Skip to main content

Storage / Object / Threats / DEV

Data Exfiltration via Insecure Lifecycle Policies

CCC.ObjStor.TH01

Misconfigured lifecycle policies may unintentionally allow data to be exfiltrated or destroyed prematurely, resulting in a loss of availability and potential exposure of sensitive data.

Related Capabilities

IDTitleDescription
CCC.ObjStor.CP08Lifecycle PoliciesSupports defining policies to automate data management tasks, especially those related to cost management.
CCC.Core.CP11BackupThe service can generate copies of its data or configurations in the form of automated backups, snapshot-based backups, or incremental backups.

Related Controls

IDTitleDescription
CCC.ObjStor.CN04Objects have an Effective Retention Policy by DefaultEnsure that all objects stored in the object storage system have a retention policy applied by default, preventing premature deletion or modification of objects.

External Mappings

FrameworkIDRemarks
MITRE-ATT&CKT1020
MITRE-ATT&CKT1537
MITRE-ATT&CKT1567
MITRE-ATT&CKT1048
MITRE-ATT&CKT1485