| ID | Title | Description | External Mappings | Capability Mappings | Control Mappings |
|---|---|---|---|---|---|
| CCC.Build.TH01 | Unauthorized Build Execution | Attackers may trigger builds using unauthorized build agents or external services, leading to unauthorized code execution or deployment of malicious code. | 1 | 1 | 0 |
| CCC.Build.TH02 | External Exposure of Build Environments | If build environments have external network access, they may be accessed by unauthorized parties, leading to data exfiltration or tampering. | 1 | 1 | 0 |
Imports
| ID | Remarks |
|---|---|
| CCC.Core.TH01 | Access control is misconfigured |
| CCC.Core.TH02 | Data is intercepted in transit |
| CCC.Core.TH03 | Deployment region network is untrusted |
| CCC.Core.TH04 | Data is replicated to untrusted or external locations |
| CCC.Core.TH05 | Data is corrupted during replication |
| CCC.Core.TH06 | Data is lost or corrupted |
| CCC.Core.TH07 | Logs are Tampered With or Deleted |
| CCC.Core.TH09 | Logs or Monitoring Data are Read by Unauthorized Users |
| CCC.Core.TH11 | Event Notifications are Incorrectly Triggered |
| CCC.Core.TH12 | Resource constraints are exhausted |
| CCC.Core.TH14 | Older Resource Versions Are Exploited |
| CCC.Core.TH15 | Automated Enumeration and Reconnaissance by Non-Human Entities |
| CCC.Core.TH16 | Logging and Monitoring are Disabled |