cyberstrikeus
- 7.2k skills
- 0 followers
- 2 days ago last updated
- ▌ Cp 4 1 Coordinate With Related Plans · cyberstrikeusCoordinate contingency plan testing with organizational elements responsible for related plans.
- ▌ Cp 7 6 Inability To Return To Primary Site · cyberstrikeusPlan and prepare for circumstances that preclude returning to the primary processing site.
- ▌ Ia 8 6 Disassociability · cyberstrikeusImplement the following measures to disassociate user attributes or identifier assertion relationships among individuals, credential service providers
- ▌ Pe 13 4 Inspections · cyberstrikeusEnsure that the facility undergoes [organization-defined] fire protection inspections by authorized and qualified inspectors and identified deficienci
- ▌
- ▌ Ps 6 2 Classified Information Requiring Special Protection · cyberstrikeusVerify that access to classified information requiring special protection is granted only to individuals who: Have a valid access authorization that i
- ▌ Sa 1 Policy And Procedures · cyberstrikeusDevelop, document, and disseminate to [organization-defined]: [organization-defined] system and services acquisition policy that: Procedures to facili
- ▌
- ▌ Sa 3 3 Technology Refresh · cyberstrikeusPlan for and implement a technology refresh schedule for the system throughout the system development life cycle.
- ▌ Sa 4 11 System Of Records · cyberstrikeusInclude [organization-defined] in the acquisition contract for the operation of a system of records on behalf of an organization to accomplish an orga
- ▌ Sa 8 1 Clear Abstractions · cyberstrikeusImplement the security design principle of clear abstractions.
- ▌ Sa 8 25 Economic Security · cyberstrikeusImplement the security design principle of economic security in [organization-defined].
- ▌ Sa 8 7 Reduced Complexity · cyberstrikeusImplement the security design principle of reduced complexity in [organization-defined].
- ▌ Sa 8 9 Trusted Components · cyberstrikeusImplement the security design principle of trusted components in [organization-defined].
- ▌ Sc 12 1 Availability · cyberstrikeusMaintain availability of information in the event of the loss of cryptographic keys by users.
- ▌
- ▌ Sc 7 3 Access Points · cyberstrikeusLimit the number of external network connections to the system.
- ▌ Si 21 Information Refresh · cyberstrikeusRefresh [organization-defined] at [organization-defined] or generate the information on demand and delete the information when no longer needed.
- ▌
- ▌ Si 4 20 Privileged Users · cyberstrikeusImplement the following additional monitoring of privileged users: [organization-defined].
- ▌ Si 8 2 Automatic Updates · cyberstrikeusAutomatically update spam protection mechanisms [organization-defined].
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌ Cis Docker 2 18 · cyberstrikeusEnsure that a daemon-wide custom seccomp profile is applied if appropriate
- ▌
- ▌ Cis Docker 3 10 · cyberstrikeusEnsure that TLS CA certificate file permissions are set to 444 or more restrictively
- ▌ Cis Docker 3 11 · cyberstrikeusEnsure that Docker server certificate file ownership is set to root:root
- ▌ Cis Docker 3 12 · cyberstrikeusEnsure that the Docker server certificate file permissions are set to 444 or more restrictively
- ▌ Cis Docker 3 13 · cyberstrikeusEnsure that the Docker server certificate key file ownership is set to root:root
- ▌ Cis Docker 3 14 · cyberstrikeusEnsure that the Docker server certificate key file permissions are set to 400
- ▌
- ▌ Cis Docker 3 16 · cyberstrikeusEnsure that the Docker socket file permissions are set to 660 or more restrictively
- ▌
- ▌ Cis Docker 3 18 · cyberstrikeusEnsure that daemon.json file permissions are set to 644 or more restrictive
- ▌ Cis Docker 3 19 · cyberstrikeusEnsure that the /etc/default/docker file ownership is set to root:root
- ▌ Cis Docker 3 20 · cyberstrikeusEnsure that the /etc/default/docker file permissions are set to 644 or more restrictively
- ▌ Cis Docker 3 21 · cyberstrikeusEnsure that the /etc/sysconfig/docker file permissions are set to 644 or more restrictively
- ▌ Cis Docker 3 22 · cyberstrikeusEnsure that the /etc/sysconfig/docker file ownership is set to root:root
- ▌ Cis Docker 3 23 · cyberstrikeusEnsure that the Containerd socket file ownership is set to root:root
- ▌ Cis Docker 3 24 · cyberstrikeusEnsure that the Containerd socket file permissions are set to 660 or more restrictively
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌ Cis Docker 5 14 · cyberstrikeusEnsure that incoming container traffic is bound to a specific host interface
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌ Cis Docker 5 23 · cyberstrikeusEnsure that docker exec commands are not used with the privileged option
- ▌ Cis Docker 5 24 · cyberstrikeusEnsure that docker exec commands are not used with the user=root option
- ▌
- ▌ Cis Docker 5 26 · cyberstrikeusEnsure that the container is restricted from acquiring additional privileges
- ▌
- ▌ Cis Docker 5 28 · cyberstrikeusEnsure that Docker commands always make use of the latest version of their image
- ▌
- ▌
- ▌
- ▌
- ▌ T0855 Unauthorized Command Message · cyberstrikeusAdversaries may send unauthorized command messages to instruct control system assets to perform actions outside of their intended functionality, or without the logical preconditions to trigger thei...
- ▌ T1635 Steal Application Access Token · cyberstrikeusAdversaries can steal user application access tokens as a means of acquiring credentials to access remote systems and resources.
- ▌ T1428 Exploitation Of Remote Services · cyberstrikeusAdversaries may exploit remote services of enterprise servers, workstations, or other resources to gain unauthorized access to internal systems once inside of a network.
- ▌ T1548 004 Elevated Execution With Prompt · cyberstrikeusAdversaries may leverage the <code>AuthorizationExecuteWithPrivileges</code> API to escalate privileges by prompting the user for credentials.
- ▌ Least Privilege 03 01 05 Least Privilege · cyberstrikeusAllow only authorized system access for users (or processes acting on behalf of users) that is necessary to accomplish assigned organizational tasks.
- ▌ Wireless Access 03 01 16 Wireless Access · cyberstrikeusEstablish usage restrictions, configuration requirements, and connection requirements for each type of wireless access to the system.
- ▌
- ▌
- ▌ System Backup Cryptographic Protection 03 08 09 System Backu · cyberstrikeusProtect the confidentiality of backup information.
- ▌ Monitoring Physical Access 03 10 02 Monitoring Physical Acce · cyberstrikeusMonitor physical access to the facility where the system resides to detect and respond to physical security incidents.
- ▌ Assess Prioritize And Remediate Vulnerabilities Rv 2 Assess · cyberstrikeusHelp ensure that vulnerabilities are remediated in accordance with risk to reduce the window of opportunity for attackers.
- ▌ At 2 Literacy Training And Awareness · cyberstrikeusProvide security and privacy literacy training to system users (including managers, senior executives, and contractors): As part of initial training f
- ▌ At 2 4 Suspicious Communications And Anomalous System Behavi · cyberstrikeusProvide literacy training on recognizing suspicious communications and anomalous behavior in organizational systems using [organization-defined].
- ▌ At 3 4 Suspicious Communications And Anomalous System Behavi · cyberstrikeusSuspicious Communications and Anomalous System Behavior
- ▌ Au 10 1 Association Of Identities · cyberstrikeusBind the identity of the information producer with the information to [organization-defined] ;
- ▌ Au 13 2 Review Of Monitored Sites · cyberstrikeusReview the list of open-source information sites being monitored [organization-defined].
- ▌ Au 5 3 Configurable Traffic Volume Thresholds · cyberstrikeusEnforce configurable network communications traffic volume thresholds reflecting limits on audit log storage capacity and [organization-defined] netwo
- ▌ Ca 7 1 Independent Assessment · cyberstrikeusEmploy independent assessors or assessment teams to monitor the controls in the system on an ongoing basis.
- ▌ Cm 11 2 Software Installation With Privileged Status · cyberstrikeusAllow user installation of software only with explicit privileged status.
- ▌ Cm 12 1 Automated Tools To Support Information Location · cyberstrikeusUse automated tools to identify [organization-defined] on [organization-defined] to ensure controls are in place to protect organizational information
- ▌ Cm 4 1 Separate Test Environments · cyberstrikeusAnalyze changes to the system in a separate test environment before implementation in an operational environment, looking for security and privacy imp
- ▌ Cm 5 7 Automatic Implementation Of Security Safeguards · cyberstrikeusAutomatic Implementation of Security Safeguards
- ▌ Cm 7 7 Code Execution In Protected Environments · cyberstrikeusAllow execution of binary or machine-executable code only in confined physical or virtual machine environments and with the explicit approval of [orga
- ▌ Cm 8 6 Assessed Configurations And Approved Deviations · cyberstrikeusInclude assessed component configurations and any approved deviations to current deployed configurations in the system component inventory.
- ▌
- ▌ Cm 8 4 Accountability Information · cyberstrikeusInclude in the system component inventory information, a means for identifying by [organization-defined] , individuals responsible and accountable for
- ▌ Cm 9 Configuration Management Plan · cyberstrikeusDevelop, document, and implement a configuration management plan for the system that: Addresses roles, responsibilities, and configuration management
- ▌ Cp 2 4 Resume All Mission And Business Functions · cyberstrikeusResume All Mission and Business Functions