← all publishers

cyberstrikeus

@cyberstrikeus source repo

7171 published skills · page 50 of 72

  1. Cis Docker 1 1 16 · cyberstrikeus
    Ensure auditing is configured for Docker files and directories - /usr/bin/containerd-shim-runc-v1
    0 installs
  2. Cis Docker 1 1 17 · cyberstrikeus
    Ensure auditing is configured for Docker files and directories - /usr/bin/containerd-shim-runc-v2
    0 installs
  3. Cis Docker 1 1 18 · cyberstrikeus
    Ensure auditing is configured for Docker files and directories - /usr/bin/runc
    0 installs
  4. Audit Record Review Analysis And Reporting 03 03 05 Audit Re · cyberstrikeus
    Review and analyze system audit records [organization-defined] for indications and the potential impact of inappropriate or unusual activity.
    0 installs
  5. Media Transport 03 08 05 Media Transport · cyberstrikeus
    Protect and control system media that contain CUI during transport outside of controlled areas.
    0 installs
  6. Personnel Screening 03 09 01 Personnel Screening · cyberstrikeus
    Screen individuals prior to authorizing access to the system.
    0 installs
  7. Access Control For Transmission 03 10 08 Access Control For · cyberstrikeus
    Access Control for Transmission
    0 installs
  8. At 5 Contacts With Security Groups And Associations · cyberstrikeus
    Contacts with Security Groups and Associations
    0 installs
  9. Au 3 3 Limit Personally Identifiable Information Elements · cyberstrikeus
    Limit personally identifiable information contained in audit records to the following elements identified in the privacy risk assessment: [organizatio
    0 installs
  10. Au 3 1 Additional Audit Information · cyberstrikeus
    Generate audit records containing the following additional information: [organization-defined].
    0 installs
  11. Au 9 Protection Of Audit Information · cyberstrikeus
    Protect audit information and audit logging tools from unauthorized access, modification, and deletion;
    0 installs
  12. Ca 3 3 Unclassified Non National Security System Connections · cyberstrikeus
    Unclassified Non-national Security System Connections
    0 installs
  13. Ca 6 1 Joint Authorization Intra Organization · cyberstrikeus
    Employ a joint authorization process for the system that includes multiple authorizing officials from the same organization conducting the authorizati
    0 installs
  14. Ca 6 2 Joint Authorization Inter Organization · cyberstrikeus
    Employ a joint authorization process for the system that includes multiple authorizing officials with at least one authorizing official from an organi
    0 installs
  15. Ca 9 Internal System Connections · cyberstrikeus
    Authorize internal connections of [organization-defined] to the system;
    0 installs
  16. Cm 7 4 Unauthorized Software Deny By Exception · cyberstrikeus
    Identify [organization-defined];
    0 installs
  17. Cm 9 1 Assignment Of Responsibility · cyberstrikeus
    Assign responsibility for developing the configuration management process to organizational personnel that are not directly involved in system develop
    0 installs
  18. Cp 10 System Recovery And Reconstitution · cyberstrikeus
    Provide for the recovery and reconstitution of the system to a known state within [organization-defined] after a disruption, compromise, or failure.
    0 installs
  19. Cp 11 Alternate Communications Protocols · cyberstrikeus
    Provide the capability to employ [organization-defined] in support of maintaining continuity of operations.
    0 installs
  20. Cp 4 4 Full Recovery And Reconstitution · cyberstrikeus
    Include a full recovery and reconstitution of the system to a known state as part of contingency plan testing.
    0 installs
  21. Pe 10 Emergency Shutoff · cyberstrikeus
    Provide the capability of shutting off power to [organization-defined] in emergency situations;
    0 installs
  22. Pe 22 Component Marking · cyberstrikeus
    Mark [organization-defined] indicating the impact level or classification level of the information permitted to be processed, stored, or transmitted b
    0 installs
  23. Pe 23 Facility Location · cyberstrikeus
    Plan the location or site of the facility where the system resides considering physical and environmental hazards;
    0 installs
  24. Sa 10 6 Trusted Distribution · cyberstrikeus
    Require the developer of the system, system component, or system service to execute procedures for ensuring that security-relevant hardware, software,
    0 installs
  25. Sa 11 1 Static Code Analysis · cyberstrikeus
    Require the developer of the system, system component, or system service to employ static code analysis tools to identify common flaws and document th
    0 installs
  26. Sa 12 Supply Chain Protection · cyberstrikeus
    Supply Chain Protection
    0 installs
  27. Sa 12 15 Processes To Address Weaknesses Or Deficiencies · cyberstrikeus
    Processes to Address Weaknesses or Deficiencies
    0 installs
  28. Sa 15 3 Criticality Analysis · cyberstrikeus
    Require the developer of the system, system component, or system service to perform a criticality analysis: At the following decision points in the sy
    0 installs
  29. Sa 8 15 Predicate Permission · cyberstrikeus
    Implement the security design principle of predicate permission in [organization-defined].
    0 installs
  30. Sa 8 26 Performance Security · cyberstrikeus
    Implement the security design principle of performance security in [organization-defined].
    0 installs
  31. Sa 9 External System Services · cyberstrikeus
    Require that providers of external system services comply with organizational security and privacy requirements and employ the following controls: ...
    0 installs
  32. Sc 10 Network Disconnect · cyberstrikeus
    Terminate the network connection associated with a communications session at the end of the session or after [organization-defined] of inactivity.
    0 installs
  33. Sc 12 3 Asymmetric Keys · cyberstrikeus
    Produce, control, and distribute asymmetric cryptographic keys using [organization-defined].
    0 installs
  34. Sc 2 2 Disassociability · cyberstrikeus
    Store state information from applications and software separately.
    0 installs
  35. Sc 20 1 Child Subspaces · cyberstrikeus
    Child Subspaces
    0 installs
  36. Sc 28 2 Offline Storage · cyberstrikeus
    Remove the following information from online storage and store offline in a secure location: [organization-defined].
    0 installs
  37. Sc 36 2 Synchronization · cyberstrikeus
    Synchronize the following duplicate systems or system components: [organization-defined].
    0 installs
  38. Sc 43 Usage Restrictions · cyberstrikeus
    Establish usage restrictions and implementation guidelines for the following system components: [organization-defined] ;
    0 installs
  39. Sc 7 Boundary Protection · cyberstrikeus
    Monitor and control communications at the external managed interfaces to the system and at key internal managed interfaces within the system;
    0 installs
  40. Si 10 4 Timing Interactions · cyberstrikeus
    Account for timing interactions among system components in determining appropriate responses for invalid inputs.
    0 installs
  41. Si 13 5 Failover Capability · cyberstrikeus
    Provide [organization-defined] [organization-defined] for the system.
    0 installs
  42. Si 18 4 Individual Requests · cyberstrikeus
    Correct or delete personally identifiable information upon request by individuals or their designated representatives.
    0 installs
  43. Si 3 3 Non Privileged Users · cyberstrikeus
    Non-privileged Users
    0 installs
  44. Si 4 15 Wireless To Wireline Communications · cyberstrikeus
    Employ an intrusion detection system to monitor wireless communications traffic as the traffic passes from wireless to wireline networks.
    0 installs
  45. Si 7 15 Code Authentication · cyberstrikeus
    Implement cryptographic mechanisms to authenticate the following software or firmware components prior to installation: [organization-defined].
    0 installs
  46. Sr 9 1 Multiple Stages Of System Development Life Cycle · cyberstrikeus
    Employ anti-tamper technologies, tools, and techniques throughout the system development life cycle.
    0 installs
  47. Cis AWS Euc 2 1 · cyberstrikeus
    Ensure Administration of WorkSpaces is defined using IAM
    0 installs
  48. Cis AWS Euc 2 2 · cyberstrikeus
    Ensure MFA is enabled for WorkSpaces users
    0 installs
  49. Cis AWS Euc 2 3 · cyberstrikeus
    Ensure WorkSpace volumes are encrypted
    0 installs
  50. Cis AWS Euc 2 4 · cyberstrikeus
    Ensure WorkSpaces are deployed in their own virtual private cloud (VPC)
    0 installs
  51. Cis AWS Euc 2 5 · cyberstrikeus
    Ensure WorkSpaces traffic is controlled and routed through a NAT Gateway
    0 installs
  52. Cis AWS Euc 2 6 · cyberstrikeus
    Ensure Web Access to Workspaces is Disabled
    0 installs
  53. Cis AWS Euc 2 7 · cyberstrikeus
    Ensure access is limited to trusted devices
    0 installs
  54. Cis AWS Euc 2 8 · cyberstrikeus
    Ensure the default IP access control group is disassociated
    0 installs
  55. Cis AWS Euc 2 9 · cyberstrikeus
    Ensure CloudWatch is set up for WorkSpaces
    0 installs
  56. Cis AWS Euc 3 1 · cyberstrikeus
    Ensure User Access Logging is enabled
    0 installs
  57. Cis AWS Euc 4 1 · cyberstrikeus
    Ensure Administrators of WorkDocs is defined using IAM
    0 installs
  58. Cis AWS Euc 4 2 · cyberstrikeus
    Ensure MFA is enabled for WorkDoc users
    0 installs
  59. Cis AWS Euc 4 3 · cyberstrikeus
    Ensure Workdocs access is limited to a range of allowable IP addresses
    0 installs
  60. Cis AWS Euc 4 4 · cyberstrikeus
    Utilize site wide activity feed for monitoring
    0 installs
  61. Cis AWS Euc 4 5 · cyberstrikeus
    Ensure new users can only be invited from allowed domains
    0 installs
  62. Cis AWS Euc 4 6 · cyberstrikeus
    Ensure only specific users are allowed to invite external users
    0 installs
  63. Cis AWS Euc 4 7 · cyberstrikeus
    Ensure publicly shareable links is not allowed in WorkDocs
    0 installs
  64. Cis AWS Euc 4 8 · cyberstrikeus
    Ensure any user that has not accessed WorkDocs in 30 days is set to inactive
    0 installs
  65. Cis AWS Euc 5 1 · cyberstrikeus
    Ensure AppStream is utilizing its own virtual private cloud (VPC)
    0 installs
  66. Cis AWS Euc 5 2 · cyberstrikeus
    Ensure a VPC Endpoint is set for AppStream
    0 installs
  67. Cis AWS Euc 5 3 · cyberstrikeus
    Ensure maximum session duration is no longer than 10 hours
    0 installs
  68. Cis AWS Euc 5 4 · cyberstrikeus
    Ensure session disconnect timeout is set to 5 minutes or less
    0 installs
  69. Cis AWS Euc 5 5 · cyberstrikeus
    Ensure session Idle disconnect timeout is set to 10 minutes or less
    0 installs
  70. Cis AWS Euc 5 6 · cyberstrikeus
    Ensure internet access is granted and managed through your VPC
    0 installs
  71. Cis AWS Euc 5 7 · cyberstrikeus
    Ensure Operating system updates are applied to your base image every 30 days
    0 installs
  72. Cis Nginx V300 1 1 1 · cyberstrikeus
    Ensure NGINX is installed (Manual)
    0 installs
  73. Cis Nginx V300 1 2 1 · cyberstrikeus
    Ensure package manager repositories are properly configured (Manual)
    0 installs
  74. Cis Nginx V300 1 2 2 · cyberstrikeus
    Ensure the latest software package is installed (Manual)
    0 installs
  75. Cis Nginx V300 2 1 1 · cyberstrikeus
    Ensure only required dynamic modules are loaded (Manual)
    0 installs
  76. Cis Nginx V300 2 2 1 · cyberstrikeus
    Ensure that NGINX is run using a non-privileged, dedicated service account (Manual)
    0 installs
  77. Cis Nginx V300 2 2 2 · cyberstrikeus
    Ensure the NGINX service account is locked (Manual)
    0 installs
  78. Cis Nginx V300 2 2 3 · cyberstrikeus
    Ensure the NGINX service account has an invalid shell (Manual)
    0 installs
  79. Cis Nginx V300 2 3 1 · cyberstrikeus
    Ensure NGINX directories and files are owned by root (Manual)
    0 installs
  80. Cis Nginx V300 2 3 2 · cyberstrikeus
    Ensure access to NGINX directories and files is restricted (Manual)
    0 installs
  81. Cis Nginx V300 2 3 3 · cyberstrikeus
    Ensure the NGINX process ID (PID) file is secured (Manual)
    0 installs
  82. Cis Nginx V300 2 4 1 · cyberstrikeus
    Ensure NGINX only listens for network connections on authorized ports (Manual)
    0 installs
  83. Cis Nginx V300 2 4 2 · cyberstrikeus
    Ensure requests for unknown host names are rejected (Manual)
    0 installs
  84. Cis Nginx V300 2 4 3 · cyberstrikeus
    Ensure keepalive_timeout is 10 seconds or less, but not 0 (Manual)
    0 installs
  85. Cis Nginx V300 2 4 4 · cyberstrikeus
    Ensure send_timeout is set to 10 seconds or less, but not 0 (Manual)
    0 installs
  86. Cis Nginx V300 2 5 1 · cyberstrikeus
    Ensure server_tokens directive is set to off (Manual)
    0 installs
  87. Cis Nginx V300 2 5 2 · cyberstrikeus
    Ensure default error and index.html pages do not reference NGINX (Manual)
    0 installs
  88. Cis Nginx V300 2 5 3 · cyberstrikeus
    Ensure hidden file serving is disabled (Manual)
    0 installs
  89. Cis Nginx V300 2 5 4 · cyberstrikeus
    Ensure the NGINX reverse proxy does not enable information disclosure (Manual)
    0 installs
  90. Cis Nginx V300 4 1 1 · cyberstrikeus
    Ensure HTTP is redirected to HTTPS (Manual)
    0 installs
  91. Cis Nginx V300 4 1 2 · cyberstrikeus
    Ensure a trusted certificate and trust chain is installed (Manual)
    0 installs
  92. Cis Nginx V300 4 1 3 · cyberstrikeus
    Ensure private key permissions are restricted (Manual)
    0 installs
  93. Cis Nginx V300 4 1 4 · cyberstrikeus
    Ensure only modern TLS protocols are used (Manual)
    0 installs
  94. Cis Nginx V300 4 1 5 · cyberstrikeus
    Disable weak ciphers (Manual)
    0 installs
  95. Cis Nginx V300 4 1 6 · cyberstrikeus
    Ensure awareness of TLS 1.3 new Diffie-Hellman parameters (Manual)
    0 installs
  96. Cis Nginx V300 4 1 7 · cyberstrikeus
    Ensure Online Certificate Status Protocol (OCSP) stapling is enabled (Manual)
    0 installs
  97. Cis Nginx V300 4 1 8 · cyberstrikeus
    Ensure HTTP Strict Transport Security (HSTS) is enabled (Manual)
    0 installs
  98. Cis Nginx V300 4 1 9 · cyberstrikeus
    Ensure upstream server traffic is authenticated with a client certificate (Manual)
    0 installs
  99. Cis Nginx V300 5 1 1 · cyberstrikeus
    Ensure allow and deny filters limit access to specific IP addresses (Manual)
    0 installs
  100. Cis Nginx V300 5 1 2 · cyberstrikeus
    Ensure only approved HTTP methods are allowed (Manual)
    0 installs