← all publishers

cyberstrikeus

@cyberstrikeus source repo

7171 published skills · page 38 of 72

  1. Cp 4 1 Coordinate With Related Plans · cyberstrikeus
    Coordinate contingency plan testing with organizational elements responsible for related plans.
    0 installs
  2. Cp 7 6 Inability To Return To Primary Site · cyberstrikeus
    Plan and prepare for circumstances that preclude returning to the primary processing site.
    0 installs
  3. Ia 8 6 Disassociability · cyberstrikeus
    Implement the following measures to disassociate user attributes or identifier assertion relationships among individuals, credential service providers
    0 installs
  4. Pe 13 4 Inspections · cyberstrikeus
    Ensure that the facility undergoes [organization-defined] fire protection inspections by authorized and qualified inspectors and identified deficienci
    0 installs
  5. Pe 7 Visitor Control · cyberstrikeus
    Visitor Control
    0 installs
  6. Ps 6 2 Classified Information Requiring Special Protection · cyberstrikeus
    Verify that access to classified information requiring special protection is granted only to individuals who: Have a valid access authorization that i
    0 installs
  7. Sa 1 Policy And Procedures · cyberstrikeus
    Develop, document, and disseminate to [organization-defined]: [organization-defined] system and services acquisition policy that: Procedures to facili
    0 installs
  8. Sa 14 Criticality Analysis · cyberstrikeus
    Criticality Analysis
    0 installs
  9. Sa 3 3 Technology Refresh · cyberstrikeus
    Plan for and implement a technology refresh schedule for the system throughout the system development life cycle.
    0 installs
  10. Sa 4 11 System Of Records · cyberstrikeus
    Include [organization-defined] in the acquisition contract for the operation of a system of records on behalf of an organization to accomplish an orga
    0 installs
  11. Sa 8 1 Clear Abstractions · cyberstrikeus
    Implement the security design principle of clear abstractions.
    0 installs
  12. Sa 8 25 Economic Security · cyberstrikeus
    Implement the security design principle of economic security in [organization-defined].
    0 installs
  13. Sa 8 7 Reduced Complexity · cyberstrikeus
    Implement the security design principle of reduced complexity in [organization-defined].
    0 installs
  14. Sa 8 9 Trusted Components · cyberstrikeus
    Implement the security design principle of trusted components in [organization-defined].
    0 installs
  15. Sc 12 1 Availability · cyberstrikeus
    Maintain availability of information in the event of the loss of cryptographic keys by users.
    0 installs
  16. Sc 7 2 Public Access · cyberstrikeus
    Public Access
    0 installs
  17. Sc 7 3 Access Points · cyberstrikeus
    Limit the number of external network connections to the system.
    0 installs
  18. Si 21 Information Refresh · cyberstrikeus
    Refresh [organization-defined] at [organization-defined] or generate the information on demand and delete the information when no longer needed.
    0 installs
  19. Si 3 2 Automatic Updates · cyberstrikeus
    Automatic Updates
    0 installs
  20. Si 4 20 Privileged Users · cyberstrikeus
    Implement the following additional monitoring of privileged users: [organization-defined].
    0 installs
  21. Si 8 2 Automatic Updates · cyberstrikeus
    Automatically update spam protection mechanisms [organization-defined].
    0 installs
  22. Cis Docker 2 10 · cyberstrikeus
    Enable user namespace support
    0 installs
  23. Cis Docker 2 11 · cyberstrikeus
    Ensure the default cgroup usage has been confirmed
    0 installs
  24. Cis Docker 2 12 · cyberstrikeus
    Ensure base device size is not changed until needed
    0 installs
  25. Cis Docker 2 13 · cyberstrikeus
    Ensure that authorization for Docker client commands is enabled
    0 installs
  26. Cis Docker 2 14 · cyberstrikeus
    Ensure centralized and remote logging is configured
    0 installs
  27. Cis Docker 2 15 · cyberstrikeus
    Ensure containers are restricted from acquiring new privileges
    0 installs
  28. Cis Docker 2 16 · cyberstrikeus
    Ensure live restore is enabled
    0 installs
  29. Cis Docker 2 17 · cyberstrikeus
    Ensure Userland Proxy is Disabled
    0 installs
  30. Cis Docker 2 18 · cyberstrikeus
    Ensure that a daemon-wide custom seccomp profile is applied if appropriate
    2 installs
  31. Cis Docker 2 19 · cyberstrikeus
    Ensure that experimental features are not implemented in production
    0 installs
  32. Cis Docker 3 10 · cyberstrikeus
    Ensure that TLS CA certificate file permissions are set to 444 or more restrictively
    2 installs
  33. Cis Docker 3 11 · cyberstrikeus
    Ensure that Docker server certificate file ownership is set to root:root
    0 installs
  34. Cis Docker 3 12 · cyberstrikeus
    Ensure that the Docker server certificate file permissions are set to 444 or more restrictively
    0 installs
  35. Cis Docker 3 13 · cyberstrikeus
    Ensure that the Docker server certificate key file ownership is set to root:root
    0 installs
  36. Cis Docker 3 14 · cyberstrikeus
    Ensure that the Docker server certificate key file permissions are set to 400
    0 installs
  37. Cis Docker 3 15 · cyberstrikeus
    Ensure that the Docker socket file ownership is set to root:docker
    0 installs
  38. Cis Docker 3 16 · cyberstrikeus
    Ensure that the Docker socket file permissions are set to 660 or more restrictively
    0 installs
  39. Cis Docker 3 17 · cyberstrikeus
    Ensure that the daemon.json file ownership is set to root:root
    0 installs
  40. Cis Docker 3 18 · cyberstrikeus
    Ensure that daemon.json file permissions are set to 644 or more restrictive
    0 installs
  41. Cis Docker 3 19 · cyberstrikeus
    Ensure that the /etc/default/docker file ownership is set to root:root
    2 installs
  42. Cis Docker 3 20 · cyberstrikeus
    Ensure that the /etc/default/docker file permissions are set to 644 or more restrictively
    0 installs
  43. Cis Docker 3 21 · cyberstrikeus
    Ensure that the /etc/sysconfig/docker file permissions are set to 644 or more restrictively
    0 installs
  44. Cis Docker 3 22 · cyberstrikeus
    Ensure that the /etc/sysconfig/docker file ownership is set to root:root
    0 installs
  45. Cis Docker 3 23 · cyberstrikeus
    Ensure that the Containerd socket file ownership is set to root:root
    0 installs
  46. Cis Docker 3 24 · cyberstrikeus
    Ensure that the Containerd socket file permissions are set to 660 or more restrictively
    0 installs
  47. Cis Docker 4 10 · cyberstrikeus
    Ensure secrets are not stored in Dockerfiles
    0 installs
  48. Cis Docker 4 11 · cyberstrikeus
    Ensure only verified packages are installed
    0 installs
  49. Cis Docker 4 12 · cyberstrikeus
    Ensure all signed artifacts are validated
    0 installs
  50. Cis Docker 5 10 · cyberstrikeus
    Ensure that the host's network namespace is not shared
    0 installs
  51. Cis Docker 5 11 · cyberstrikeus
    Ensure that the memory usage for containers is limited
    0 installs
  52. Cis Docker 5 12 · cyberstrikeus
    Ensure that CPU priority is set appropriately on containers
    0 installs
  53. Cis Docker 5 13 · cyberstrikeus
    Ensure that the container's root filesystem is mounted as read only
    0 installs
  54. Cis Docker 5 14 · cyberstrikeus
    Ensure that incoming container traffic is bound to a specific host interface
    0 installs
  55. Cis Docker 5 15 · cyberstrikeus
    Ensure that the 'on-failure' container restart policy is set to '5'
    0 installs
  56. Cis Docker 5 16 · cyberstrikeus
    Ensure that the host's process namespace is not shared
    0 installs
  57. Cis Docker 5 17 · cyberstrikeus
    Ensure that the host's IPC namespace is not shared
    0 installs
  58. Cis Docker 5 18 · cyberstrikeus
    Ensure that host devices are not directly exposed to containers
    0 installs
  59. Cis Docker 5 19 · cyberstrikeus
    Ensure that the default ulimit is overwritten at runtime if needed
    0 installs
  60. Cis Docker 5 20 · cyberstrikeus
    Ensure mount propagation mode is not set to shared
    0 installs
  61. Cis Docker 5 21 · cyberstrikeus
    Ensure that the host's UTS namespace is not shared
    0 installs
  62. Cis Docker 5 22 · cyberstrikeus
    Ensure the default seccomp profile is not Disabled
    0 installs
  63. Cis Docker 5 23 · cyberstrikeus
    Ensure that docker exec commands are not used with the privileged option
    0 installs
  64. Cis Docker 5 24 · cyberstrikeus
    Ensure that docker exec commands are not used with the user=root option
    0 installs
  65. Cis Docker 5 25 · cyberstrikeus
    Ensure that cgroup usage is confirmed
    0 installs
  66. Cis Docker 5 26 · cyberstrikeus
    Ensure that the container is restricted from acquiring additional privileges
    0 installs
  67. Cis Docker 5 27 · cyberstrikeus
    Ensure that container health is checked at runtime
    0 installs
  68. Cis Docker 5 28 · cyberstrikeus
    Ensure that Docker commands always make use of the latest version of their image
    0 installs
  69. Cis Docker 5 29 · cyberstrikeus
    Ensure that the PIDs cgroup limit is used
    0 installs
  70. Cis Docker 5 30 · cyberstrikeus
    Ensure that Docker's default bridge docker0 is not used
    0 installs
  71. Cis Docker 5 31 · cyberstrikeus
    Ensure that the host's user namespaces are not shared
    0 installs
  72. Cis Docker 5 32 · cyberstrikeus
    Ensure that the Docker socket is not mounted inside any containers
    0 installs
  73. T0855 Unauthorized Command Message · cyberstrikeus
    Adversaries may send unauthorized command messages to instruct control system assets to perform actions outside of their intended functionality, or without the logical preconditions to trigger thei...
    0 installs
  74. T1635 Steal Application Access Token · cyberstrikeus
    Adversaries can steal user application access tokens as a means of acquiring credentials to access remote systems and resources.
    0 installs
  75. T1428 Exploitation Of Remote Services · cyberstrikeus
    Adversaries may exploit remote services of enterprise servers, workstations, or other resources to gain unauthorized access to internal systems once inside of a network.
    0 installs
  76. T1548 004 Elevated Execution With Prompt · cyberstrikeus
    Adversaries may leverage the <code>AuthorizationExecuteWithPrivileges</code> API to escalate privileges by prompting the user for credentials.
    0 installs
  77. Least Privilege 03 01 05 Least Privilege · cyberstrikeus
    Allow only authorized system access for users (or processes acting on behalf of users) that is necessary to accomplish assigned organizational tasks.
    0 installs
  78. Wireless Access 03 01 16 Wireless Access · cyberstrikeus
    Establish usage restrictions, configuration requirements, and connection requirements for each type of wireless access to the system.
    0 installs
  79. Media Marking 03 08 04 Media Marking · cyberstrikeus
    Media Marking
    0 installs
  80. Media Storage 03 08 01 Media Storage · cyberstrikeus
    Media Storage
    0 installs
  81. System Backup Cryptographic Protection 03 08 09 System Backu · cyberstrikeus
    Protect the confidentiality of backup information.
    0 installs
  82. Monitoring Physical Access 03 10 02 Monitoring Physical Acce · cyberstrikeus
    Monitor physical access to the facility where the system resides to detect and respond to physical security incidents.
    0 installs
  83. Assess Prioritize And Remediate Vulnerabilities Rv 2 Assess · cyberstrikeus
    Help ensure that vulnerabilities are remediated in accordance with risk to reduce the window of opportunity for attackers.
    0 installs
  84. At 2 Literacy Training And Awareness · cyberstrikeus
    Provide security and privacy literacy training to system users (including managers, senior executives, and contractors): As part of initial training f
    0 installs
  85. At 2 4 Suspicious Communications And Anomalous System Behavi · cyberstrikeus
    Provide literacy training on recognizing suspicious communications and anomalous behavior in organizational systems using [organization-defined].
    0 installs
  86. At 3 4 Suspicious Communications And Anomalous System Behavi · cyberstrikeus
    Suspicious Communications and Anomalous System Behavior
    0 installs
  87. Au 10 1 Association Of Identities · cyberstrikeus
    Bind the identity of the information producer with the information to [organization-defined] ;
    0 installs
  88. Au 13 2 Review Of Monitored Sites · cyberstrikeus
    Review the list of open-source information sites being monitored [organization-defined].
    0 installs
  89. Au 5 3 Configurable Traffic Volume Thresholds · cyberstrikeus
    Enforce configurable network communications traffic volume thresholds reflecting limits on audit log storage capacity and [organization-defined] netwo
    0 installs
  90. Ca 7 1 Independent Assessment · cyberstrikeus
    Employ independent assessors or assessment teams to monitor the controls in the system on an ongoing basis.
    0 installs
  91. Cm 11 2 Software Installation With Privileged Status · cyberstrikeus
    Allow user installation of software only with explicit privileged status.
    0 installs
  92. Cm 12 1 Automated Tools To Support Information Location · cyberstrikeus
    Use automated tools to identify [organization-defined] on [organization-defined] to ensure controls are in place to protect organizational information
    0 installs
  93. Cm 4 1 Separate Test Environments · cyberstrikeus
    Analyze changes to the system in a separate test environment before implementation in an operational environment, looking for security and privacy imp
    0 installs
  94. Cm 5 7 Automatic Implementation Of Security Safeguards · cyberstrikeus
    Automatic Implementation of Security Safeguards
    0 installs
  95. Cm 7 7 Code Execution In Protected Environments · cyberstrikeus
    Allow execution of binary or machine-executable code only in confined physical or virtual machine environments and with the explicit approval of [orga
    0 installs
  96. Cm 8 6 Assessed Configurations And Approved Deviations · cyberstrikeus
    Include assessed component configurations and any approved deviations to current deployed configurations in the system component inventory.
    0 installs
  97. Cm 8 9 Assignment Of Components To Systems · cyberstrikeus
    Assign system components to a system;
    0 installs
  98. Cm 8 4 Accountability Information · cyberstrikeus
    Include in the system component inventory information, a means for identifying by [organization-defined] , individuals responsible and accountable for
    0 installs
  99. Cm 9 Configuration Management Plan · cyberstrikeus
    Develop, document, and implement a configuration management plan for the system that: Addresses roles, responsibilities, and configuration management
    0 installs
  100. Cp 2 4 Resume All Mission And Business Functions · cyberstrikeus
    Resume All Mission and Business Functions
    0 installs