CCC.Monitor.C03: Access External Monitoring
Control ID:CCC.Monitor.C03
Title:Access External Monitoring
Objective:Control access to Synthetic monitoring solutions using API keys or Certificate based authentication to
ensure they don't become an attack path, preventing monitoring systems from forging network requests to
gain access to internal systems.
Control Family:
Identity and Access Management
Related Threats
ID | Title | Description | External Mappings | Capability Mappings | Control Mappings |
---|---|---|---|---|---|
CCC.Monitor.TH04 | External Monitoring Access | If an external monitoring system is compromised, it acts as a trusted external remote service and can then access internal services which would otherwise not be accessible directly. | 1 | 1 | 0 |