Skip to main content

CCC.Core.TH03: Deployment Region Network is Untrusted

Threat ID:CCC.Core.TH03
Title:Deployment Region Network is Untrusted
Description:

Systems are susceptible to unauthorized access or interception by actors with social or physical control over the network in which they are deployed. If the geopolitical status of the deployment network is untrusted, unstable, or insecure, this could result in a loss of confidentiality, integrity, or availability of the service and its data.

Related Capabilities

IDTitleDescription
CCC.Core.F22Location Lock-InThe service may be configured to restrict the deployment of child resources to specific geographic locations.

External Mappings

Reference IDEntry IDStrengthRemarks
MITRE-ATT&CK
T1040
0
Network Sniffing
MITRE-ATT&CK
T1110
0
Brute Force
MITRE-ATT&CK
T1105
0
Ingress Tool Transfer
MITRE-ATT&CK
T1583
0
Acquire Infrastructure
MITRE-ATT&CK
T1557
0
Adversary-in-the-Middle

Controls

IDTitleObjectiveControl FamilyThreat MappingsGuideline MappingsAssessment Requirements
CCC.Core.C06Restrict Deployments to Trust PerimeterEnsure that the service and its child resources are only deployed on infrastructure in locations that are explicitly included within a defined trust perimeter. Data
1
4
2