cyberstrikeus
- 7.2k skills
- 0 followers
- 2 days ago last updated
- ▌ Sa 10 Developer Configuration Management · cyberstrikeusRequire the developer of the system, system component, or system service to: Perform configuration management during system, component, or service [or
- ▌ Sa 10 3 Hardware Integrity Verification · cyberstrikeusRequire the developer of the system, system component, or system service to enable integrity verification of hardware components.
- ▌
- ▌
- ▌ Sa 15 7 Automated Vulnerability Analysis · cyberstrikeusRequire the developer of the system, system component, or system service [organization-defined] to: Perform an automated vulnerability analysis using
- ▌ Sa 3 1 Manage Preproduction Environment · cyberstrikeusProtect system preproduction environments commensurate with risk throughout the system development life cycle for the system, system component, or sys
- ▌ Sa 4 1 Functional Properties Of Controls · cyberstrikeusRequire the developer of the system, system component, or system service to provide a description of the functional properties of the controls to be i
- ▌ Sa 4 7 Niap Approved Protection Profiles · cyberstrikeusLimit the use of commercially provided information assurance and information assurance-enabled information technology products to those products th...
- ▌ Sa 8 18 Trusted Communications Channels · cyberstrikeusImplement the security design principle of trusted communications channels in [organization-defined].
- ▌ Sa 8 22 Accountability And Traceability · cyberstrikeusImplement the security design principle of accountability and traceability in [organization-defined].
- ▌ Sc 15 4 Explicitly Indicate Current Participants · cyberstrikeusProvide an explicit indication of current participants in [organization-defined].
- ▌ Sc 20 Secure Nameaddress Resolution Service Authoritative So · cyberstrikeusProvide additional data origin authentication and integrity verification artifacts along with the authoritative name resolution data the system ret...
- ▌ Sc 21 Secure Nameaddress Resolution Service Recursive Or Cac · cyberstrikeusRequest and perform data origin authentication and data integrity verification on the name/address resolution responses the system receives from autho
- ▌ Sc 40 2 Reduce Detection Potential · cyberstrikeusImplement cryptographic mechanisms to reduce the detection potential of wireless links to [organization-defined].
- ▌ Sc 7 13 Isolation Of Security Tools Mechanisms And Support C · cyberstrikeusIsolate [organization-defined] from other internal system components by implementing physically separate subnetworks with managed interfaces to other
- ▌ Sc 7 16 Prevent Discovery Of System Components · cyberstrikeusPrevent the discovery of specific system components that represent a managed interface.
- ▌ Sc 7 29 Separate Subnets To Isolate Functions · cyberstrikeusImplement [organization-defined] separate subnetworks to isolate the following critical system components and functions: [organization-defined].
- ▌ Sc 8 3 Cryptographic Protection For Message Externals · cyberstrikeusImplement cryptographic mechanisms to protect message externals unless otherwise protected by [organization-defined].
- ▌ Si 13 2 Time Limit On Process Execution Without Supervision · cyberstrikeusTime Limit on Process Execution Without Supervision
- ▌ Si 19 5 Statistical Disclosure Control · cyberstrikeusManipulate numerical data, contingency tables, and statistical findings so that no individual or organization is identifiable in the results of the an
- ▌ Si 4 7 Automated Response To Suspicious Events · cyberstrikeusNotify [organization-defined] of detected suspicious events;
- ▌ Si 5 1 Automated Alerts And Advisories · cyberstrikeusBroadcast security alert and advisory information throughout the organization using [organization-defined].
- ▌ Si 7 16 Time Limit On Process Execution Without Supervision · cyberstrikeusProhibit processes from executing without supervision for more than [organization-defined].
- ▌ Cis AWS Foundations 2 10 · cyberstrikeusEnsure multi-factor authentication (MFA) is enabled for all IAM users that have a console password
- ▌
- ▌
- ▌
- ▌ Cis AWS Foundations 2 14 · cyberstrikeusEnsure IAM policies that allow full "*:*" administrative privileges are not attached
- ▌ Cis AWS Foundations 2 15 · cyberstrikeusEnsure a support role has been created to manage incidents with AWS Support
- ▌ Cis AWS Foundations 2 16 · cyberstrikeusEnsure IAM instance roles are used for AWS resource access from instances
- ▌ Cis AWS Foundations 2 17 · cyberstrikeusEnsure that all expired SSL/TLS certificates stored in AWS IAM are removed
- ▌ Cis AWS Foundations 2 18 · cyberstrikeusEnsure that IAM External Access Analyzer is enabled for all regions
- ▌ Cis AWS Foundations 2 19 · cyberstrikeusEnsure IAM users are managed centrally via identity federation or AWS Organizations for multi-account environments
- ▌
- ▌ Cis AWS Foundations 2 21 · cyberstrikeusEnsure AWS resource policies do not allow unrestricted access using "Principal": "*"
- ▌ Cis AWS Foundations 4 10 · cyberstrikeusEnsure all AWS-managed web front-end services have access logging enabled
- ▌
- ▌ Cis AWS Foundations 5 11 · cyberstrikeusEnsure Network Access Control List (NACL) changes are monitored
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌ Cis AWS Compute 11 1 · cyberstrikeusEnsure customer-managed keys are used to encrypt AWS Fargate ephemeral storage data for Amazon ECS
- ▌
- ▌
- ▌ Cis AWS Compute 12 3 · cyberstrikeusEnsure AWS Secrets manager is configured and being used by Lambda for databases
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌ Cis AWS Compute 12 9 · cyberstrikeusEnsure there are no Lambda functions with admin privileges within your AWS account
- ▌ Cis AWS Compute 16 1 · cyberstrikeusEnsure communications between your applications and clients is encrypted
- ▌
- ▌
- ▌ Cis AWS Compute 2 12 · cyberstrikeusEnsure EBS volumes attached to an EC2 instance are marked for deletion upon instance termination
- ▌ Cis AWS Compute 2 13 · cyberstrikeusEnsure Secrets and Sensitive Data are not stored directly in EC2 User Data
- ▌ Cis AWS Compute 2 14 · cyberstrikeusEnsure EC2 Auto Scaling Groups Propagate Tags to EC2 Instances that it launches
- ▌
- ▌
- ▌
- ▌
- ▌ Cis AWS Compute 3 14 · cyberstrikeusEnsure 'assignPublicIp' is set to 'DISABLED' for Amazon ECS task sets
- ▌
- ▌ Cis AWS Compute 5 11 · cyberstrikeusEnsure your Windows Server based lightsail instances are updated with the latest security patches
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌ Cis AWS Database 5 12 · cyberstrikeusEnsure ElastiCache is deployed across multiple Availability Zones (AZs)
- ▌
- ▌
- ▌