| ID | Title | Description | External Mappings | Capability Mappings | Control Mappings |
|---|---|---|---|---|---|
| CCC.RDMS.TH01 | Unauthorized Access via Default Credentials | If default credentials are not disabled or changed, unauthorized access may be gained to the RDMS environment. This may lead to data breaches, data manipulation, or overall compromise of the database instance. | 1 | 1 | 1 |
| CCC.RDMS.TH02 | Brute Force Attempts on Database Authentication | Repeated attempts to guess database user passwords may be made through brute force techniques. This condition could result in unauthorized access if successful, compromising database security and sensitive information. | 1 | 1 | 1 |
| CCC.RDMS.TH03 | Database Backups Stopped | Database backups may be halted, potentially impairing the organization's ability to recover data and maintain business continuity. This condition increases the risk of data loss and extended system downtime. | 1 | 1 | 1 |
| CCC.RDMS.TH04 | Unintentional Database Backup Restoration | A database backup may be restored unintentionally, potentially leading to the loss or overwrite of current data. This condition could disrupt operations and result in data inconsistency or corruption. | 1 | 1 | 1 |
| CCC.RDMS.TH05 | Unauthorized Snapshot Sharing | Snapshots may be shared with untrusted accounts, which can lead to unauthorized access and potential data exfiltration. This significantly increases the risk of data exposure if sensitive information is contained in the snapshots. | 1 | 1 | 1 |
Imports
| ID | Remarks |
|---|---|
| CCC.Core.TH01 | Access control is misconfigured |
| CCC.Core.TH02 | Data is intercepted in transit |
| CCC.Core.TH03 | Deployment region network is untrusted |
| CCC.Core.TH04 | Data is Replicated to Untrusted or External Locations |
| CCC.Core.TH05 | Data is corrupted during replication |
| CCC.Core.TH06 | Data is lost or corrupted |
| CCC.Core.TH07 | Logs are tampered with or deleted |
| CCC.Core.TH09 | Logs or monitoring data are read by unauthorized users |
| CCC.Core.TH10 | Alerts are Intercepted |
| CCC.Core.TH11 | Event Notifications are Incorrectly Triggered |
| CCC.Core.TH12 | Resource constraints are exhausted |
| CCC.Core.TH13 | Resource tags are manipulated |
| CCC.Core.TH15 | Automated enumeration and reconnaissance by non-human entities |
| CCC.Core.TH16 | Logging and Monitoring are Disabled |
| CCC.Core.TH17 | Unauthorized Network Access via Misconfigured Rules |