cyberstrikeus
- 7.2k skills
- 0 followers
- 2 days ago last updated
- ▌ Cis Docker 1 1 16 · cyberstrikeusEnsure auditing is configured for Docker files and directories - /usr/bin/containerd-shim-runc-v1
- ▌ Cis Docker 1 1 17 · cyberstrikeusEnsure auditing is configured for Docker files and directories - /usr/bin/containerd-shim-runc-v2
- ▌ Cis Docker 1 1 18 · cyberstrikeusEnsure auditing is configured for Docker files and directories - /usr/bin/runc
- ▌ Audit Record Review Analysis And Reporting 03 03 05 Audit Re · cyberstrikeusReview and analyze system audit records [organization-defined] for indications and the potential impact of inappropriate or unusual activity.
- ▌ Media Transport 03 08 05 Media Transport · cyberstrikeusProtect and control system media that contain CUI during transport outside of controlled areas.
- ▌ Personnel Screening 03 09 01 Personnel Screening · cyberstrikeusScreen individuals prior to authorizing access to the system.
- ▌ Access Control For Transmission 03 10 08 Access Control For · cyberstrikeusAccess Control for Transmission
- ▌ At 5 Contacts With Security Groups And Associations · cyberstrikeusContacts with Security Groups and Associations
- ▌ Au 3 3 Limit Personally Identifiable Information Elements · cyberstrikeusLimit personally identifiable information contained in audit records to the following elements identified in the privacy risk assessment: [organizatio
- ▌ Au 3 1 Additional Audit Information · cyberstrikeusGenerate audit records containing the following additional information: [organization-defined].
- ▌ Au 9 Protection Of Audit Information · cyberstrikeusProtect audit information and audit logging tools from unauthorized access, modification, and deletion;
- ▌ Ca 3 3 Unclassified Non National Security System Connections · cyberstrikeusUnclassified Non-national Security System Connections
- ▌ Ca 6 1 Joint Authorization Intra Organization · cyberstrikeusEmploy a joint authorization process for the system that includes multiple authorizing officials from the same organization conducting the authorizati
- ▌ Ca 6 2 Joint Authorization Inter Organization · cyberstrikeusEmploy a joint authorization process for the system that includes multiple authorizing officials with at least one authorizing official from an organi
- ▌ Ca 9 Internal System Connections · cyberstrikeusAuthorize internal connections of [organization-defined] to the system;
- ▌
- ▌ Cm 9 1 Assignment Of Responsibility · cyberstrikeusAssign responsibility for developing the configuration management process to organizational personnel that are not directly involved in system develop
- ▌ Cp 10 System Recovery And Reconstitution · cyberstrikeusProvide for the recovery and reconstitution of the system to a known state within [organization-defined] after a disruption, compromise, or failure.
- ▌ Cp 11 Alternate Communications Protocols · cyberstrikeusProvide the capability to employ [organization-defined] in support of maintaining continuity of operations.
- ▌ Cp 4 4 Full Recovery And Reconstitution · cyberstrikeusInclude a full recovery and reconstitution of the system to a known state as part of contingency plan testing.
- ▌ Pe 10 Emergency Shutoff · cyberstrikeusProvide the capability of shutting off power to [organization-defined] in emergency situations;
- ▌ Pe 22 Component Marking · cyberstrikeusMark [organization-defined] indicating the impact level or classification level of the information permitted to be processed, stored, or transmitted b
- ▌ Pe 23 Facility Location · cyberstrikeusPlan the location or site of the facility where the system resides considering physical and environmental hazards;
- ▌ Sa 10 6 Trusted Distribution · cyberstrikeusRequire the developer of the system, system component, or system service to execute procedures for ensuring that security-relevant hardware, software,
- ▌ Sa 11 1 Static Code Analysis · cyberstrikeusRequire the developer of the system, system component, or system service to employ static code analysis tools to identify common flaws and document th
- ▌
- ▌ Sa 12 15 Processes To Address Weaknesses Or Deficiencies · cyberstrikeusProcesses to Address Weaknesses or Deficiencies
- ▌ Sa 15 3 Criticality Analysis · cyberstrikeusRequire the developer of the system, system component, or system service to perform a criticality analysis: At the following decision points in the sy
- ▌ Sa 8 15 Predicate Permission · cyberstrikeusImplement the security design principle of predicate permission in [organization-defined].
- ▌ Sa 8 26 Performance Security · cyberstrikeusImplement the security design principle of performance security in [organization-defined].
- ▌ Sa 9 External System Services · cyberstrikeusRequire that providers of external system services comply with organizational security and privacy requirements and employ the following controls: ...
- ▌ Sc 10 Network Disconnect · cyberstrikeusTerminate the network connection associated with a communications session at the end of the session or after [organization-defined] of inactivity.
- ▌ Sc 12 3 Asymmetric Keys · cyberstrikeusProduce, control, and distribute asymmetric cryptographic keys using [organization-defined].
- ▌ Sc 2 2 Disassociability · cyberstrikeusStore state information from applications and software separately.
- ▌
- ▌ Sc 28 2 Offline Storage · cyberstrikeusRemove the following information from online storage and store offline in a secure location: [organization-defined].
- ▌ Sc 36 2 Synchronization · cyberstrikeusSynchronize the following duplicate systems or system components: [organization-defined].
- ▌ Sc 43 Usage Restrictions · cyberstrikeusEstablish usage restrictions and implementation guidelines for the following system components: [organization-defined] ;
- ▌ Sc 7 Boundary Protection · cyberstrikeusMonitor and control communications at the external managed interfaces to the system and at key internal managed interfaces within the system;
- ▌ Si 10 4 Timing Interactions · cyberstrikeusAccount for timing interactions among system components in determining appropriate responses for invalid inputs.
- ▌ Si 13 5 Failover Capability · cyberstrikeusProvide [organization-defined] [organization-defined] for the system.
- ▌ Si 18 4 Individual Requests · cyberstrikeusCorrect or delete personally identifiable information upon request by individuals or their designated representatives.
- ▌
- ▌ Si 4 15 Wireless To Wireline Communications · cyberstrikeusEmploy an intrusion detection system to monitor wireless communications traffic as the traffic passes from wireless to wireline networks.
- ▌ Si 7 15 Code Authentication · cyberstrikeusImplement cryptographic mechanisms to authenticate the following software or firmware components prior to installation: [organization-defined].
- ▌ Sr 9 1 Multiple Stages Of System Development Life Cycle · cyberstrikeusEmploy anti-tamper technologies, tools, and techniques throughout the system development life cycle.
- ▌
- ▌
- ▌
- ▌ Cis AWS Euc 2 4 · cyberstrikeusEnsure WorkSpaces are deployed in their own virtual private cloud (VPC)
- ▌ Cis AWS Euc 2 5 · cyberstrikeusEnsure WorkSpaces traffic is controlled and routed through a NAT Gateway
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌ Cis AWS Euc 4 3 · cyberstrikeusEnsure Workdocs access is limited to a range of allowable IP addresses
- ▌
- ▌
- ▌
- ▌
- ▌ Cis AWS Euc 4 8 · cyberstrikeusEnsure any user that has not accessed WorkDocs in 30 days is set to inactive
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌ Cis AWS Euc 5 7 · cyberstrikeusEnsure Operating system updates are applied to your base image every 30 days
- ▌
- ▌ Cis Nginx V300 1 2 1 · cyberstrikeusEnsure package manager repositories are properly configured (Manual)
- ▌
- ▌
- ▌ Cis Nginx V300 2 2 1 · cyberstrikeusEnsure that NGINX is run using a non-privileged, dedicated service account (Manual)
- ▌
- ▌
- ▌
- ▌ Cis Nginx V300 2 3 2 · cyberstrikeusEnsure access to NGINX directories and files is restricted (Manual)
- ▌
- ▌ Cis Nginx V300 2 4 1 · cyberstrikeusEnsure NGINX only listens for network connections on authorized ports (Manual)
- ▌
- ▌ Cis Nginx V300 2 4 3 · cyberstrikeusEnsure keepalive_timeout is 10 seconds or less, but not 0 (Manual)
- ▌ Cis Nginx V300 2 4 4 · cyberstrikeusEnsure send_timeout is set to 10 seconds or less, but not 0 (Manual)
- ▌
- ▌ Cis Nginx V300 2 5 2 · cyberstrikeusEnsure default error and index.html pages do not reference NGINX (Manual)
- ▌
- ▌ Cis Nginx V300 2 5 4 · cyberstrikeusEnsure the NGINX reverse proxy does not enable information disclosure (Manual)
- ▌
- ▌ Cis Nginx V300 4 1 2 · cyberstrikeusEnsure a trusted certificate and trust chain is installed (Manual)
- ▌
- ▌
- ▌
- ▌ Cis Nginx V300 4 1 6 · cyberstrikeusEnsure awareness of TLS 1.3 new Diffie-Hellman parameters (Manual)
- ▌ Cis Nginx V300 4 1 7 · cyberstrikeusEnsure Online Certificate Status Protocol (OCSP) stapling is enabled (Manual)
- ▌ Cis Nginx V300 4 1 8 · cyberstrikeusEnsure HTTP Strict Transport Security (HSTS) is enabled (Manual)
- ▌ Cis Nginx V300 4 1 9 · cyberstrikeusEnsure upstream server traffic is authenticated with a client certificate (Manual)
- ▌ Cis Nginx V300 5 1 1 · cyberstrikeusEnsure allow and deny filters limit access to specific IP addresses (Manual)
- ▌