← all publishers

cyberstrikeus

@cyberstrikeus source repo

7171 published skills · page 49 of 72

  1. Pe 3 6 Facility Penetration Testing · cyberstrikeus
    Facility Penetration Testing
    0 installs
  2. Pe 4 Access Control For Transmission · cyberstrikeus
    Control physical access to [organization-defined] within organizational facilities using [organization-defined].
    0 installs
  3. Pe 6 4 Monitoring Physical Access To Systems · cyberstrikeus
    Monitor physical access to the system in addition to the physical access monitoring of the facility at [organization-defined].
    0 installs
  4. Pe 8 1 Automated Records Maintenance And Review · cyberstrikeus
    Maintain and review visitor access records using [organization-defined].
    0 installs
  5. Pe 8 3 Limit Personally Identifiable Information Elements · cyberstrikeus
    Limit personally identifiable information contained in visitor access records to the following elements identified in the privacy risk assessment: [or
    0 installs
  6. Pt 7 Specific Categories Of Personally Identifiable Informat · cyberstrikeus
    Apply [organization-defined] for specific categories of personally identifiable information.
    0 installs
  7. Sc 12 Cryptographic Key Establishment And Management · cyberstrikeus
    Establish and manage cryptographic keys when cryptography is employed within the system in accordance with the following key management requirements:
    0 installs
  8. Sc 15 2 Blocking Inbound And Outbound Communications Traffic · cyberstrikeus
    Blocking Inbound and Outbound Communications Traffic
    0 installs
  9. Sc 15 Collaborative Computing Devices And Applications · cyberstrikeus
    Prohibit remote activation of collaborative computing devices and applications with the following exceptions: [organization-defined] ;
    0 installs
  10. Sc 30 3 Change Processing And Storage Locations · cyberstrikeus
    Change the location of [organization-defined] [organization-defined]].
    0 installs
  11. Sc 32 1 Separate Physical Domains For Privileged Functions · cyberstrikeus
    Partition privileged functions into separate physical domains.
    0 installs
  12. Sc 39 2 Separate Execution Domain Per Thread · cyberstrikeus
    Maintain a separate execution domain for each thread in [organization-defined].
    0 installs
  13. Sc 40 1 Electromagnetic Interference · cyberstrikeus
    Implement cryptographic mechanisms that achieve [organization-defined] against the effects of intentional electromagnetic interference.
    0 installs
  14. Sc 46 Cross Domain Policy Enforcement · cyberstrikeus
    Implement a policy enforcement mechanism [organization-defined] between the physical and/or network interfaces for the connecting security domains.
    0 installs
  15. Sc 48 1 Dynamic Relocation Of Sensors Or Monitoring Capabili · cyberstrikeus
    Dynamically relocate [organization-defined] to [organization-defined] under the following conditions or circumstances: [organization-defined].
    0 installs
  16. Sc 7 8 Route Traffic To Authenticated Proxy Servers · cyberstrikeus
    Route [organization-defined] to [organization-defined] through authenticated proxy servers at managed interfaces.
    0 installs
  17. Sc 8 Transmission Confidentiality And Integrity · cyberstrikeus
    Protect the [organization-defined] of transmitted information.
    0 installs
  18. Sc 8 5 Protected Distribution System · cyberstrikeus
    Implement [organization-defined] to [organization-defined] during transmission.
    0 installs
  19. Cis Ocp V170 2 1 · cyberstrikeus
    Ensure --cert-file and --key-file set (Manual)
    0 installs
  20. Cis Ocp V170 2 2 · cyberstrikeus
    Ensure --client-cert-auth set to true (Manual)
    0 installs
  21. Cis Ocp V170 2 3 · cyberstrikeus
    Ensure --auto-tls not set to true (Manual)
    0 installs
  22. Cis Ocp V170 2 4 · cyberstrikeus
    Ensure --peer-cert-file and --peer-key-file set (Manual)
    0 installs
  23. Cis Ocp V170 2 5 · cyberstrikeus
    Ensure --peer-client-cert-auth set to true (Manual)
    0 installs
  24. Cis Ocp V170 2 6 · cyberstrikeus
    Ensure --peer-auto-tls not set to true (Manual)
    0 installs
  25. Cis Ocp V170 2 7 · cyberstrikeus
    Ensure unique Certificate Authority used for etcd (Manual)
    0 installs
  26. Cis Ocp V190 2 1 · cyberstrikeus
    Ensure that the --cert-file and --key-file arguments are set as appropriate (Manual)
    0 installs
  27. Cis Ocp V190 2 2 · cyberstrikeus
    Ensure that the --client-cert-auth argument is set to true (Manual)
    0 installs
  28. Cis Ocp V190 2 3 · cyberstrikeus
    Ensure that the --auto-tls argument is not set to true (Manual)
    0 installs
  29. Cis Ocp V190 2 4 · cyberstrikeus
    Ensure that the --peer-cert-file and --peer-key-file arguments are set as appropriate (Manual)
    0 installs
  30. Cis Ocp V190 2 5 · cyberstrikeus
    Ensure that the --peer-client-cert-auth argument is set to true (Manual)
    0 installs
  31. Cis Ocp V190 2 6 · cyberstrikeus
    Ensure that the --peer-auto-tls argument is not set to true (Manual)
    0 installs
  32. Cis Ocp V190 2 7 · cyberstrikeus
    Ensure that a unique Certificate Authority is used for etcd (Manual)
    0 installs
  33. Cis Ocp V180 2 1 · cyberstrikeus
    Ensure --cert-file and --key-file set (Manual)
    0 installs
  34. Cis Ocp V180 2 2 · cyberstrikeus
    Ensure --client-cert-auth set to true (Manual)
    0 installs
  35. Cis Ocp V180 2 3 · cyberstrikeus
    Ensure --auto-tls not set to true (Manual)
    0 installs
  36. Cis Ocp V180 2 4 · cyberstrikeus
    Ensure --peer-cert-file and --peer-key-file set (Manual)
    0 installs
  37. Cis Ocp V180 2 5 · cyberstrikeus
    Ensure --peer-client-cert-auth set to true (Manual)
    2 installs
  38. Cis Ocp V180 2 6 · cyberstrikeus
    Ensure --peer-auto-tls not set to true (Manual)
    0 installs
  39. Cis Ocp V180 2 7 · cyberstrikeus
    Ensure unique Certificate Authority used for etcd (Manual)
    0 installs
  40. Password Management 03 05 07 Password Management · cyberstrikeus
    Maintain a list of commonly-used, expected, or compromised passwords, and update the list [organization-defined] and when organizational passwords ...
    0 installs
  41. Replay Resistant Authentication 03 05 04 Replay Resistant Au · cyberstrikeus
    Replay-Resistant Authentication
    0 installs
  42. Pe 13 2 Suppression Systems Automatic Activation And Notific · cyberstrikeus
    Employ fire suppression systems that activate automatically and notify [organization-defined] and [organization-defined] ;
    0 installs
  43. Pe 5 1 Access To Output By Authorized Individuals · cyberstrikeus
    Access to Output by Authorized Individuals
    0 installs
  44. Sc 18 1 Identify Unacceptable Code And Take Corrective Actio · cyberstrikeus
    Identify [organization-defined] and take [organization-defined].
    0 installs
  45. Sc 23 1 Invalidate Session Identifiers At Logout · cyberstrikeus
    Invalidate session identifiers upon user logout or other session termination.
    0 installs
  46. Sc 49 Hardware Enforced Separation And Policy Enforcement · cyberstrikeus
    Implement hardware-enforced separation and policy enforcement mechanisms between [organization-defined].
    0 installs
  47. Sc 50 Software Enforced Separation And Policy Enforcement · cyberstrikeus
    Implement software-enforced separation and policy enforcement mechanisms between [organization-defined].
    0 installs
  48. Au 2 2 Selection Of Audit Events By Component · cyberstrikeus
    Selection of Audit Events by Component
    0 installs
  49. Au 6 5 Integrated Analysis Of Audit Records · cyberstrikeus
    Integrate analysis of audit records with analysis of [organization-defined] to further enhance the ability to identify inappropriate or unusual activi
    0 installs
  50. Au 6 9 Correlation With Information From Nontechnical Source · cyberstrikeus
    Correlate information from nontechnical sources with audit record information to enhance organization-wide situational awareness.
    0 installs
  51. Au 6 4 Central Review And Analysis · cyberstrikeus
    Provide and implement the capability to centrally review and analyze audit records from multiple components within the system.
    0 installs
  52. Au 8 2 Secondary Authoritative Time Source · cyberstrikeus
    Secondary Authoritative Time Source
    0 installs
  53. Ca 2 2 Specialized Assessments · cyberstrikeus
    Include as part of control assessments, [organization-defined], [organization-defined], [organization-defined].
    0 installs
  54. Ca 3 6 Transfer Authorizations · cyberstrikeus
    Verify that individuals or systems transferring data between interconnecting systems have the requisite authorizations (i.e., write permissions or pri
    0 installs
  55. Cm 3 5 Automated Security Response · cyberstrikeus
    Implement the following security responses automatically if baseline configurations are changed in an unauthorized manner: [organization-defined].
    0 installs
  56. Cm 5 Access Restrictions For Change · cyberstrikeus
    Define, document, approve, and enforce physical and logical access restrictions associated with changes to the system.
    0 installs
  57. Cm 7 5 Authorized Software Allow By Exception · cyberstrikeus
    Identify [organization-defined];
    0 installs
  58. Cm 8 8 Automated Location Tracking · cyberstrikeus
    Support the tracking of system components by geographic location using [organization-defined].
    0 installs
  59. Cp 10 3 Compensating Security Controls · cyberstrikeus
    Addressed through tailoring.
    0 installs
  60. Cp 2 6 Alternate Processing And Storage Sites · cyberstrikeus
    Plan for the transfer of [organization-defined] mission and business functions to alternate processing and/or storage sites with minimal or no loss of
    0 installs
  61. Cp 2 7 Coordinate With External Service Providers · cyberstrikeus
    Coordinate the contingency plan with the contingency plans of external service providers to ensure that contingency requirements can be satisfied.
    0 installs
  62. Cp 6 2 Recovery Time And Recovery Point Objectives · cyberstrikeus
    Configure the alternate storage site to facilitate recovery operations in accordance with recovery time and recovery point objectives.
    0 installs
  63. Cp 9 2 Test Restoration Using Sampling · cyberstrikeus
    Use a sample of backup information in the restoration of selected system functions as part of contingency plan testing.
    0 installs
  64. Ia 1 Policy And Procedures · cyberstrikeus
    Develop, document, and disseminate to [organization-defined]: [organization-defined] identification and authentication policy that: Procedures to faci
    0 installs
  65. Ia 12 2 Identity Evidence · cyberstrikeus
    Require evidence of individual identification be presented to the registration authority.
    0 installs
  66. Ia 3 4 Device Attestation · cyberstrikeus
    Handle device identification and authentication based on attestation by [organization-defined].
    0 installs
  67. Ia 4 Identifier Management · cyberstrikeus
    Manage system identifiers by: Receiving authorization from [organization-defined] to assign an individual, group, role, service, or device identifier;
    0 installs
  68. Ia 4 5 Dynamic Management · cyberstrikeus
    Manage individual identifiers dynamically in accordance with [organization-defined].
    0 installs
  69. Ia 5 18 Password Managers · cyberstrikeus
    Employ [organization-defined] to generate and manage passwords;
    0 installs
  70. Pe 18 1 Facility Site · cyberstrikeus
    Facility Site
    0 installs
  71. Pt 4 1 Tailored Consent · cyberstrikeus
    Provide [organization-defined] to allow individuals to tailor processing permissions to selected elements of personally identifiable information.
    0 installs
  72. Sa 10 7 Security And Privacy Representatives · cyberstrikeus
    Require [organization-defined] to be included in the [organization-defined].
    0 installs
  73. Sa 11 4 Manual Code Reviews · cyberstrikeus
    Require the developer of the system, system component, or system service to perform a manual code review of [organization-defined] using the following
    0 installs
  74. Sa 11 5 Penetration Testing · cyberstrikeus
    Require the developer of the system, system component, or system service to perform penetration testing: At the following level of rigor: [organizatio
    0 installs
  75. Sa 12 9 Operations Security · cyberstrikeus
    Operations Security
    0 installs
  76. Sa 15 12 Minimize Personally Identifiable Information · cyberstrikeus
    Require the developer of the system or system component to minimize the use of personally identifiable information in development and test environment
    0 installs
  77. Sa 17 1 Formal Policy Model · cyberstrikeus
    Require the developer of the system, system component, or system service to: Produce, as an integral part of the development process, a formal policy
    0 installs
  78. Sa 19 Component Authenticity · cyberstrikeus
    Component Authenticity
    0 installs
  79. Sa 2 Allocation Of Resources · cyberstrikeus
    Determine the high-level information security and privacy requirements for the system or system service in mission and business process planning;
    0 installs
  80. Sa 7 User Installed Software · cyberstrikeus
    User-installed Software
    0 installs
  81. Sa 8 28 Acceptable Security · cyberstrikeus
    Implement the security design principle of acceptable security in [organization-defined].
    0 installs
  82. Sc 12 2 Symmetric Keys · cyberstrikeus
    Produce, control, and distribute symmetric cryptographic keys using [organization-defined] key management technology and processes.
    0 installs
  83. Sc 39 Process Isolation · cyberstrikeus
    Maintain a separate execution domain for each executing system process.
    0 installs
  84. Sc 4 1 Security Levels · cyberstrikeus
    Security Levels
    0 installs
  85. Sc 42 2 Authorized Use · cyberstrikeus
    Employ the following measures so that data or information collected by [organization-defined] is only used for authorized purposes: [organization-defi
    0 installs
  86. Sc 48 Sensor Relocation · cyberstrikeus
    Relocate [organization-defined] to [organization-defined] under the following conditions or circumstances: [organization-defined].
    0 installs
  87. Si 12 2 Minimize Personally Identifiable Information In Test · cyberstrikeus
    Use the following techniques to minimize the use of personally identifiable information for research, testing, or training: [organization-defined].
    0 installs
  88. Si 18 1 Automation Support · cyberstrikeus
    Correct or delete personally identifiable information that is inaccurate or outdated, incorrectly determined regarding impact, or incorrectly de-ident
    0 installs
  89. Si 19 8 Motivated Intruder · cyberstrikeus
    Perform a motivated intruder test on the de-identified dataset to determine if the identified data remains or if the de-identified data can be re-iden
    0 installs
  90. Si 2 7 Root Cause Analysis · cyberstrikeus
    Conduct root cause analysis to identify underlying causes of issues or failures.
    0 installs
  91. Si 22 Information Diversity · cyberstrikeus
    Identify the following alternative sources of information for [organization-defined]: [organization-defined] ;
    0 installs
  92. Si 4 4 Inbound And Outbound Communications Traffic · cyberstrikeus
    Determine criteria for unusual or unauthorized activities or conditions for inbound and outbound communications traffic;
    0 installs
  93. Si 4 23 Host Based Devices · cyberstrikeus
    Implement the following host-based monitoring mechanisms at [organization-defined]: [organization-defined].
    0 installs
  94. Si 7 9 Verify Boot Process · cyberstrikeus
    Verify the integrity of the boot process of the following system components: [organization-defined].
    0 installs
  95. Cis Docker 1 1 10 · cyberstrikeus
    Ensure auditing is configured for Docker files and directories - /etc/default/docker
    0 installs
  96. Cis Docker 1 1 11 · cyberstrikeus
    Ensure auditing is configured for Docker files and directories - /etc/docker/daemon.json
    0 installs
  97. Cis Docker 1 1 12 · cyberstrikeus
    Ensure auditing is configured for Docker files and directories - /etc/containerd/config.toml
    0 installs
  98. Cis Docker 1 1 13 · cyberstrikeus
    Ensure auditing is configured for Docker files and directories - /etc/sysconfig/docker
    0 installs
  99. Cis Docker 1 1 14 · cyberstrikeus
    Ensure auditing is configured for Docker files and directories - /usr/bin/containerd
    0 installs
  100. Cis Docker 1 1 15 · cyberstrikeus
    Ensure auditing is configured for Docker files and directories - /usr/bin/containerd-shim
    0 installs