cyberstrikeus
- 7.2k skills
- 0 followers
- 2 days ago last updated
- ▌ Sr 2 Supply Chain Risk Management Plan · cyberstrikeusDevelop a plan for managing supply chain risks associated with the research and development, design, manufacturing, acquisition, delivery, integrat...
- ▌ Cis K8S V200 2 1 · cyberstrikeusEnsure that the --cert-file and --key-file arguments are set as appropriate (Automated)
- ▌ Cis K8S V200 2 2 · cyberstrikeusEnsure that the --client-cert-auth argument is set to true (Automated)
- ▌
- ▌ Cis K8S V200 2 4 · cyberstrikeusEnsure that the --peer-cert-file and --peer-key-file arguments are set as appropriate (Automated)
- ▌ Cis K8S V200 2 5 · cyberstrikeusEnsure that the --peer-client-cert-auth argument is set to true (Automated)
- ▌ Cis K8S V200 2 6 · cyberstrikeusEnsure that the --peer-auto-tls argument is not set to true (Automated)
- ▌ Cis K8S V200 2 7 · cyberstrikeusEnsure that a unique Certificate Authority is used for etcd (Manual)
- ▌ Cis Ocp V160 2 1 · cyberstrikeusEnsure that the --cert-file and --key-file arguments are set as appropriate (Manual)
- ▌ Cis Ocp V160 2 2 · cyberstrikeusEnsure that the --client-cert-auth argument is set to true (Manual)
- ▌
- ▌ Cis Ocp V160 2 4 · cyberstrikeusEnsure that the --peer-cert-file and --peer-key-file arguments are set as appropriate (Manual)
- ▌ Cis Ocp V160 2 5 · cyberstrikeusEnsure that the --peer-client-cert-auth argument is set to true (Manual)
- ▌ Cis Ocp V160 2 6 · cyberstrikeusEnsure that the --peer-auto-tls argument is not set to true (Manual)
- ▌ Cis Ocp V160 2 7 · cyberstrikeusEnsure that a unique Certificate Authority is used for etcd (Manual)
- ▌ Information In Shared System Resources 03 13 04 Information · cyberstrikeusInformation in Shared System Resources
- ▌ Network Communications Deny By Default Allow By Exception 03 · cyberstrikeusNetwork Communications – Deny by Default – Allow by Exception
- ▌ Access Restrictions For Change 03 04 05 Access Restrictions · cyberstrikeusAccess Restrictions for Change
- ▌ Identifier Management 03 05 05 Identifier Management · cyberstrikeusReceive authorization from organizational personnel or roles to assign an individual, group, role, service, or device identifier.
- ▌ Information Exchange 03 12 05 Information Exchange · cyberstrikeusApprove and manage the exchange of CUI between the system and other systems using [organization-defined].
- ▌ Configure The Compilation Interpreter And Build Processes To · cyberstrikeusDecrease the number of security vulnerabilities in the software and reduce costs by eliminating vulnerabilities before testing occurs.
- ▌ Ca 2 3 Leveraging Results From External Organizations · cyberstrikeusLeverage the results of control assessments performed by [organization-defined] on [organization-defined] when the assessment meets [organization-defi
- ▌ Ia 2 6 Access To Accounts Separate Device · cyberstrikeusImplement multi-factor authentication for [organization-defined] access to [organization-defined] such that: One of the factors is provided by a devic
- ▌ Ia 3 1 Cryptographic Bidirectional Authentication · cyberstrikeusAuthenticate [organization-defined] before establishing [organization-defined] connection using bidirectional authentication that is cryptographically
- ▌ Ia 3 2 Cryptographic Bidirectional Network Authentication · cyberstrikeusCryptographic Bidirectional Network Authentication
- ▌ Ia 3 3 Dynamic Address Allocation · cyberstrikeusWhere addresses are allocated dynamically, standardize dynamic address allocation lease information and the lease duration assigned to devices in a...
- ▌
- ▌ Sa 12 1 Acquisition Strategies Tools Methods · cyberstrikeusAcquisition Strategies / Tools / Methods
- ▌
- ▌ Sa 12 13 Critical Information System Components · cyberstrikeusCritical Information System Components
- ▌
- ▌ Sa 17 Developer Security And Privacy Architecture And Design · cyberstrikeusRequire the developer of the system, system component, or system service to produce a design specification and security and privacy architecture that:
- ▌ Sa 4 9 Functions Ports Protocols And Services In Use · cyberstrikeusRequire the developer of the system, system component, or system service to identify the functions, ports, protocols, and services intended for organi
- ▌ Sa 8 13 Minimized Security Elements · cyberstrikeusImplement the security design principle of minimized security elements in [organization-defined].
- ▌ Sa 8 24 Secure Failure And Recovery · cyberstrikeusImplement the security design principle of secure failure and recovery in [organization-defined].
- ▌
- ▌ Sc 16 1 Integrity Verification · cyberstrikeusVerify the integrity of transmitted security and privacy attributes.
- ▌ Sc 17 Public Key Infrastructure Certificates · cyberstrikeusIssue public key certificates under an [organization-defined] or obtain public key certificates from an approved service provider;
- ▌ Sc 18 3 Prevent Downloading And Execution · cyberstrikeusPrevent the download and execution of [organization-defined].
- ▌ Sc 18 5 Allow Execution Only In Confined Environments · cyberstrikeusAllow execution of permitted mobile code only in confined virtual machine environments.
- ▌ Sc 30 4 Misleading Information · cyberstrikeusEmploy realistic, but misleading information in [organization-defined] about its security state or posture.
- ▌ Sc 41 Port And Io Device Access · cyberstrikeus[organization-defined] disable or remove [organization-defined] on the following systems or system components: [organization-defined].
- ▌ Sc 42 1 Reporting To Authorized Individuals Or Roles · cyberstrikeusVerify that the system is configured so that data or information collected by the [organization-defined] is only reported to authorized individuals or
- ▌ Sc 51 Hardware Based Protection · cyberstrikeusEmploy hardware-based, write-protect for [organization-defined] ;
- ▌ Sc 7 24 Personally Identifiable Information · cyberstrikeusFor systems that process personally identifiable information: Apply the following processing rules to data elements of personally identifiable informa
- ▌ Sc 7 5 Deny By Default Allow By Exception · cyberstrikeusDeny network communications traffic by default and allow network communications traffic by exception [organization-defined].
- ▌ Si 10 1 Manual Override Capability · cyberstrikeusProvide a manual override capability for input validation of the following information inputs: [organization-defined];
- ▌
- ▌ Si 4 3 Automated Tool And Mechanism Integration · cyberstrikeusEmploy automated tools and mechanisms to integrate intrusion detection tools and mechanisms into access control and flow control mechanisms.
- ▌ Si 5 Security Alerts Advisories And Directives · cyberstrikeusReceive system security alerts, advisories, and directives from [organization-defined] on an ongoing basis;
- ▌ Si 6 3 Report Verification Results · cyberstrikeusReport the results of security and privacy function verification to [organization-defined].
- ▌ Si 7 13 Code Execution In Protected Environments · cyberstrikeusCode Execution in Protected Environments
- ▌ Si 7 7 Integration Of Detection And Response · cyberstrikeusIncorporate the detection of the following unauthorized changes into the organizational incident response capability: [organization-defined].
- ▌
- ▌ Sr 4 4 Supply Chain Integrity Pedigree · cyberstrikeusEmploy [organization-defined] and conduct [organization-defined] to ensure the integrity of the system and system components by validating the interna
- ▌ Impact Analyses 03 04 04 Impact Analyses · cyberstrikeusAnalyze changes to the system to determine potential security impacts prior to change implementation.
- ▌
- ▌ External System Services 03 16 03 External System Services · cyberstrikeusRequire the providers of external system services used for the processing, storage, or transmission of CUI to comply with the following security re...
- ▌ Ca 3 7 Transitive Information Exchanges · cyberstrikeusIdentify transitive (downstream) information exchanges with other systems through the systems identified in [CA-3a](#ca-3_smt.a) ;
- ▌ Ca 7 6 Automation Support For Monitoring · cyberstrikeusEnsure the accuracy, currency, and availability of monitoring results for the system using [organization-defined].
- ▌ Ia 2 13 Out Of Band Authentication · cyberstrikeusImplement the following out-of-band authentication mechanisms under [organization-defined]: [organization-defined].
- ▌ Ia 5 10 Dynamic Credential Binding · cyberstrikeusBind identities and authenticators dynamically using the following rules: [organization-defined].
- ▌ Pe 6 Monitoring Physical Access · cyberstrikeusMonitor physical access to the facility where the system resides to detect and respond to physical security incidents;
- ▌
- ▌ Sa 10 5 Mapping Integrity For Version Control · cyberstrikeusRequire the developer of the system, system component, or system service to maintain the integrity of the mapping between the master build data descri
- ▌ Sa 12 11 Penetration Testing Analysis Of Elements Processes · cyberstrikeusPenetration Testing / Analysis of Elements, Processes, and Actors
- ▌ Sa 15 2 Security And Privacy Tracking Tools · cyberstrikeusRequire the developer of the system, system component, or system service to select and employ security and privacy tracking tools for use during the d
- ▌ Sa 15 11 Archive System Or Component · cyberstrikeusRequire the developer of the system or system component to archive the system or component to be released or delivered together with the corresponding
- ▌ Sa 17 2 Security Relevant Components · cyberstrikeusRequire the developer of the system, system component, or system service to: Define security-relevant hardware, software, and firmware; and Provide a
- ▌
- ▌ Sa 4 3 Development Methods Techniques And Practices · cyberstrikeusRequire the developer of the system, system component, or system service to demonstrate the use of a system development life cycle process that includ
- ▌ Sa 4 8 Continuous Monitoring Plan For Controls · cyberstrikeusRequire the developer of the system, system component, or system service to produce a plan for continuous monitoring of control effectiveness that is
- ▌ Sa 4 10 Use Of Approved Piv Products · cyberstrikeusEmploy only information technology products on the FIPS 201-approved products list for Personal Identity Verification (PIV) capability implemented wit
- ▌ Sa 8 Security And Privacy Engineering Principles · cyberstrikeusApply the following systems security and privacy engineering principles in the specification, design, development, implementation, and modification of
- ▌ Sa 8 16 Self Reliant Trustworthiness · cyberstrikeusImplement the security design principle of self-reliant trustworthiness in [organization-defined].
- ▌ Sa 9 5 Processing Storage And Service Location · cyberstrikeusRestrict the location of [organization-defined] to [organization-defined] based on [organization-defined].
- ▌ Sc 3 Security Function Isolation · cyberstrikeusIsolate security functions from nonsecurity functions.
- ▌ Sc 31 1 Test Covert Channels For Exploitability · cyberstrikeusTest a subset of the identified covert channels to determine the channels that are exploitable.
- ▌
- ▌
- ▌ Sc 42 5 Collection Minimization · cyberstrikeusEmploy [organization-defined] that are configured to minimize the collection of information about individuals that is not needed.
- ▌ Sc 5 3 Detection And Monitoring · cyberstrikeusEmploy the following monitoring tools to detect indicators of denial-of-service attacks against, or launched from, the system: [organization-define...
- ▌ Sc 7 17 Automated Enforcement Of Protocol Formats · cyberstrikeusEnforce adherence to protocol formats.
- ▌ Sc 8 2 Pre And Post Transmission Handling · cyberstrikeusMaintain the [organization-defined] of information during preparation for transmission and during reception.
- ▌ Sc 8 1 Cryptographic Protection · cyberstrikeusImplement cryptographic mechanisms to [organization-defined] during transmission.
- ▌ Si 13 Predictable Failure Prevention · cyberstrikeusDetermine mean time to failure (MTTF) for the following system components in specific environments of operation: [organization-defined] ;
- ▌ Si 14 3 Non Persistent Connectivity · cyberstrikeusEstablish connections to the system on demand and terminate connections after [organization-defined].
- ▌
- ▌ Si 3 8 Detect Unauthorized Commands · cyberstrikeusDetect the following unauthorized operating system commands through the kernel application programming interface on [organization-defined]: [organi...
- ▌
- ▌
- ▌ Si 7 10 Protection Of Boot Firmware · cyberstrikeusImplement the following mechanisms to protect the integrity of boot firmware in [organization-defined]: [organization-defined].
- ▌ Sr 3 Supply Chain Controls And Processes · cyberstrikeusEstablish a process or processes to identify and address weaknesses or deficiencies in the supply chain elements and processes of [organization-def...
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌