Skip to main content

Management / Monitoring / Controls / DEV

Metrics pushed for authorised services only

CCC.Monitor.CN06 · Access

Use IAM to control which types of metrics or traces can be pushed by different system to avoid a compromised system pushing fabricated metrics about a different service

Related Capabilities

IDTitleDescription
CCC.Monitoring.CP01CCC.Monitoring.CP01
CCC.Monitoring.CP11CCC.Monitoring.CP11

Related Threats

IDTitleDescription
CCC.Monitor.TH05Data Exfiltration Through Tampered MetricsIf a malicious actor is able to make changes to the metrics being collected, it could be used to encrypt and or compress sensitive data and bypass controls preventing exfiltration. The data can then be staged in the monitoring system and exfiltrated in bulk at a later point in time

Assessment Requirements

IDTextApplicability
CCC.Monitor.CN06.AR01When systems push metrics or traces they MUST be authenticated for that particular type of metric or tracetlp-clear, tlp-green, tlp-amber, tlp-red

Guideline Mappings

FrameworkIDRemarks
NIST-CSFPR.AA-05
NIST_800_53AC-5