| ID | Title | Description | External Mappings | Capability Mappings | Control Mappings |
|---|---|---|---|---|---|
| CCC.DataWar.TH01 | Unauthorized Public Access to Datasets | Datasets may be unintentionally made publicly accessible, either at the dataset level or via IAM policies, allowing unauthorized users to read or modify sensitive data, leading to data breaches and compliance violations. | 1 | 1 | 0 |
| CCC.DataWar.TH02 | Data Exfiltration via Unauthorized Views | Attackers may create or exploit unauthorized views to access sensitive data without proper permissions, leading to data leakage. | 1 | 1 | 0 |
| CCC.DataWar.TH03 | Exposure of Sensitive Data through Inadequate Column-Level Security | Lack of proper column-level security can lead to unauthorized users accessing sensitive data fields, resulting in data breaches. | 1 | 1 | 0 |
Imports
| ID | Remarks |
|---|---|
| CCC.Core.TH01 | Access Control is Misconfigured |
| CCC.Core.TH02 | Data is intercepted in transit |
| CCC.Core.TH03 | Deployment region network is untrusted |
| CCC.Core.TH04 | Data is replicated to untrusted or external locations |
| CCC.Core.TH05 | Data is corrupted during replication |
| CCC.Core.TH06 | Data is lost or corrupted |
| CCC.Core.TH07 | Logs are Tampered With or Deleted |
| CCC.Core.TH08 | Cost Management Data is Manipulated |
| CCC.Core.TH09 | Logs or Monitoring Data are Read by Unauthorized Users |
| CCC.Core.TH10 | Alerts are Intercepted |
| CCC.Core.TH11 | Event Notifications are Incorrectly Triggered |
| CCC.Core.TH12 | Resource constraints are exhausted |
| CCC.Core.TH13 | Resource Tags Are Manipulated |
| CCC.Core.TH14 | Older Resource Versions Are Exploited |
| CCC.Core.TH15 | Automated Enumeration and Reconnaissance by Non-Human Entities |