cyberstrikeus
- 7.2k skills
- 0 followers
- 2 days ago last updated
- ▌ Cis Nginx V300 5 2 1 · cyberstrikeusEnsure timeout values for reading the client header and body are set correctly (Manual)
- ▌
- ▌
- ▌ Cis Nginx V300 5 2 4 · cyberstrikeusEnsure the number of connections per IP address is limited (Manual)
- ▌
- ▌ Cis Nginx V300 5 3 1 · cyberstrikeusEnsure X-Content-Type-Options header is configured and enabled (Manual)
- ▌ Cis Nginx V300 5 3 2 · cyberstrikeusEnsure that Content Security Policy (CSP) is enabled and configured properly (Manual)
- ▌ Cis Nginx V300 5 3 3 · cyberstrikeusEnsure the Referrer Policy is enabled and configured properly (Manual)
- ▌ T1481 002 Bidirectional Communication · cyberstrikeusAdversaries may use an existing, legitimate external Web service channel as a means for sending commands to and receiving output from a compromised system.
- ▌ Audit Record Reduction And Report Generation 03 03 06 Audit · cyberstrikeusImplement an audit record reduction and report generation capability that supports audit record review, analysis, reporting requirements, and after...
- ▌ Response To Audit Logging Process Failures 03 03 04 Response · cyberstrikeusAlert organizational personnel or roles within [organization-defined] in the event of an audit logging process failure.
- ▌ Alternate Work Site 03 10 06 Alternate Work Site · cyberstrikeusDetermine alternate work sites allowed for use by employees.
- ▌ Define And Use Criteria For Software Security Checks Po 4 De · cyberstrikeusHelp ensure that the software resulting from the SDLC meets the organization’s expectations by defining and using criteria for checking the software’s
- ▌ Implement Supporting Toolchains Po 3 Implement Supporting To · cyberstrikeusUse automation to reduce human effort and improve the accuracy, reproducibility, usability, and comprehensiveness of security practices throughout ...
- ▌ Au 14 3 Remote Viewing And Listening · cyberstrikeusProvide and implement the capability for authorized users to remotely view and hear content related to an established user session in real time.
- ▌ Au 16 2 Sharing Of Audit Information · cyberstrikeusProvide cross-organizational audit information to [organization-defined] based on [organization-defined].
- ▌ Au 4 1 Transfer To Alternate Storage · cyberstrikeusTransfer audit logs [organization-defined] to a different system, system component, or media other than the system or system component conducting the
- ▌ Au 6 Audit Record Review Analysis And Reporting · cyberstrikeusReview and analyze system audit records [organization-defined] for indications of [organization-defined] and the potential impact of the inappropri...
- ▌ Au 6 1 Automated Process Integration · cyberstrikeusIntegrate audit record review, analysis, and reporting processes using [organization-defined].
- ▌ Au 9 4 Access By Subset Of Privileged Users · cyberstrikeusAuthorize access to management of audit logging functionality to only [organization-defined].
- ▌
- ▌ Ia 13 Identity Providers And Authorization Servers · cyberstrikeusEmploy identity providers and authorization servers to manage user, device, and non-person entity (NPE) identities, attributes, and access rights supp
- ▌ Ia 4 4 Identify User Status · cyberstrikeusManage individual identifiers by uniquely identifying each individual as [organization-defined].
- ▌
- ▌ Ia 5 13 Expiration Of Cached Authenticators · cyberstrikeusProhibit the use of cached authenticators after [organization-defined].
- ▌ Ia 6 Authentication Feedback · cyberstrikeusObscure feedback of authentication information during the authentication process to protect the information from possible exploitation and use by unau
- ▌
- ▌ Pe 12 Emergency Lighting · cyberstrikeusEmploy and maintain automatic emergency lighting for the system that activates in the event of a power outage or disruption and that covers emergency
- ▌ Pe 3 4 Lockable Casings · cyberstrikeusUse lockable physical casings to protect [organization-defined] from unauthorized physical access.
- ▌ Pt 1 Policy And Procedures · cyberstrikeusDevelop, document, and disseminate to [organization-defined]: [organization-defined] personally identifiable information processing and transparency p
- ▌ Sa 11 8 Dynamic Code Analysis · cyberstrikeusRequire the developer of the system, system component, or system service to employ dynamic code analysis tools to identify common flaws and document t
- ▌ Sa 17 3 Formal Correspondence · cyberstrikeusRequire the developer of the system, system component, or system service to: Produce, as an integral part of the development process, a formal top-lev
- ▌ Sa 17 6 Structure For Testing · cyberstrikeusRequire the developer of the system, system component, or system service to structure security-relevant hardware, software, and firmware to facilitate
- ▌ Sa 8 19 Continuous Protection · cyberstrikeusImplement the security design principle of continuous protection in [organization-defined].
- ▌ Sa 8 2 Least Common Mechanism · cyberstrikeusImplement the security design principle of least common mechanism in [organization-defined].
- ▌ Sa 9 4 Consistent Interests Of Consumers And Providers · cyberstrikeusTake the following actions to verify that the interests of [organization-defined] are consistent with and reflect organizational interests: [organizat
- ▌ Sa 9 6 Organization Controlled Cryptographic Keys · cyberstrikeusMaintain exclusive control of cryptographic keys for encrypted material stored or transmitted through an external system.
- ▌ Sa 9 7 Organization Controlled Integrity Checking · cyberstrikeusProvide the capability to check the integrity of information while it resides in the external system.
- ▌
- ▌ Sc 24 Fail In Known State · cyberstrikeusFail to a [organization-defined] for the following failures on the indicated components while preserving [organization-defined] in failure: [organizat
- ▌ Sc 32 System Partitioning · cyberstrikeusPartition the system into [organization-defined] residing in separate [organization-defined] domains or environments based on [organization-defined].
- ▌ Sc 38 Operations Security · cyberstrikeusEmploy the following operations security controls to protect key organizational information throughout the system development life cycle: [organizatio
- ▌ Sc 44 Detonation Chambers · cyberstrikeusEmploy a detonation chamber capability within [organization-defined].
- ▌ Sc 7 11 Restrict Incoming Communications Traffic · cyberstrikeusOnly allow incoming communications from [organization-defined] to be routed to [organization-defined].
- ▌ Si 10 3 Predictable Behavior · cyberstrikeusVerify that the system behaves in a predictable and documented manner when invalid inputs are received.
- ▌
- ▌ Si 12 3 Information Disposal · cyberstrikeusUse the following techniques to dispose of, destroy, or erase information following the retention period: [organization-defined].
- ▌
- ▌ Cm 3 2 Testing Validation And Documentation Of Changes · cyberstrikeusTest, validate, and document changes to the system before finalizing the implementation of the changes.
- ▌ Cm 3 7 Review System Changes · cyberstrikeusReview changes to the system [organization-defined] or when [organization-defined] to determine whether unauthorized changes have occurred.
- ▌
- ▌ Cm 7 9 Prohibiting The Use Of Unauthorized Hardware · cyberstrikeusIdentify [organization-defined];
- ▌ Cm 8 2 Automated Maintenance · cyberstrikeusMaintain the currency, completeness, accuracy, and availability of the inventory of system components using [organization-defined].
- ▌
- ▌ Cp 4 2 Alternate Processing Site · cyberstrikeusTest the contingency plan at the alternate processing site: To familiarize contingency personnel with the facility and available resources; and To eva
- ▌ Cp 8 4 Provider Contingency Plan · cyberstrikeusRequire primary and alternate telecommunications service providers to have contingency plans;
- ▌ Ir 4 11 Integrated Incident Response Team · cyberstrikeusEstablish and maintain an integrated incident response team that can be deployed to any location identified by the organization in [organization-defin
- ▌ Pm 16 1 Automated Means For Sharing Threat Intelligence · cyberstrikeusEmploy automated mechanisms to maximize the effectiveness of sharing threat intelligence information.
- ▌ Pt 2 2 Automation · cyberstrikeusManage enforcement of the authorized processing of personally identifiable information using [organization-defined].
- ▌ Pt 3 2 Automation · cyberstrikeusTrack processing purposes of personally identifiable information using [organization-defined].
- ▌ Pt 4 3 Revocation · cyberstrikeusImplement [organization-defined] for individuals to revoke consent to the processing of their personally identifiable information.
- ▌ Ra 3 2 Use Of All Source Intelligence · cyberstrikeusUse all-source intelligence to assist in the analysis of risk.
- ▌ Sa 17 8 Orchestration · cyberstrikeusDesign [organization-defined] with coordinated behavior to implement the following capabilities: [organization-defined].
- ▌ Sa 8 21 Self Analysis · cyberstrikeusImplement the security design principle of self-analysis in [organization-defined].
- ▌ Sc 18 Mobile Code · cyberstrikeusDefine acceptable and unacceptable mobile code and mobile code technologies;
- ▌ Si 14 Non Persistence · cyberstrikeusImplement non-persistent [organization-defined] that are initiated in a known state and terminated [organization-defined].
- ▌
- ▌ T0803 Block Command Message · cyberstrikeusAdversaries may block a command message from reaching its intended target to prevent command execution.
- ▌ T0838 Modify Alarm Settings · cyberstrikeusAdversaries may modify alarm settings to prevent alerts that may inform operators of their presence or to prevent responses to dangerous and unintended scenarios.
- ▌ T0890 Exploitation For Privilege Escalation · cyberstrikeusAdversaries may exploit software vulnerabilities in an attempt to elevate privileges.
- ▌ T1458 Replication Through Removable Media · cyberstrikeusAdversaries may move onto devices by exploiting or copying malware to devices connected via USB.
- ▌ T1625 001 System Runtime API Hijacking · cyberstrikeusAdversaries may execute their own malicious payloads by hijacking the way an operating system runs applications.
- ▌ T1407 Download New Code At Runtime · cyberstrikeusAdversaries may download and execute dynamic code not included in the original application package after installation.
- ▌ T1628 003 Conceal Multimedia Files · cyberstrikeusAdversaries may attempt to hide multimedia files from the user.
- ▌ T1655 001 Match Legitimate Name Or Location · cyberstrikeusAdversaries may match or approximate the name or location of legitimate files or resources when naming/placing them.
- ▌ T1555 003 Credentials From Web Browsers · cyberstrikeusAdversaries may acquire credentials from web browsers by reading files specific to the target browser.
- ▌ T1556 004 Network Device Authentication · cyberstrikeusAdversaries may use Patch System Image to hard code a password in the operating system, thus bypassing of native authentication mechanisms for local accounts on network devices.
- ▌ T1557 001 Llmnrnbt Ns Poisoning And Smb Relay · cyberstrikeusBy responding to LLMNR/NBT-NS network traffic, adversaries may spoof an authoritative source for name resolution to force communication with an adversary controlled system.
- ▌ T1092 Communication Through Removable Media · cyberstrikeusAdversaries can perform command and control between compromised hosts on potentially disconnected networks using removable media to transfer commands from system to system.
- ▌ T1102 002 Bidirectional Communication · cyberstrikeusAdversaries may use an existing, legitimate external Web service as a means for sending commands to and receiving output from a compromised system over the Web service channel.
- ▌ Publicly Accessible Content 03 01 22 Publicly Accessible Con · cyberstrikeusTrain authorized individuals to ensure that publicly accessible information does not contain CUI.
- ▌
- ▌ Unsuccessful Logon Attempts 03 01 08 Unsuccessful Logon Atte · cyberstrikeusEnforce a limit of [organization-defined] consecutive invalid logon attempts by a user during a [organization-defined].
- ▌
- ▌
- ▌
- ▌ Incident Monitoring Reporting And Response Assistance 03 06 · cyberstrikeusTrack and document system security incidents.
- ▌ Implement And Maintain Secure Environments For Software Deve · cyberstrikeusEnsure that all components of the environments for software development are strongly protected from internal and external threats to prevent compro...
- ▌ Ac 18 4 Restrict Configurations By Users · cyberstrikeusIdentify and explicitly authorize users allowed to independently configure wireless networking capabilities.
- ▌ Ac 21 2 Information Search And Retrieval · cyberstrikeusImplement information search and retrieval services that enforce [organization-defined].
- ▌
- ▌ At 2 6 Cyber Threat Environment · cyberstrikeusProvide literacy training on the cyber threat environment;
- ▌ Au 16 1 Identity Preservation · cyberstrikeusPreserve the identity of individuals in cross-organizational audit trails.
- ▌ Au 5 5 Alternate Audit Logging Capability · cyberstrikeusProvide an alternate audit logging capability in the event of a failure in primary audit logging capability that implements [organization-defined].
- ▌ Au 9 7 Store On Component With Different Operating System · cyberstrikeusStore audit information on a component running a different operating system than the system or component being audited.
- ▌ Ca 1 Policy And Procedures · cyberstrikeusDevelop, document, and disseminate to [organization-defined]: [organization-defined] assessment, authorization, and monitoring policy that: Procedures
- ▌ Ca 7 Continuous Monitoring · cyberstrikeusDevelop a system-level continuous monitoring strategy and implement continuous monitoring in accordance with the organization-level continuous monitor
- ▌ Ca 8 2 Red Team Exercises · cyberstrikeusEmploy the following red-team exercises to simulate attempts by adversaries to compromise organizational systems in accordance with applicable rules o
- ▌ Cm 3 1 Automated Documentation Notification And Prohibition · cyberstrikeusUse [organization-defined] to: Document proposed changes to the system; Notify [organization-defined] of proposed changes to the system and request ch
- ▌ Cm 8 7 Centralized Repository · cyberstrikeusProvide a centralized repository for the inventory of system components.