| ID | Title | Objective | Control Family | Threat Mappings | Guideline Mappings | Assessment Requirements |
|---|---|---|---|---|---|---|
| CCC.RDMS.CN01 | Password Management | Ensure default vendor-supplied DB administrator credentials are replaced with strong, unique passwords and that these credentials are properly managed using a secure password or secrets management solution. | Access | 1 | 2 | 1 |
| CCC.RDMS.CN02 | Account Lockout and Rate-Limiting | Ensure the database enforces lockouts or rate-limiting after a specified number of failed authentication attempts. This prevents brute force or password-guessing attacks from succeeding. | Access | 1 | 2 | 1 |
| CCC.RDMS.CN03 | Enforce and Monitor Automated Backups | Ensure database backups are automatically scheduled, actively monitored, and promptly reported if any disruptions occur. This helps maintain data integrity, facilitates disaster recovery, and supports business continuity when a system failure or breach occurs. | Data | 1 | 2 | 1 |
| CCC.RDMS.CN04 | Access Control for Backup and Restore Operations | Restrict who can initiate, manage, and validate database backup or restore operations through strict role-based or least-privilege access. Prevents accidental or malicious restorations, protecting data integrity and availability. | Access | 1 | 2 | 1 |
| CCC.RDMS.CN05 | Restrict Snapshot Sharing to Authorized Accounts | Ensure database snapshots can only be shared with explicitly authorized accounts, thereby minimizing the risk of data exposure or exfiltration. | Access | 1 | 2 | 1 |
Imports
| ID | Remarks |
|---|---|
| CCC.Core.CN01 | Prevent unencrypted requests |
| CCC.Core.CN02 | Ensure data encryption at rest for all stored data |
| CCC.Core.CN03 | Implement multi-factor authentication (MFA) for access |
| CCC.Core.CN04 | Log all access and changes |
| CCC.Core.CN05 | Prevent access from untrusted entities |
| CCC.Core.CN06 | Prevent deployment in restricted regions |
| CCC.Core.CN07 | Alert on unusual enumeration activity |
| CCC.Core.CN08 | Enable Multi-zone or Multi-region Data Replication |
| CCC.Core.CN09 | Prevent tampering, deletion, or unauthorized access to access logs |
| CCC.Core.CN10 | Prevent data replication to destinations outside of defined trust perimeter |
| CCC.Core.CN12 | Ensure Secure Network Access Rules |