{"data":{"id":"AC-04","name":"Information Flow Enforcement","family":"AC","family_name":"Access Control","withdrawn":false,"description":"Enforce approved authorizations for controlling the flow of information within the system and between connected systems based on [Assignment: organization-defined information flow control policies].","supplemental_guidance":"Information flow control regulates where information can travel within a system and between systems (in contrast to who is allowed to access the information) and without regard to subsequent accesses to that information. Flow control restrictions include blocking external traffic that claims to be from within the organization, keeping export-controlled information from being transmitted in the clear to the Internet, restricting web requests that are not from the internal web proxy server, and limiting information transfers between organizations based on data structures and content. Transferring information between organizations may require an agreement specifying how the information flow is enforced (see CA-03). Transferring information between systems in different security or privacy domains with different security or privacy policies introduces the risk that such transfers violate one or more domain security or privacy policies. In such situations, information owners/stewards provide guidance at designated policy enforcement points between connected systems. Organizations consider mandating specific architectural solutions to enforce specific security and privacy policies. Enforcement includes prohibiting information transfers between connected systems (i.e., allowing access only), verifying write permissions before accepting information from another security or privacy domain or connected system, employing hardware mechanisms to enforce one-way information flows, and implementing trustworthy regrading mechanisms to reassign security or privacy attributes and labels.\n\nOrganizations commonly employ information flow control policies and enforcement mechanisms to control the flow of information between designated sources and destinations within systems and between connected systems. Flow control is based on the characteristics of the information and/or the information path. Enforcement occurs, for example, in boundary protection devices that employ rule sets or establish configuration settings that restrict system services, provide a packet-filtering capability based on header information, or provide a message-filtering capability based on message content. Organizations also consider the trustworthiness of filtering and/or inspection mechanisms (i.e., hardware, firmware, and software components) that are critical to information flow enforcement. Control enhancements 3 through 32 primarily address cross-domain solution needs that focus on more advanced filtering techniques, in-depth analysis, and stronger flow enforcement mechanisms implemented in cross-domain products, such as high-assurance guards. Such capabilities are generally not available in commercial off-the-shelf products. Information flow enforcement also applies to control plane traffic (e.g., routing and DNS).","enhancements":[{"id":"AC-04(01)","name":"Object Security and Privacy Attributes","statement":"Use [Assignment: organization-defined security and privacy attributes] associated with [Assignment: organization-defined information, source, and destination objects] to enforce [Assignment: organization-defined information flow control policies] as a basis for flow control decisions.","baselines":[]},{"id":"AC-04(02)","name":"Processing Domains","statement":"Use protected processing domains to enforce [Assignment: organization-defined information flow control policies] as a basis for flow control decisions.","baselines":[]},{"id":"AC-04(03)","name":"Dynamic Information Flow Control","statement":"Enforce [Assignment: organization-defined information flow control policies].","baselines":[]},{"id":"AC-04(04)","name":"Flow Control of Encrypted Information","statement":"Prevent encrypted information from bypassing [Assignment: organization-defined information flow control mechanisms] by [Selection (one or more): decrypting the information; blocking the flow of the encrypted information; terminating communications sessions attempting to pass encrypted information; [Assignment: organization-defined procedure or method]].","baselines":["high"]},{"id":"AC-04(05)","name":"Embedded Data Types","statement":"Enforce [Assignment: organization-defined limitations] on embedding data types within other data types.","baselines":[]},{"id":"AC-04(06)","name":"Metadata","statement":"Enforce information flow control based on [Assignment: organization-defined metadata].","baselines":[]},{"id":"AC-04(07)","name":"One-way Flow Mechanisms","statement":"Enforce one-way information flows through hardware-based flow control mechanisms.","baselines":[]},{"id":"AC-04(08)","name":"Security and Privacy Policy Filters","statement":"a. Enforce information flow control using [Assignment: organization-defined security or privacy policy filters] as a basis for flow control decisions for [Assignment: organization-defined information flows]; and\nb. [Selection (one or more): Block; Strip; Modify; Quarantine] data after a filter processing failure in accordance with [Assignment: organization-defined security or privacy policy].","baselines":[]},{"id":"AC-04(09)","name":"Human Reviews","statement":"Enforce the use of human reviews for [Assignment: organization-defined information flows] under the following conditions: [Assignment: organization-defined conditions].","baselines":[]},{"id":"AC-04(10)","name":"Enable and Disable Security or Privacy Policy Filters","statement":"Provide the capability for privileged administrators to enable and disable [Assignment: organization-defined security or privacy policy filters] under the following conditions: [Assignment: organization-defined conditions].","baselines":[]},{"id":"AC-04(11)","name":"Configuration of Security or Privacy Policy Filters","statement":"Provide the capability for privileged administrators to configure [Assignment: organization-defined security or privacy policy filters] to support different security or privacy policies.","baselines":[]},{"id":"AC-04(12)","name":"Data Type Identifiers","statement":"When transferring information between different security domains, use [Assignment: organization-defined data type identifiers] to validate data essential for information flow decisions.","baselines":[]},{"id":"AC-04(13)","name":"Decomposition into Policy-relevant Subcomponents","statement":"When transferring information between different security domains, decompose information into [Assignment: organization-defined policy-relevant subcomponents] for submission to policy enforcement mechanisms.","baselines":[]},{"id":"AC-04(14)","name":"Security or Privacy Policy Filter Constraints","statement":"When transferring information between different security domains, implement [Assignment: organization-defined security or privacy policy filters] requiring fully enumerated formats that restrict data structure and content.","baselines":[]},{"id":"AC-04(15)","name":"Detection of Unsanctioned Information","statement":"When transferring information between different security domains, examine the information for the presence of [Assignment: organization-defined unsanctioned information] and prohibit the transfer of such information in accordance with the [Assignment: organization-defined security or privacy policy].","baselines":[]},{"id":"AC-04(16)","name":"Information Transfers on Interconnected Systems","withdrawn":true,"incorporated_into":["AC-04"]},{"id":"AC-04(17)","name":"Domain Authentication","statement":"Uniquely identify and authenticate source and destination points by [Selection (one or more): organization; system; application; service; individual] for information transfer.","baselines":[]},{"id":"AC-04(18)","name":"Security Attribute Binding","withdrawn":true,"incorporated_into":["AC-16"]},{"id":"AC-04(19)","name":"Validation of Metadata","statement":"When transferring information between different security domains, implement [Assignment: organization-defined security or privacy policy filters] on metadata.","baselines":[]},{"id":"AC-04(20)","name":"Approved Solutions","statement":"Employ [Assignment: organization-defined solutions in approved configurations] to control the flow of [Assignment: organization-defined information] across security domains.","baselines":[]},{"id":"AC-04(21)","name":"Physical or Logical Separation of Information Flows","statement":"Separate information flows logically or physically using [Assignment: organization-defined mechanisms and/or techniques] to accomplish [Assignment: organization-defined required separations by types of information].","baselines":[]},{"id":"AC-04(22)","name":"Access Only","statement":"Provide access from a single device to computing platforms, applications, or data residing in multiple different security domains, while preventing information flow between the different security domains.","baselines":[]},{"id":"AC-04(23)","name":"Modify Non-releasable Information","statement":"When transferring information between different security domains, modify non-releasable information by implementing [Assignment: organization-defined modification action].","baselines":[]},{"id":"AC-04(24)","name":"Internal Normalized Format","statement":"When transferring information between different security domains, parse incoming data into an internal normalized format and regenerate the data to be consistent with its intended specification.","baselines":[]},{"id":"AC-04(25)","name":"Data Sanitization","statement":"When transferring information between different security domains, sanitize data to minimize [Selection (one or more): delivery of malicious content, command and control of malicious code, malicious code augmentation, and steganography encoded data; spillage of sensitive information] in accordance with [Assignment: organization-defined policy].","baselines":[]},{"id":"AC-04(26)","name":"Audit Filtering Actions","statement":"When transferring information between different security domains, record and audit content filtering actions and results for the information being filtered.","baselines":[]},{"id":"AC-04(27)","name":"Redundant/Independent Filtering Mechanisms","statement":"When transferring information between different security domains, implement content filtering solutions that provide redundant and independent filtering mechanisms for each data type.","baselines":[]},{"id":"AC-04(28)","name":"Linear Filter Pipelines","statement":"When transferring information between different security domains, implement a linear content filter pipeline that is enforced with discretionary and mandatory access controls.","baselines":[]},{"id":"AC-04(29)","name":"Filter Orchestration Engines","statement":"When transferring information between different security domains, employ content filter orchestration engines to ensure that:\na. Content filtering mechanisms successfully complete execution without errors; and\nb. Content filtering actions occur in the correct order and comply with [Assignment: organization-defined policy].","baselines":[]},{"id":"AC-04(30)","name":"Filter Mechanisms Using Multiple Processes","statement":"When transferring information between different security domains, implement content filtering mechanisms using multiple processes.","baselines":[]},{"id":"AC-04(31)","name":"Failed Content Transfer Prevention","statement":"When transferring information between different security domains, prevent the transfer of failed content to the receiving domain.","baselines":[]},{"id":"AC-04(32)","name":"Process Requirements for Information Transfer","statement":"When transferring information between different security domains, the process that transfers information between filter pipelines:\na. Does not filter message content;\nb. Validates filtering metadata;\nc. Ensures the content associated with the filtering metadata has successfully completed filtering; and\nd. Transfers the content to the destination filter pipeline.","baselines":[]}],"baseline_low":false,"baseline_moderate":true,"baseline_high":true,"nist_800_53":{"rev5":{"id":"AC-04","name":"Information Flow Enforcement","description":"Enforce approved authorizations for controlling the flow of information within the system and between connected systems based on [Assignment: organization-defined information flow control policies].","discussion":"Information flow control regulates where information can travel within a system and between systems (in contrast to who is allowed to access the information) and without regard to subsequent accesses to that information. Flow control restrictions include blocking external traffic that claims to be from within the organization, keeping export-controlled information from being transmitted in the clear to the Internet, restricting web requests that are not from the internal web proxy server, and limiting information transfers between organizations based on data structures and content. Transferring information between organizations may require an agreement specifying how the information flow is enforced (see CA-03). Transferring information between systems in different security or privacy domains with different security or privacy policies introduces the risk that such transfers violate one or more domain security or privacy policies. In such situations, information owners/stewards provide guidance at designated policy enforcement points between connected systems. Organizations consider mandating specific architectural solutions to enforce specific security and privacy policies. Enforcement includes prohibiting information transfers between connected systems (i.e., allowing access only), verifying write permissions before accepting information from another security or privacy domain or connected system, employing hardware mechanisms to enforce one-way information flows, and implementing trustworthy regrading mechanisms to reassign security or privacy attributes and labels.\n\nOrganizations commonly employ information flow control policies and enforcement mechanisms to control the flow of information between designated sources and destinations within systems and between connected systems. Flow control is based on the characteristics of the information and/or the information path. Enforcement occurs, for example, in boundary protection devices that employ rule sets or establish configuration settings that restrict system services, provide a packet-filtering capability based on header information, or provide a message-filtering capability based on message content. Organizations also consider the trustworthiness of filtering and/or inspection mechanisms (i.e., hardware, firmware, and software components) that are critical to information flow enforcement. Control enhancements 3 through 32 primarily address cross-domain solution needs that focus on more advanced filtering techniques, in-depth analysis, and stronger flow enforcement mechanisms implemented in cross-domain products, such as high-assurance guards. Such capabilities are generally not available in commercial off-the-shelf products. Information flow enforcement also applies to control plane traffic (e.g., routing and DNS).","related_controls":["AC-03","AC-06","AC-16","AC-17","AC-19","AC-21","AU-10","CA-03","CA-09","CM-07","PL-09","PM-24","SA-17","SC-04","SC-07","SC-16","SC-31"],"baseline_low":false,"baseline_moderate":true,"baseline_high":true,"baseline_privacy":false,"new_in_rev5":false,"changes_from_rev4":""}},"compliance_mappings":{"iso_27001_2022":["A.5.14","A.8.3","A.8.12","A.8.20","A.8.22","A.8.23"],"iso_27002_2022":["5.14","8.3","8.12","8.20","8.23"],"cobit_2019":["APO14","DSS05","DSS06"],"pci_dss_v4":["1.2","1.3"],"nist_csf_2":["DE.CM-09","ID.AM-03","PR.DS-10","PR.IR-01"],"cis_controls_v8":["CIS 3","CIS 3.8","CIS 3.12","CIS 3.13","CIS 9.3","CIS 12","CIS 13.4","CIS 13.10"],"soc2_tsc":["CC6.1","CC6.1-POF6","CC6.6","CC6.6-POF1"],"finos_ccc":["CCC-C05","CCC-C09"],"iso_42001_2023":["A.9.4"],"iec_62443":["3-3 SR 2.1","3-3 SR 5.1"],"asd_e8":[],"nis2":["Art. 21(2)(i)"],"apra_cps_234":[],"mas_trm":["9"],"pra_op_resilience":["SS2/21-11.1"],"bsi_grundschutz":["NET.1.1","ORP.4"],"anssi":["Hygiene.23","Hygiene.27","SecNumCloud.14.1"],"osfi_b13":["B-13.3.2"],"finma_circular":["IV.B.d(59)","IV.C(62)","IV.C(63)"],"gdpr":["Art.5(1)(f)","Art.32(1)(a)","Art.44","Art.46(1)"],"dora":["Art.9(4)(a)"],"bio2":["5.14","8.3","8.12","8.20","8.23"],"rbi_csf":["Annex1.4","Annex1.15","ITGRCA.19"],"fisc":["FISC.T2","FISC.T3","FISC.T5","FISC.T8","FISC.T13"],"lgpd_bcb":["BCB.Art.3","BCB.Art.13","BCB.Art.14","BCB.OpenFinance","BCB.PIX","LGPD.Art.23-26","LGPD.Art.33-36","LGPD.Art.46"],"hkma_tme1":["TME1.10.1","TME1.10.3"],"mlps_2":["8.1.2.1","8.1.3.2","8.2","8.5"],"dnb_good_practice":["DNB.12.3","DNB.18.4","DNB.18.5"],"cra":["CRA.I.2j"],"swift_cscf":["SWIFT.1.1","SWIFT.1.3","SWIFT.1.4","SWIFT.1.5","SWIFT.2.4A"],"cbb_tm":["TM-6","TM-8"],"cbuae":["CR-4","CR-5"],"nca_ecc":["2-5","2-7","2-14"],"qatar_nia":["AC","CS"],"sama_csf":["3.1","3.3"],"uae_ia":["T8","T9"],"bog_cisd":["CISD-VIII","CISD-XI","CISD-XIII"],"bom_ctrm":["3.2","3.10"],"cbe_csf":["CTO-1","CTO-2","CTO-5","CTO-6","CTO-8"],"cbn_csf":["Part3.2","Part3.4","Part5.2"],"popia":["s19","s72"],"sa_js2":["JS2-7.1","JS2-8.2"],"bcbs_239":["Principle 11"],"bot_cyber":["Ch2.2","Ch2.4"],"cpmi_pfmi":["CG.PR","PFMI.P17","PFMI.P22"],"eba_ict":["3.4.2"],"ecb_croe":["CROE.2.3.5"],"ffiec_is":["II.C.6","II.C.9","II.C.13","II.C.13(b)"],"hipaa_sr":["§164.308(a)(4)(i)","§164.308(a)(4)(ii)(A)","§164.314(b)(1)","§164.314(b)(2)"],"iosco_cyber":["PFMI-20","PROT-2"],"nydfs_500":["500.18"],"sebi_cscrf":["DATALOC","EMAIL-SEC","PR.AA","PR.DS","PR.NS"],"cmmc_2":["AC"],"nerc_cip":["CIP-005-7"],"nrc_73_54":["73.54(c)(1)","73.54(c)(2)"],"tsa_psd":["SD-2 Sec A"],"ieee_1686":["5.6"],"ferc_cip":["Order 887","Order 2222"],"doe_c2m2":["ARCHITECTURE"],"api_1164":["Sec 5","Sec 8"],"awia":["AWWA Sec 4"],"iaea_nss":["Sec 5.1","Sec 5.6"],"pci_pts":["E","J"],"fips_140":["FIPS 140-3 §7.3"],"cbest":[],"tiber_eu":[],"pci_hsm":["3"],"common_criteria":["CC Part 2 — FDP"],"isae_3402":["Clause 4"],"fca_sysc_13":[],"fda_21_cfr_11":[],"fda_cyber":["SA-4","TM-2"],"hitrust_csf":["01.b","09.e"],"iso_27799":["9.5","13.1","13.2","H.2","H.4"],"lloyds_ms":["BP2.2","MS6.1","MS8.9","MS13.2"],"naic_ds":["4B","8"],"nhs_dspt":["NDG-9.2","NDG-9.5"],"pra_ss1_23":[],"solvency_ii":["Art.49(3)","DR.266-DataSec","EIOPA-Cloud-GL9","EIOPA-ICT-4.6"],"owasp_masvs_v2":["MASVS-PLATFORM-1","MASVS-PLATFORM-2","MASVS-PLATFORM-3","MASVS-STORAGE-2"],"csa_ccm_v4":["DSP-05","DSP-10","IVS-03","IVS-06","UEM-11"],"csa_aicm":["AIS-08","DSP-05","DSP-10","DSP-22","I&S-03","I&S-06","UEM-11"],"ccss_v9":["1.05.4"],"mica":["Art.63(1)","Art.68(1)","Art.76(1)"],"basel_sco60":["SCO60.64"],"bssc":["NOS-04","TIS-04"],"sec_custody_digital":["SEC-CD-04"],"dpdpa":["Act.16","Rules.13(4)","Rules.15"]},"attack_techniques":[{"id":"T1001","name":"Data Obfuscation","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Information flow enforcement policies that inspect and filter network traffic based on content characteristics can block obfuscated C2 data by rejecting traffic that fails protocol conformance checks or contains anomalous payload encodings."},{"id":"T1003","name":"OS Credential Dumping","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Restricting information flows between security domains—particularly isolating credential stores and domain controllers behind strict network segmentation—limits adversary ability to access credential dumping targets from compromised endpoints."},{"id":"T1008","name":"Fallback Channels","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Flow control policies that restrict outbound connections to authorized destinations and protocols can block fallback C2 channels by preventing compromised hosts from establishing connections to alternate adversary infrastructure."},{"id":"T1029","name":"Scheduled Transfer","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Flow enforcement that monitors and restricts data transfers based on schedules, volumes, and destination characteristics can detect and block automated scheduled exfiltration by enforcing approved transfer windows and size limits."},{"id":"T1030","name":"Data Transfer Size Limits","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Information flow controls that track cumulative data transfer volumes can detect exfiltration using small transfer sizes by aggregating individual transfers and alerting when total outbound data exceeds thresholds even at low per-transfer rates."},{"id":"T1041","name":"Exfiltration Over C2 Channel","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Flow enforcement between internal networks and external infrastructure can restrict exfiltration over C2 channels by applying content inspection and data loss prevention at network boundaries to detect sensitive data in outbound traffic."},{"id":"T1046","name":"Network Service Discovery","tactics":["discovery"],"mapping_type":"mitigates","mapping_rationale":"Network flow enforcement that restricts inter-zone communication to explicitly authorized service paths limits network service discovery by preventing adversary scanning across network segments they should not be able to reach."},{"id":"T1048","name":"Exfiltration Over Alternative Protocol","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Flow control policies that whitelist authorized outbound protocols and destinations can block exfiltration over alternative protocols by rejecting DNS tunneling, ICMP-based transfers, or unauthorized protocol usage at enforcement boundaries."},{"id":"T1068","name":"Exploitation for Privilege Escalation","tactics":["privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Enforcing information flow boundaries between privilege levels and security domains constrains the impact of privilege escalation exploits by limiting what an attacker can access even after gaining elevated permissions within a single zone."},{"id":"T1071","name":"Application Layer Protocol","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Information flow enforcement through application-layer gateways and proxy architectures can detect and block C2 channels by validating that application protocol usage conforms to expected patterns and authorized communication paths."},{"id":"T1072","name":"Software Deployment Tools","tactics":["execution","lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Flow enforcement policies restricting software deployment tool communication to authorized management networks prevent adversaries from abusing these tools for lateral execution by blocking deployment commands from unauthorized network segments."},{"id":"T1090","name":"Proxy","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Network flow enforcement that restricts proxy usage to authorized proxy infrastructure and blocks direct outbound connections prevents adversaries from establishing unauthorized proxy chains for C2 traffic relay."},{"id":"T1095","name":"Non-Application Layer Protocol","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Flow control at network boundaries that enforces application-layer protocol requirements can block non-application layer C2 protocols by rejecting raw TCP, ICMP tunneling, or custom protocol traffic that bypasses proxy infrastructure."},{"id":"T1098","name":"Account Manipulation","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Information flow policies that restrict administrative operations to authorized management channels prevent adversaries from performing account manipulation from compromised user workstations by enforcing administrative action boundaries."},{"id":"T1102","name":"Web Service","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Flow enforcement that controls access to cloud services and external web platforms can restrict C2 channels leveraging legitimate web services by blocking or inspecting traffic to categories of sites commonly abused for command-and-control."},{"id":"T1104","name":"Multi-Stage Channels","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Flow control policies restricting outbound connection chains and blocking multi-hop routing through unauthorized relays can disrupt multi-stage C2 channel establishment that progressively tunnels through multiple intermediaries."},{"id":"T1105","name":"Ingress Tool Transfer","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Information flow enforcement blocking executable downloads, script retrieval, and tool staging from unauthorized external sources prevents adversaries from transferring additional attack tools into the environment through ingress channels."},{"id":"T1114","name":"Email Collection","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Flow enforcement policies restricting email data access to authorized clients and protocols—and preventing bulk email export across security boundaries—limit adversary ability to collect and exfiltrate email content from compromised environments."},{"id":"T1132","name":"Data Encoding","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Flow control with content inspection can detect encoded C2 data by analyzing traffic payloads for Base64, XOR, or custom encoding signatures that differ from expected application-layer data formats within permitted protocols."},{"id":"T1133","name":"External Remote Services","tactics":["initial-access","persistence"],"mapping_type":"mitigates","mapping_rationale":"Information flow enforcement through VPN concentrators and remote access gateways—with strict source validation and protocol restrictions—limits adversary exploitation of external remote services for initial access and persistence."},{"id":"T1136","name":"Create Account","tactics":["persistence"],"mapping_type":"mitigates","mapping_rationale":"Flow enforcement restricting account provisioning operations to authorized identity management systems and approved network pathways prevents adversaries from creating persistent accounts through unauthorized administrative channels."},{"id":"T1187","name":"Forced Authentication","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Flow control that restricts outbound SMB and NTLM traffic from crossing network boundaries prevents forced authentication attacks from coercing credential hash transmission to adversary-controlled external servers."},{"id":"T1189","name":"Drive-by Compromise","tactics":["initial-access"],"mapping_type":"mitigates","mapping_rationale":"Information flow enforcement through web proxy architectures with content filtering, URL categorization, and sandboxing of web content can block drive-by compromise payloads before they reach user endpoints."},{"id":"T1190","name":"Exploit Public-Facing Application","tactics":["initial-access"],"mapping_type":"mitigates","mapping_rationale":"Flow enforcement through web application firewalls and reverse proxies with input validation rules limits exploitation of public-facing applications by blocking malformed requests, injection attempts, and known exploit payloads."},{"id":"T1197","name":"BITS Jobs","tactics":["defense-evasion","persistence"],"mapping_type":"mitigates","mapping_rationale":"Flow control policies that restrict BITS transfer destinations to authorized update servers prevent adversary abuse of the Background Intelligent Transfer Service for downloading tools or exfiltrating data through BITS jobs."},{"id":"T1199","name":"Trusted Relationship","tactics":["initial-access"],"mapping_type":"mitigates","mapping_rationale":"Information flow enforcement between trusted partner networks and internal systems—through strictly defined interface boundaries and data validation—limits the blast radius of supply chain compromise through trusted relationships."},{"id":"T1203","name":"Exploitation for Client Execution","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Flow enforcement that sandboxes or restricts content from external sources—including email attachments, web downloads, and shared files—can limit client-side exploitation by preventing malicious content from reaching vulnerable applications."},{"id":"T1204","name":"User Execution","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Flow control policies that restrict executable content from external sources—blocking file types, enforcing download restrictions, and validating content—reduce the impact of user execution by preventing malicious payloads from entering the environment."},{"id":"T1205","name":"Traffic Signaling","tactics":["command-and-control","defense-evasion","persistence"],"mapping_type":"mitigates","mapping_rationale":"Flow enforcement through stateful firewalls and strict protocol compliance checking can prevent traffic signaling techniques by rejecting malformed packets, unexpected flag combinations, or out-of-sequence traffic used to activate backdoors."},{"id":"T1210","name":"Exploitation of Remote Services","tactics":["lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Network segmentation enforced through information flow controls limits exploitation of remote services by restricting which systems can communicate with vulnerable services, containing lateral movement to authorized network paths."},{"id":"T1211","name":"Exploitation for Defense Evasion","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Flow enforcement between security zones limits the utility of defense evasion exploits by ensuring that even if an adversary exploits a vulnerability to bypass local controls, they remain constrained by network-level flow boundaries."},{"id":"T1212","name":"Exploitation for Credential Access","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Information flow policies isolating authentication infrastructure behind strict network access controls limit adversary ability to exploit credential access vulnerabilities by restricting which systems can reach authentication services."},{"id":"T1213","name":"Data from Information Repositories","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Flow enforcement restricting access to information repositories—including SharePoint, Confluence, and databases—to authorized user segments and preventing bulk data transfers across boundaries limits adversary data collection."},{"id":"T1218","name":"System Binary Proxy Execution","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Flow control that restricts outbound connectivity from signed system binaries—preventing rundll32, regsvr32, and similar utilities from reaching external resources—limits proxy execution techniques that fetch remote payloads."},{"id":"T1219","name":"Remote Access Software","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Information flow policies blocking unauthorized remote access tool traffic—by restricting TeamViewer, AnyDesk, and similar application protocols at network boundaries—prevent adversary C2 through commercial remote support software."},{"id":"T1482","name":"Domain Trust Discovery","tactics":["discovery"],"mapping_type":"mitigates","mapping_rationale":"Flow enforcement restricting directory replication traffic and LDAP queries across trust boundaries limits domain trust discovery by preventing adversaries from enumerating trust relationships across network segments."},{"id":"T1484","name":"Domain or Tenant Policy Modification","tactics":["defense-evasion","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Information flow controls that restrict Group Policy and tenant configuration changes to authorized administrative channels prevent adversaries from modifying domain or tenant policies from compromised user workstations."},{"id":"T1489","name":"Service Stop","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Flow enforcement restricting service management commands to authorized management networks and admin workstations prevents adversaries from remotely stopping critical services from compromised user endpoints."},{"id":"T1498","name":"Network Denial of Service","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Network flow enforcement with rate limiting, traffic shaping, and upstream scrubbing center integration mitigates network denial-of-service attacks by filtering volumetric attack traffic before it overwhelms target infrastructure."},{"id":"T1499","name":"Endpoint Denial of Service","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Flow control with connection rate limiting and request throttling at application boundaries mitigates endpoint denial-of-service by restricting the volume of traffic that can reach target services from any single source."},{"id":"T1528","name":"Steal Application Access Token","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Flow enforcement restricting OAuth and API token traffic to authorized client applications and endpoints limits adversary ability to use stolen application access tokens from unauthorized network locations."},{"id":"T1530","name":"Data from Cloud Storage","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Information flow policies controlling access to cloud storage—including network-based access restrictions and cloud service broker enforcement—limit adversary ability to access misconfigured or over-permissioned cloud storage from unauthorized networks."},{"id":"T1537","name":"Transfer Data to Cloud Account","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Flow enforcement blocking unauthorized cross-account data transfers and restricting cloud storage replication to approved destinations prevents adversary exfiltration of data to external cloud accounts."},{"id":"T1552","name":"Unsecured Credentials","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Information flow controls that restrict access to credential storage locations—isolating configuration management databases and secrets managers behind network boundaries—limit adversary discovery of unsecured credentials."},{"id":"T1557","name":"Adversary-in-the-Middle","tactics":["collection","credential-access"],"mapping_type":"mitigates","mapping_rationale":"Flow enforcement through network segmentation, encrypted channels, and strict routing policies limits adversary-in-the-middle opportunities by reducing the network paths available for traffic interception and manipulation."},{"id":"T1559","name":"Inter-Process Communication","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Flow control policies restricting inter-process communication across security boundaries—including DCOM, COM, and DDE cross-process calls—limit adversary execution through IPC mechanisms that span security contexts."},{"id":"T1563","name":"Remote Service Session Hijacking","tactics":["lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Flow enforcement restricting remote session protocols to authorized management networks and requiring re-authentication for session transfers limits adversary ability to hijack remote service sessions for lateral movement."},{"id":"T1565","name":"Data Manipulation","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Information flow integrity controls—including cryptographic validation and data provenance checking at system boundaries—enable detection of adversary data manipulation by verifying data integrity during transit between systems."},{"id":"T1566","name":"Phishing","tactics":["initial-access"],"mapping_type":"mitigates","mapping_rationale":"Flow enforcement through email security gateways with attachment sandboxing, URL rewriting, and content filtering blocks phishing delivery by intercepting malicious payloads before they reach user inboxes."},{"id":"T1567","name":"Exfiltration Over Web Service","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Flow control policies restricting outbound uploads to cloud storage, code repositories, and web services—through proxy enforcement and DLP inspection—prevent adversary exfiltration over legitimate web service channels."},{"id":"T1568","name":"Dynamic Resolution","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"DNS flow enforcement through organizational resolvers with threat intelligence filtering and sinkholing can block dynamic C2 resolution by preventing clients from resolving domains generated by DGA algorithms or fast-flux infrastructure."},{"id":"T1570","name":"Lateral Tool Transfer","tactics":["lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Flow enforcement restricting internal file transfer protocols between network zones limits lateral tool transfer by blocking SMB, SCP, and PowerShell remoting file copies across segment boundaries."},{"id":"T1571","name":"Non-Standard Port","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Flow control policies that enforce standard port-to-service mappings and block traffic on non-standard ports prevent C2 channels from operating on unexpected ports to evade port-based security controls."},{"id":"T1572","name":"Protocol Tunneling","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Information flow enforcement with deep packet inspection can detect and block protocol tunneling by identifying encapsulated traffic that does not match the expected characteristics of the outer protocol."},{"id":"T1573","name":"Encrypted Channel","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Flow enforcement through TLS inspection proxies and encrypted traffic analysis can identify encrypted C2 channels by examining certificate characteristics, JA3 fingerprints, and traffic patterns of encrypted sessions."},{"id":"T1574","name":"Hijack Execution Flow","tactics":["defense-evasion","persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Flow control restricting write access to system binary directories and library paths across network boundaries prevents remote adversaries from placing hijacking payloads in locations that intercept legitimate execution flows."},{"id":"T1598","name":"Phishing for Information","tactics":["reconnaissance"],"mapping_type":"mitigates","mapping_rationale":"Flow enforcement filtering inbound communications through email gateways and web proxies with reputation services blocks phishing-for-information attempts by intercepting social engineering messages before they reach targets."},{"id":"T1599","name":"Network Boundary Bridging","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Information flow enforcement on network devices—including strict routing policies and network boundary controls—prevents adversaries from bridging isolated network segments by manipulating device configurations to bypass segmentation."},{"id":"T1601","name":"Modify System Image","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Flow control restricting management plane access to network devices prevents unauthorized firmware modifications by ensuring only authenticated administrators on approved management networks can alter system images."},{"id":"T1602","name":"Data from Configuration Repository","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Flow enforcement restricting SNMP, CLI, and API access to network devices from authorized management stations prevents adversaries from remotely extracting device configurations containing sensitive network architecture details."},{"id":"T1609","name":"Container Administration Command","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Flow enforcement restricting access to container orchestration APIs and container runtime interfaces to authorized management systems prevents adversaries from executing unauthorized container administration commands."},{"id":"T1611","name":"Escape to Host","tactics":["privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Information flow controls that enforce container isolation boundaries—including restricted kernel namespaces and seccomp profiles—limit container escape techniques by preventing containers from accessing host resources."},{"id":"T1622","name":"Debugger Evasion","tactics":["defense-evasion","discovery"],"mapping_type":"mitigates","mapping_rationale":"Flow enforcement that restricts debugger and analysis tool access across security boundaries limits adversary ability to probe security tools and develop evasion techniques against monitoring infrastructure."},{"id":"T1654","name":"Log Enumeration","tactics":["discovery"],"mapping_type":"mitigates","mapping_rationale":"Flow control restricting access to log repositories and SIEM infrastructure to authorized administrative channels prevents adversaries from enumerating security logs to understand detection capabilities."},{"id":"T1659","name":"Content Injection","tactics":["command-and-control","initial-access"],"mapping_type":"mitigates","mapping_rationale":"Information flow enforcement through content validation and integrity checking at network boundaries blocks content injection attacks by verifying that data crossing security boundaries has not been tampered with."},{"id":"T1001.001","name":"Junk Data","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Flow enforcement with payload analysis can block junk data padding in C2 traffic by rejecting packets with anomalous padding patterns or payload sizes that deviate from expected protocol specifications."},{"id":"T1001.002","name":"Steganography","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Information flow controls with content inspection capabilities can detect steganographic channels by analyzing file transfers for statistical anomalies in media files that indicate hidden data payloads."},{"id":"T1001.003","name":"Protocol or Service Impersonation","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Protocol-conformant flow enforcement that validates traffic against expected protocol behavior can block service impersonation by rejecting traffic that mimics but does not fully comply with legitimate protocol specifications."},{"id":"T1003.001","name":"LSASS Memory","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Flow controls isolating domain controllers and credential stores behind strict network segmentation restrict adversary access to LSASS memory by preventing remote credential extraction tools from reaching targets."},{"id":"T1003.005","name":"Cached Domain Credentials","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Information flow policies that restrict replication traffic and domain controller access to authorized systems limit adversary ability to remotely access cached domain credentials by blocking unauthorized authentication traffic."},{"id":"T1003.006","name":"DCSync","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Flow enforcement restricting directory replication protocol (MS-DRSR) traffic to authorized domain controllers blocks DCSync attacks by preventing non-DC systems from requesting credential data through replication channels."},{"id":"T1020.001","name":"Traffic Duplication","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Flow control policies that restrict port mirroring and SPAN configuration to authorized management interfaces prevent adversaries from establishing unauthorized traffic duplication that copies sensitive data for exfiltration."},{"id":"T1021.001","name":"Remote Desktop Protocol","tactics":["lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Information flow enforcement restricting RDP traffic to authorized jump servers and management networks limits lateral movement by preventing direct Remote Desktop connections between workstations or from unauthorized network segments."},{"id":"T1021.002","name":"SMB/Windows Admin Shares","tactics":["lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Flow control restricting SMB traffic between network zones—particularly blocking administrative share access across security boundaries—limits lateral movement through Windows administrative shares."},{"id":"T1021.003","name":"Distributed Component Object Model","tactics":["lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Flow enforcement blocking DCOM traffic at network boundaries and restricting RPC port ranges prevents adversaries from leveraging Distributed COM for remote code execution across network segments."},{"id":"T1021.005","name":"VNC","tactics":["lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Information flow policies restricting VNC traffic to authorized management networks and blocking VNC ports at segment boundaries prevent adversaries from using VNC for lateral graphical access."},{"id":"T1021.006","name":"Windows Remote Management","tactics":["lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Flow enforcement restricting WinRM traffic (ports 5985/5986) to authorized administrative networks limits adversary lateral movement through Windows Remote Management and PowerShell remoting."},{"id":"T1048.001","name":"Exfiltration Over Symmetric Encrypted Non-C2 Protocol","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Flow control that inspects or blocks encrypted outbound connections on non-standard ports or to unauthorized destinations prevents exfiltration using symmetric encrypted channels outside normal C2 infrastructure."},{"id":"T1048.002","name":"Exfiltration Over Asymmetric Encrypted Non-C2 Protocol","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Information flow enforcement blocking unauthorized TLS/SSH connections to external hosts—particularly from servers—prevents adversary exfiltration using asymmetric encrypted non-C2 protocol channels."},{"id":"T1048.003","name":"Exfiltration Over Unencrypted Non-C2 Protocol","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Flow enforcement monitoring and restricting cleartext protocol traffic—including FTP, HTTP, and TFTP—at network boundaries prevents exfiltration over unencrypted alternative protocols by blocking unauthorized transfers."},{"id":"T1070.008","name":"Clear Mailbox Data","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Flow control restricting mailbox management operations to authorized administrative systems and preventing bulk message deletion from compromised user sessions limits adversary ability to clear email evidence."},{"id":"T1071.001","name":"Web Protocols","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Information flow enforcement through web proxy architectures with URL filtering, SSL inspection, and content analysis enables detection and blocking of HTTP/HTTPS-based C2 channels at network boundaries."},{"id":"T1071.002","name":"File Transfer Protocols","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Flow control restricting FTP and SFTP traffic to authorized transfer servers and blocking ad hoc file transfer connections at network boundaries prevents adversary C2 through file transfer protocols."},{"id":"T1071.003","name":"Mail Protocols","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Flow enforcement restricting mail protocol traffic (SMTP, IMAP, POP3) to authorized mail servers prevents adversaries from establishing C2 channels through direct mail protocol connections from compromised hosts."},{"id":"T1071.004","name":"DNS","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"DNS flow enforcement that restricts queries to organizational resolvers, blocks direct external DNS, and inspects query patterns prevents DNS-based C2 tunneling and data exfiltration through covert DNS channels."},{"id":"T1071.005","name":"Publish/Subscribe Protocols","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Flow control restricting publish/subscribe protocol traffic—including MQTT and AMQP—to authorized broker infrastructure prevents adversary C2 channels through messaging middleware protocols."},{"id":"T1090.001","name":"Internal Proxy","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Flow enforcement that restricts internal traffic routing and prevents unauthorized systems from acting as network relays blocks adversary deployment of internal proxy infrastructure for C2 traffic forwarding."},{"id":"T1090.002","name":"External Proxy","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Information flow policies requiring all external traffic to route through authorized proxy infrastructure and blocking direct outbound connections prevent adversary use of external proxy services for C2."},{"id":"T1090.003","name":"Multi-hop Proxy","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Flow enforcement through network egress controls that detect and block multi-hop proxy chains—including Tor, VPN cascades, and anonymization services—prevents adversaries from obscuring C2 origins through layered proxies."},{"id":"T1098.001","name":"Additional Cloud Credentials","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Flow control restricting cloud IAM management operations to authorized administrative channels and requiring elevated authentication prevents adversary creation of additional cloud credentials from compromised user sessions."},{"id":"T1098.007","name":"Additional Local or Domain Groups","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Information flow policies that restrict group management operations to authorized identity governance systems prevent adversaries from adding accounts to privileged groups through unauthorized administrative channels."},{"id":"T1102.001","name":"Dead Drop Resolver","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Flow enforcement blocking or inspecting access to known dead drop resolver platforms—including paste sites and social media profiles used for C2 address retrieval—prevents adversary infrastructure discovery through public services."},{"id":"T1102.002","name":"Bidirectional Communication","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Information flow controls restricting bidirectional data exchange with unauthorized cloud services and social media platforms block full-duplex C2 channels operating through legitimate web services."},{"id":"T1102.003","name":"One-Way Communication","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Flow enforcement restricting polling access to external web services, RSS feeds, and cloud storage prevents adversaries from receiving one-way command delivery through publicly accessible content platforms."},{"id":"T1114.001","name":"Local Email Collection","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Flow control restricting local email file access across security boundaries and preventing email data extraction to removable media limits adversary collection of email from local mail stores."},{"id":"T1114.002","name":"Remote Email Collection","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Information flow enforcement restricting remote email protocol access to authorized clients and enforcing conditional access policies limits adversary remote email collection from Exchange or cloud mail services."},{"id":"T1114.003","name":"Email Forwarding Rule","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Flow control monitoring and restricting email forwarding rule creation—particularly rules forwarding to external domains—prevents adversary persistent email collection through automated forwarding mechanisms."},{"id":"T1132.001","name":"Standard Encoding","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Flow enforcement with payload inspection that decodes and analyzes Base64 and standard encoding in network traffic can detect and block C2 commands hidden within commonly encoded data formats."},{"id":"T1132.002","name":"Non-Standard Encoding","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Information flow controls with anomaly detection can identify non-standard encoding in C2 traffic by flagging byte patterns that do not match any expected application data encoding for the observed protocol."},{"id":"T1134.005","name":"SID-History Injection","tactics":["defense-evasion","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Flow enforcement preventing unauthorized SID-History modifications during cross-domain migration and restricting access to domain migration tools limits adversary ability to inject SID-History for privilege escalation."},{"id":"T1136.002","name":"Domain Account","tactics":["persistence"],"mapping_type":"mitigates","mapping_rationale":"Flow control restricting Active Directory account creation to authorized provisioning systems and approved administrative channels prevents adversary creation of domain accounts from compromised workstations."},{"id":"T1136.003","name":"Cloud Account","tactics":["persistence"],"mapping_type":"mitigates","mapping_rationale":"Information flow enforcement restricting cloud identity management to authorized administrative interfaces prevents adversary creation of persistent cloud accounts through unauthorized API access."},{"id":"T1204.001","name":"Malicious Link","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Flow enforcement through web proxy content filtering and URL categorization blocks malicious link execution by preventing user browsers from reaching adversary-controlled download sites or credential harvesting pages."},{"id":"T1204.002","name":"Malicious File","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Information flow controls that sandbox or block executable file types at email gateways and web proxies prevent malicious file execution by intercepting weaponized documents before they reach user endpoints."},{"id":"T1204.003","name":"Malicious Image","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Flow enforcement restricting container image pulls to authorized registries and validating image provenance prevents execution of malicious container images pulled from adversary-controlled or untrusted sources."},{"id":"T1205.001","name":"Port Knocking","tactics":["command-and-control","defense-evasion","persistence"],"mapping_type":"mitigates","mapping_rationale":"Flow enforcement through stateful firewalls that track connection state and reject unexpected connection sequences prevents port knocking techniques that rely on specific packet sequences to activate hidden services."},{"id":"T1205.002","name":"Socket Filters","tactics":["command-and-control","defense-evasion","persistence"],"mapping_type":"mitigates","mapping_rationale":"Information flow controls that restrict raw socket access and BPF filter installation prevent adversaries from deploying socket filters that intercept and respond to specially crafted traffic signaling packets."},{"id":"T1213.001","name":"Confluence","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Flow enforcement restricting Confluence access to authorized user networks and enforcing data classification controls limits adversary data collection from organizational wiki repositories."},{"id":"T1213.002","name":"Sharepoint","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Information flow policies restricting SharePoint access based on user context, location, and device posture limit adversary ability to harvest documents from organizational collaboration platforms."},{"id":"T1213.004","name":"Customer Relationship Management Software","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Flow control restricting CRM system API access and data export to authorized business applications prevents adversary extraction of customer data through unauthorized CRM access channels."},{"id":"T1213.005","name":"Messaging Applications","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Information flow enforcement restricting messaging application data export and API access to authorized integrations limits adversary collection of sensitive communications from Slack, Teams, and similar platforms."},{"id":"T1218.012","name":"Verclsid","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Flow control monitoring and restricting network connections initiated by verclsid.exe and similar system binary proxies prevents adversaries from using trusted binaries to fetch remote payloads."},{"id":"T1498.001","name":"Direct Network Flood","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Flow enforcement with ingress rate limiting and traffic shaping at network boundaries mitigates direct network flood attacks by throttling volumetric traffic before it saturates target network links."},{"id":"T1498.002","name":"Reflection Amplification","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Information flow controls that filter amplified response traffic from reflection sources—including DNS, NTP, and memcached—mitigate reflection amplification DDoS by blocking spoofed-source response traffic."},{"id":"T1499.001","name":"OS Exhaustion Flood","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Flow enforcement with per-source connection rate limiting at network boundaries mitigates OS exhaustion floods by restricting the number of simultaneous connections any source can establish with target systems."},{"id":"T1499.002","name":"Service Exhaustion Flood","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Information flow controls with request rate limiting and queue management prevent service exhaustion floods by throttling excessive requests before they overwhelm application service resources."},{"id":"T1499.003","name":"Application Exhaustion Flood","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Flow enforcement with application-layer rate limiting and request validation prevents application exhaustion by blocking excessive or malformed requests that target resource-intensive application features."},{"id":"T1499.004","name":"Application or System Exploitation","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Information flow controls with input validation and protocol conformance checking at application boundaries can block exploit-based denial of service by rejecting malformed requests that trigger application crashes."},{"id":"T1505.004","name":"IIS Components","tactics":["persistence"],"mapping_type":"mitigates","mapping_rationale":"Flow control restricting IIS module installation to authorized management processes and monitoring server software component changes prevents adversary persistence through unauthorized IIS component registration."},{"id":"T1547.003","name":"Time Providers","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Information flow enforcement restricting access to Windows Time service configuration prevents adversaries from registering malicious Time Provider DLLs from unauthorized network locations for persistence."},{"id":"T1552.001","name":"Credentials In Files","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Flow control restricting access to configuration files and credential storage locations across security boundaries limits adversary ability to discover plaintext credentials in files accessible from compromised systems."},{"id":"T1552.005","name":"Cloud Instance Metadata API","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Information flow enforcement blocking instance metadata API access from application containers or restricting metadata service token scope limits adversary credential harvesting from cloud metadata endpoints."},{"id":"T1552.007","name":"Container API","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Flow control restricting container API access to authorized orchestration systems and enforcing network policies between pods prevents adversary credential extraction through unauthorized container API queries."},{"id":"T1552.008","name":"Chat Messages","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Information flow policies restricting messaging platform API access and data export from chat applications to authorized integrations limit adversary mining of credentials from messaging systems."},{"id":"T1557.001","name":"LLMNR/NBT-NS Poisoning and SMB Relay","tactics":["collection","credential-access"],"mapping_type":"mitigates","mapping_rationale":"Flow enforcement disabling LLMNR and NBT-NS at network boundaries, combined with SMB signing requirements, prevents LLMNR/NBT-NS poisoning and SMB relay attacks by eliminating the vulnerable name resolution pathways."},{"id":"T1557.002","name":"ARP Cache Poisoning","tactics":["collection","credential-access"],"mapping_type":"mitigates","mapping_rationale":"Network flow controls implementing dynamic ARP inspection, DHCP snooping, and port security prevent ARP cache poisoning by validating ARP responses against known IP-MAC bindings on managed network switches."},{"id":"T1557.003","name":"DHCP Spoofing","tactics":["collection","credential-access"],"mapping_type":"mitigates","mapping_rationale":"Flow enforcement through DHCP snooping and authorized DHCP server validation prevents DHCP spoofing by blocking rogue DHCP responses from unauthorized ports and ensuring clients receive legitimate network configurations."},{"id":"T1557.004","name":"Evil Twin","tactics":["collection","credential-access"],"mapping_type":"mitigates","mapping_rationale":"Information flow controls enforcing wireless authentication standards—including 802.1X and WPA3—and monitoring for rogue access points prevent evil twin attacks by validating access point identity before client association."},{"id":"T1559.001","name":"Component Object Model","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Flow enforcement restricting COM object instantiation across security boundaries and limiting DCOM access between network zones prevents adversary execution through unauthorized Component Object Model communications."},{"id":"T1559.002","name":"Dynamic Data Exchange","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Information flow controls that block DDE auto-update links in Office documents and restrict cross-application data exchange prevent adversary execution through Dynamic Data Exchange without requiring macros."},{"id":"T1563.002","name":"RDP Hijacking","tactics":["lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Flow control restricting RDP session access and requiring re-authentication for session transfers prevents adversaries from hijacking disconnected RDP sessions for lateral movement."},{"id":"T1564.008","name":"Email Hiding Rules","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Information flow policies that monitor and restrict email rule creation—particularly rules targeting specific senders or containing auto-delete actions—prevent adversaries from hiding their email activity."},{"id":"T1565.003","name":"Runtime Data Manipulation","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Flow enforcement with runtime data integrity validation—including transaction signing and output verification—can detect adversary manipulation of data during processing that alters business logic outcomes."},{"id":"T1566.001","name":"Spearphishing Attachment","tactics":["initial-access"],"mapping_type":"mitigates","mapping_rationale":"Information flow enforcement through email gateways with attachment analysis, sandboxing, and content disarmament blocks spearphishing attachments by neutralizing or quarantining weaponized email payloads."},{"id":"T1566.002","name":"Spearphishing Link","tactics":["initial-access"],"mapping_type":"mitigates","mapping_rationale":"Flow control through URL rewriting, click-time analysis, and web proxy enforcement blocks spearphishing links by evaluating destination safety when users click links in email messages."},{"id":"T1566.003","name":"Spearphishing via Service","tactics":["initial-access"],"mapping_type":"mitigates","mapping_rationale":"Information flow policies filtering messages across social media, messaging platforms, and collaboration tools block spearphishing via alternative services by applying content analysis to non-email communication channels."},{"id":"T1567.001","name":"Exfiltration to Code Repository","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Flow enforcement blocking or restricting uploads to code repositories—including GitHub, GitLab, and Bitbucket—from unauthorized systems prevents adversary exfiltration of data to public code hosting platforms."},{"id":"T1567.002","name":"Exfiltration to Cloud Storage","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Information flow controls restricting uploads to cloud storage services—including Dropbox, Google Drive, and OneDrive—through proxy enforcement and DLP prevent exfiltration to cloud storage destinations."},{"id":"T1567.003","name":"Exfiltration to Text Storage Sites","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Flow enforcement blocking access to text storage sites—including Pastebin, Ghostbin, and similar platforms—prevents adversary exfiltration of data to publicly accessible paste services."},{"id":"T1567.004","name":"Exfiltration Over Webhook","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Information flow controls restricting outbound webhook creation and monitoring webhook traffic patterns prevent adversary exfiltration through automated webhook-based data delivery to external endpoints."},{"id":"T1568.002","name":"Domain Generation Algorithms","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"DNS flow enforcement through organizational resolvers with DGA detection algorithms and domain reputation filtering blocks domain generation algorithm C2 by sinkholing algorithmically generated domains."},{"id":"T1573.001","name":"Symmetric Cryptography","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Flow enforcement through TLS inspection that decrypts and examines symmetrically encrypted C2 traffic at proxy boundaries enables detection and blocking of encrypted command channels."},{"id":"T1573.002","name":"Asymmetric Cryptography","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Information flow controls with certificate validation and JA3 fingerprinting can identify and block C2 channels using asymmetric encryption with self-signed or anomalous certificates at network boundaries."},{"id":"T1574.004","name":"Dylib Hijacking","tactics":["defense-evasion","persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Flow control restricting library load paths and preventing cross-boundary file writes to application directories limits adversary ability to plant malicious dylibs for dynamic library hijacking on macOS."},{"id":"T1574.005","name":"Executable Installer File Permissions Weakness","tactics":["defense-evasion","persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Information flow enforcement that restricts write access to installer directories from network sources prevents adversary exploitation of weak installer file permissions from remote compromise positions."},{"id":"T1574.007","name":"Path Interception by PATH Environment Variable","tactics":["defense-evasion","persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Flow control restricting creation of executables in PATH directories from network-connected processes prevents adversaries from remotely placing malicious binaries that intercept legitimate command execution."},{"id":"T1574.008","name":"Path Interception by Search Order Hijacking","tactics":["defense-evasion","persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Information flow policies that restrict write access to application search paths from unauthorized network locations prevent remote adversaries from exploiting search order hijacking vulnerabilities."},{"id":"T1574.009","name":"Path Interception by Unquoted Path","tactics":["defense-evasion","persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Flow enforcement restricting write access to unquoted service path directories from network sources prevents remote adversaries from exploiting path parsing vulnerabilities in Windows service configurations."},{"id":"T1574.010","name":"Services File Permissions Weakness","tactics":["defense-evasion","persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Information flow controls that restrict modification of service executable files and service DLL registrations to authorized management processes prevent remote exploitation of weak service file permissions."},{"id":"T1590.002","name":"DNS","tactics":["reconnaissance"],"mapping_type":"mitigates","mapping_rationale":"Flow enforcement through DNS security controls—including DNS response policy zones and DNS-over-HTTPS restrictions—limits adversary DNS reconnaissance by controlling what DNS information is exposed externally."},{"id":"T1598.001","name":"Spearphishing Service","tactics":["reconnaissance"],"mapping_type":"mitigates","mapping_rationale":"Information flow controls filtering inbound social engineering messages across communication platforms block spearphishing-for-information campaigns targeting organizational personnel through professional networking services."},{"id":"T1598.002","name":"Spearphishing Attachment","tactics":["reconnaissance"],"mapping_type":"mitigates","mapping_rationale":"Flow enforcement through email gateway content analysis that identifies and quarantines reconnaissance-stage attachments blocks phishing-for-information attempts using benign-appearing document pretexts."},{"id":"T1598.003","name":"Spearphishing Link","tactics":["reconnaissance"],"mapping_type":"mitigates","mapping_rationale":"Information flow policies with URL filtering and reputation analysis that block access to credential harvesting and information collection pages prevent spearphishing link-based reconnaissance campaigns."},{"id":"T1599.001","name":"Network Address Translation Traversal","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Flow enforcement through strict network device configuration controls and routing policy validation prevents adversaries from creating unauthorized NAT traversal rules that bridge isolated network segments."},{"id":"T1601.001","name":"Patch System Image","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Information flow controls restricting firmware update channels to authenticated, integrity-verified management interfaces prevent adversaries from deploying patched system images that contain backdoors."},{"id":"T1601.002","name":"Downgrade System Image","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Flow enforcement requiring firmware version validation and preventing downgrades through management plane access controls blocks adversary attempts to revert network devices to vulnerable system images."},{"id":"T1602.001","name":"SNMP (MIB Dump)","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Information flow enforcement restricting SNMP access to authorized management stations with SNMPv3 authentication prevents adversary SNMP MIB dumps that extract device configurations and network topology data."},{"id":"T1602.002","name":"Network Device Configuration Dump","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Flow control restricting network device CLI and API access to authorized management networks prevents adversary extraction of running configurations containing sensitive infrastructure details."}],"metadata":{"last_reviewed":"2026-10-03","review_notes":"2026-10-03: iso_27001_2022 A.8.22 added from NIST's SP 800-53 Rev 5 to ISO/IEC 27001:2022 crosswalk (OLIR entry 155), which OSA's mapping now takes as its base. 2026-10-03: nist_csf_2 DE.CM-09 added from NIST's CSF 2.0 to SP 800-53 Rev 5.2.0 crosswalk (OLIR entry 186), which OSA's mapping now takes as its base. 2026-10-03: baselines LMH to -MH, from NIST SP 800-53B Release 5.2.0.","mapping_status":"complete"},"function":"preventative","used_by_patterns":["SP-005","SP-011","SP-013","SP-015","SP-016","SP-017","SP-020","SP-025","SP-027","SP-028","SP-029","SP-030","SP-031","SP-036","SP-039","SP-041","SP-047","SP-050","SP-051","SP-052","SP-053","SP-054"]}}