cyberstrikeus
- 7.2k skills
- 0 followers
- 2 days ago last updated
- ▌
- ▌ Pe 4 Access Control For Transmission · cyberstrikeusControl physical access to [organization-defined] within organizational facilities using [organization-defined].
- ▌ Pe 6 4 Monitoring Physical Access To Systems · cyberstrikeusMonitor physical access to the system in addition to the physical access monitoring of the facility at [organization-defined].
- ▌ Pe 8 1 Automated Records Maintenance And Review · cyberstrikeusMaintain and review visitor access records using [organization-defined].
- ▌ Pe 8 3 Limit Personally Identifiable Information Elements · cyberstrikeusLimit personally identifiable information contained in visitor access records to the following elements identified in the privacy risk assessment: [or
- ▌ Pt 7 Specific Categories Of Personally Identifiable Informat · cyberstrikeusApply [organization-defined] for specific categories of personally identifiable information.
- ▌ Sc 12 Cryptographic Key Establishment And Management · cyberstrikeusEstablish and manage cryptographic keys when cryptography is employed within the system in accordance with the following key management requirements:
- ▌ Sc 15 2 Blocking Inbound And Outbound Communications Traffic · cyberstrikeusBlocking Inbound and Outbound Communications Traffic
- ▌ Sc 15 Collaborative Computing Devices And Applications · cyberstrikeusProhibit remote activation of collaborative computing devices and applications with the following exceptions: [organization-defined] ;
- ▌ Sc 30 3 Change Processing And Storage Locations · cyberstrikeusChange the location of [organization-defined] [organization-defined]].
- ▌ Sc 32 1 Separate Physical Domains For Privileged Functions · cyberstrikeusPartition privileged functions into separate physical domains.
- ▌ Sc 39 2 Separate Execution Domain Per Thread · cyberstrikeusMaintain a separate execution domain for each thread in [organization-defined].
- ▌ Sc 40 1 Electromagnetic Interference · cyberstrikeusImplement cryptographic mechanisms that achieve [organization-defined] against the effects of intentional electromagnetic interference.
- ▌ Sc 46 Cross Domain Policy Enforcement · cyberstrikeusImplement a policy enforcement mechanism [organization-defined] between the physical and/or network interfaces for the connecting security domains.
- ▌ Sc 48 1 Dynamic Relocation Of Sensors Or Monitoring Capabili · cyberstrikeusDynamically relocate [organization-defined] to [organization-defined] under the following conditions or circumstances: [organization-defined].
- ▌ Sc 7 8 Route Traffic To Authenticated Proxy Servers · cyberstrikeusRoute [organization-defined] to [organization-defined] through authenticated proxy servers at managed interfaces.
- ▌ Sc 8 Transmission Confidentiality And Integrity · cyberstrikeusProtect the [organization-defined] of transmitted information.
- ▌ Sc 8 5 Protected Distribution System · cyberstrikeusImplement [organization-defined] to [organization-defined] during transmission.
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌ Cis Ocp V190 2 1 · cyberstrikeusEnsure that the --cert-file and --key-file arguments are set as appropriate (Manual)
- ▌ Cis Ocp V190 2 2 · cyberstrikeusEnsure that the --client-cert-auth argument is set to true (Manual)
- ▌
- ▌ Cis Ocp V190 2 4 · cyberstrikeusEnsure that the --peer-cert-file and --peer-key-file arguments are set as appropriate (Manual)
- ▌ Cis Ocp V190 2 5 · cyberstrikeusEnsure that the --peer-client-cert-auth argument is set to true (Manual)
- ▌ Cis Ocp V190 2 6 · cyberstrikeusEnsure that the --peer-auto-tls argument is not set to true (Manual)
- ▌ Cis Ocp V190 2 7 · cyberstrikeusEnsure that a unique Certificate Authority is used for etcd (Manual)
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌ Password Management 03 05 07 Password Management · cyberstrikeusMaintain a list of commonly-used, expected, or compromised passwords, and update the list [organization-defined] and when organizational passwords ...
- ▌ Replay Resistant Authentication 03 05 04 Replay Resistant Au · cyberstrikeusReplay-Resistant Authentication
- ▌ Pe 13 2 Suppression Systems Automatic Activation And Notific · cyberstrikeusEmploy fire suppression systems that activate automatically and notify [organization-defined] and [organization-defined] ;
- ▌ Pe 5 1 Access To Output By Authorized Individuals · cyberstrikeusAccess to Output by Authorized Individuals
- ▌ Sc 18 1 Identify Unacceptable Code And Take Corrective Actio · cyberstrikeusIdentify [organization-defined] and take [organization-defined].
- ▌ Sc 23 1 Invalidate Session Identifiers At Logout · cyberstrikeusInvalidate session identifiers upon user logout or other session termination.
- ▌ Sc 49 Hardware Enforced Separation And Policy Enforcement · cyberstrikeusImplement hardware-enforced separation and policy enforcement mechanisms between [organization-defined].
- ▌ Sc 50 Software Enforced Separation And Policy Enforcement · cyberstrikeusImplement software-enforced separation and policy enforcement mechanisms between [organization-defined].
- ▌ Au 2 2 Selection Of Audit Events By Component · cyberstrikeusSelection of Audit Events by Component
- ▌ Au 6 5 Integrated Analysis Of Audit Records · cyberstrikeusIntegrate analysis of audit records with analysis of [organization-defined] to further enhance the ability to identify inappropriate or unusual activi
- ▌ Au 6 9 Correlation With Information From Nontechnical Source · cyberstrikeusCorrelate information from nontechnical sources with audit record information to enhance organization-wide situational awareness.
- ▌ Au 6 4 Central Review And Analysis · cyberstrikeusProvide and implement the capability to centrally review and analyze audit records from multiple components within the system.
- ▌
- ▌ Ca 2 2 Specialized Assessments · cyberstrikeusInclude as part of control assessments, [organization-defined], [organization-defined], [organization-defined].
- ▌ Ca 3 6 Transfer Authorizations · cyberstrikeusVerify that individuals or systems transferring data between interconnecting systems have the requisite authorizations (i.e., write permissions or pri
- ▌ Cm 3 5 Automated Security Response · cyberstrikeusImplement the following security responses automatically if baseline configurations are changed in an unauthorized manner: [organization-defined].
- ▌ Cm 5 Access Restrictions For Change · cyberstrikeusDefine, document, approve, and enforce physical and logical access restrictions associated with changes to the system.
- ▌
- ▌ Cm 8 8 Automated Location Tracking · cyberstrikeusSupport the tracking of system components by geographic location using [organization-defined].
- ▌
- ▌ Cp 2 6 Alternate Processing And Storage Sites · cyberstrikeusPlan for the transfer of [organization-defined] mission and business functions to alternate processing and/or storage sites with minimal or no loss of
- ▌ Cp 2 7 Coordinate With External Service Providers · cyberstrikeusCoordinate the contingency plan with the contingency plans of external service providers to ensure that contingency requirements can be satisfied.
- ▌ Cp 6 2 Recovery Time And Recovery Point Objectives · cyberstrikeusConfigure the alternate storage site to facilitate recovery operations in accordance with recovery time and recovery point objectives.
- ▌ Cp 9 2 Test Restoration Using Sampling · cyberstrikeusUse a sample of backup information in the restoration of selected system functions as part of contingency plan testing.
- ▌ Ia 1 Policy And Procedures · cyberstrikeusDevelop, document, and disseminate to [organization-defined]: [organization-defined] identification and authentication policy that: Procedures to faci
- ▌ Ia 12 2 Identity Evidence · cyberstrikeusRequire evidence of individual identification be presented to the registration authority.
- ▌ Ia 3 4 Device Attestation · cyberstrikeusHandle device identification and authentication based on attestation by [organization-defined].
- ▌ Ia 4 Identifier Management · cyberstrikeusManage system identifiers by: Receiving authorization from [organization-defined] to assign an individual, group, role, service, or device identifier;
- ▌ Ia 4 5 Dynamic Management · cyberstrikeusManage individual identifiers dynamically in accordance with [organization-defined].
- ▌ Ia 5 18 Password Managers · cyberstrikeusEmploy [organization-defined] to generate and manage passwords;
- ▌
- ▌ Pt 4 1 Tailored Consent · cyberstrikeusProvide [organization-defined] to allow individuals to tailor processing permissions to selected elements of personally identifiable information.
- ▌ Sa 10 7 Security And Privacy Representatives · cyberstrikeusRequire [organization-defined] to be included in the [organization-defined].
- ▌ Sa 11 4 Manual Code Reviews · cyberstrikeusRequire the developer of the system, system component, or system service to perform a manual code review of [organization-defined] using the following
- ▌ Sa 11 5 Penetration Testing · cyberstrikeusRequire the developer of the system, system component, or system service to perform penetration testing: At the following level of rigor: [organizatio
- ▌
- ▌ Sa 15 12 Minimize Personally Identifiable Information · cyberstrikeusRequire the developer of the system or system component to minimize the use of personally identifiable information in development and test environment
- ▌ Sa 17 1 Formal Policy Model · cyberstrikeusRequire the developer of the system, system component, or system service to: Produce, as an integral part of the development process, a formal policy
- ▌
- ▌ Sa 2 Allocation Of Resources · cyberstrikeusDetermine the high-level information security and privacy requirements for the system or system service in mission and business process planning;
- ▌
- ▌ Sa 8 28 Acceptable Security · cyberstrikeusImplement the security design principle of acceptable security in [organization-defined].
- ▌ Sc 12 2 Symmetric Keys · cyberstrikeusProduce, control, and distribute symmetric cryptographic keys using [organization-defined] key management technology and processes.
- ▌ Sc 39 Process Isolation · cyberstrikeusMaintain a separate execution domain for each executing system process.
- ▌
- ▌ Sc 42 2 Authorized Use · cyberstrikeusEmploy the following measures so that data or information collected by [organization-defined] is only used for authorized purposes: [organization-defi
- ▌ Sc 48 Sensor Relocation · cyberstrikeusRelocate [organization-defined] to [organization-defined] under the following conditions or circumstances: [organization-defined].
- ▌ Si 12 2 Minimize Personally Identifiable Information In Test · cyberstrikeusUse the following techniques to minimize the use of personally identifiable information for research, testing, or training: [organization-defined].
- ▌ Si 18 1 Automation Support · cyberstrikeusCorrect or delete personally identifiable information that is inaccurate or outdated, incorrectly determined regarding impact, or incorrectly de-ident
- ▌ Si 19 8 Motivated Intruder · cyberstrikeusPerform a motivated intruder test on the de-identified dataset to determine if the identified data remains or if the de-identified data can be re-iden
- ▌ Si 2 7 Root Cause Analysis · cyberstrikeusConduct root cause analysis to identify underlying causes of issues or failures.
- ▌ Si 22 Information Diversity · cyberstrikeusIdentify the following alternative sources of information for [organization-defined]: [organization-defined] ;
- ▌ Si 4 4 Inbound And Outbound Communications Traffic · cyberstrikeusDetermine criteria for unusual or unauthorized activities or conditions for inbound and outbound communications traffic;
- ▌ Si 4 23 Host Based Devices · cyberstrikeusImplement the following host-based monitoring mechanisms at [organization-defined]: [organization-defined].
- ▌ Si 7 9 Verify Boot Process · cyberstrikeusVerify the integrity of the boot process of the following system components: [organization-defined].
- ▌ Cis Docker 1 1 10 · cyberstrikeusEnsure auditing is configured for Docker files and directories - /etc/default/docker
- ▌ Cis Docker 1 1 11 · cyberstrikeusEnsure auditing is configured for Docker files and directories - /etc/docker/daemon.json
- ▌ Cis Docker 1 1 12 · cyberstrikeusEnsure auditing is configured for Docker files and directories - /etc/containerd/config.toml
- ▌ Cis Docker 1 1 13 · cyberstrikeusEnsure auditing is configured for Docker files and directories - /etc/sysconfig/docker
- ▌ Cis Docker 1 1 14 · cyberstrikeusEnsure auditing is configured for Docker files and directories - /usr/bin/containerd
- ▌ Cis Docker 1 1 15 · cyberstrikeusEnsure auditing is configured for Docker files and directories - /usr/bin/containerd-shim