Skip to main content

CCC.RDMS.TH02: Brute Force Attempts on Database Authentication

Threat ID:CCC.RDMS.TH02
Title:Brute Force Attempts on Database Authentication
Description:

Repeated attempts to guess database user passwords may be made through brute force techniques. This condition could result in unauthorized access if successful, compromising database security and sensitive information.

Related Capabilities

IDTitleDescription
CCC.RDMS.CP07DB Self Managed CredentialsAbility to manage the database credentials by client managed username and passwords.

External Mappings

Reference IDEntry IDStrengthRemarks
MITRE-ATT&CK
T1110
0
-

Controls

IDTitleObjectiveControl FamilyThreat MappingsGuideline MappingsAssessment Requirements
CCC.RDMS.CN02Account Lockout and Rate-LimitingEnsure the database enforces lockouts or rate-limiting after a specified number of failed authentication attempts. This prevents brute force or password-guessing attacks from succeeding. Identity and Access Management
1
2
1