Skip to main content

CCC.RDMS.TH01: Unauthorized Access via Default Credentials

Threat ID:CCC.RDMS.TH01
Title:Unauthorized Access via Default Credentials
Description:

If default credentials are not disabled or changed, unauthorized access may be gained to the RDMS environment. This may lead to data breaches, data manipulation, or overall compromise of the database instance.

Related Capabilities

IDTitleDescription
CCC.RDMS.CP06DB Managed CredentialsAbility to managed the database credentials using the cloud provider's secret management service.
CCC.RDMS.CP07DB Self Managed CredentialsAbility to manage the database credentials by client managed username and passwords.

External Mappings

Reference IDEntry IDStrengthRemarks
MITRE-ATT&CK
T1078
0
-

Controls

IDTitleObjectiveControl FamilyThreat MappingsGuideline MappingsAssessment Requirements
CCC.RDMS.CN01Password ManagementEnsure default vendor-supplied DB administrator credentials are replaced with strong, unique passwords and that these credentials are properly managed using a secure password or secrets management solution. Identity and Access Management
1
2
1