management API AccessLimit load-balancer API calls to authorised identities and trusted networks.Access121

Imports

IDRemarks
CCC.Core.CN01Prevent Unencrypted Requests
CCC.Core.CN02Ensure Data Encryption at Rest
CCC.Core.CN03Enforce Multi-Factor Authentication
CCC.Core.CN04Log All Access and Changes
CCC.Core.CN05Prevent Access From Untrusted Entities
CCC.Core.CN06Prevent Deployment in Restricted Regions
CCC.Core.CN10Prevent Data Replication Outside Perimeter