Skip to main content

Storage / File Storage / Threats / DEV

Snapshots or Replicas Expose File System Contents

CCC.FileStor.TH05

Backup snapshots, replicas, or cross-region copies of the file system may be configured with access controls broader than the primary mount. Unauthorized users or external systems can read file content from the copy without mounting the live file system. This impacts confidentiality of data retained in snapshots and replicas.

Related Capabilities

IDTitleDescription
CCC.FileStor.CP07Multi-Availability-Zone DurabilityThe service can replicate file system data across multiple availability zones within a region to improve availability during zone failures.
CCC.Core.CP08Data ReplicationThe service automatically replicates data across multiple deployments simultaneously with parity, or may be configured to do so.
CCC.Core.CP11BackupThe service can generate copies of its data or configurations in the form of automated backups, snapshot-based backups, or incremental backups.
CCC.Core.CP12RecoveryThe service can be reverted to a previous state by providing a compatible backup or snapshot identifier.

Related Controls

IDTitleDescription
CCC.FileStor.CN05Restrict Snapshot Access for File SystemsEnsure that backup snapshots and replicas of the file system are not more accessible than the primary file system.

External Mappings

FrameworkIDRemarks
MITRE-ATT&CKT1530Data from Cloud Storage Object
D3FENDD3-ACHApplication Configuration Hardening — counters T1530