← all publishers

cyberstrikeus

@cyberstrikeus source repo

7171 published skills · page 52 of 72

  1. Cp 2 3 Resume Mission And Business Functions · cyberstrikeus
    Plan for the resumption of [organization-defined] mission and business functions within [organization-defined] of contingency plan activation.
    0 installs
  2. Cp 3 2 Mechanisms Used In Training Environments · cyberstrikeus
    Employ mechanisms used in operations to provide a more thorough and realistic contingency training environment.
    0 installs
  3. Cp 8 5 Alternate Telecommunication Service Testing · cyberstrikeus
    Test alternate telecommunication services [organization-defined].
    0 installs
  4. Cp 9 1 Testing For Reliability And Integrity · cyberstrikeus
    Test backup information [organization-defined] to verify media reliability and information integrity.
    0 installs
  5. Cp 9 6 Redundant Secondary System · cyberstrikeus
    Conduct system backup by maintaining a redundant secondary system that is not collocated with the primary system and that can be activated without los
    0 installs
  6. Ir 10 Integrated Information Security Analysis Team · cyberstrikeus
    Integrated Information Security Analysis Team
    0 installs
  7. Ir 4 5 Automatic Disabling Of System · cyberstrikeus
    Implement a configurable capability to automatically disable the system if [organization-defined] are detected.
    0 installs
  8. Pm 13 Security And Privacy Workforce · cyberstrikeus
    Establish a security and privacy workforce development and improvement program.
    0 installs
  9. Pm 20 1 Privacy Policies On Websites Applications And Digita · cyberstrikeus
    Develop and post privacy policies on all external-facing websites, mobile applications, and other digital services, that: Are written in plain languag
    0 installs
  10. Pm 31 Continuous Monitoring Strategy · cyberstrikeus
    Develop an organization-wide continuous monitoring strategy and implement continuous monitoring programs that include: Establishing the following orga
    0 installs
  11. Ps 3 3 Information Requiring Special Protective Measures · cyberstrikeus
    Verify that individuals accessing a system processing, storing, or transmitting information requiring special protection: Have valid access authorizat
    0 installs
  12. Ps 4 1 Post Employment Requirements · cyberstrikeus
    Notify terminated individuals of applicable, legally binding post-employment requirements for the protection of organizational information;
    0 installs
  13. Ps 6 1 Information Requiring Special Protection · cyberstrikeus
    Information Requiring Special Protection
    0 installs
  14. Ps 6 3 Post Employment Requirements · cyberstrikeus
    Notify individuals of applicable, legally binding post-employment requirements for protection of organizational information;
    0 installs
  15. Pt 5 Privacy Notice · cyberstrikeus
    Provide notice to individuals about the processing of personally identifiable information that: Is available to individuals upon first interacting wit
    0 installs
  16. Ra 5 10 Correlate Scanning Information · cyberstrikeus
    Correlate the output from vulnerability scanning tools to determine the presence of multi-vulnerability and multi-hop attack vectors.
    0 installs
  17. Sa 4 12 Data Ownership · cyberstrikeus
    Include organizational data ownership requirements in the acquisition contract;
    0 installs
  18. Sc 11 Trusted Path · cyberstrikeus
    Provide a [organization-defined] isolated trusted communications path for communications between the user and the trusted components of the system;
    0 installs
  19. Si 4 System Monitoring · cyberstrikeus
    Monitor the system to detect: Attacks and indicators of potential attacks in accordance with the following monitoring objectives: [organization-define
    0 installs
  20. Sr 1 Policy And Procedures · cyberstrikeus
    Develop, document, and disseminate to [organization-defined]: [organization-defined] supply chain risk management policy that: Procedures to facilitat
    0 installs
  21. Sr 3 2 Limitation Of Harm · cyberstrikeus
    Employ the following controls to limit harm from potential adversaries identifying and targeting the organizational supply chain: [organization-define
    0 installs
  22. Sr 3 3 Sub Tier Flow Down · cyberstrikeus
    Ensure that the controls included in the contracts of prime contractors are also included in the contracts of subcontractors.
    0 installs
  23. T0816 Device Restartshutdown · cyberstrikeus
    Adversaries may forcibly restart or shutdown a device in an ICS environment to disrupt and potentially negatively impact physical processes.
    0 installs
  24. T0819 Exploit Public Facing Application · cyberstrikeus
    Adversaries may leverage weaknesses to exploit internet-facing software for initial access into an industrial network.
    0 installs
  25. T1474 002 Compromise Hardware Supply Chain · cyberstrikeus
    Adversaries may manipulate hardware components in products prior to receipt by a final consumer for the purpose of data or system compromise.
    0 installs
  26. T1474 003 Compromise Software Supply Chain · cyberstrikeus
    Adversaries may manipulate application software prior to receipt by a final consumer for the purpose of data or system compromise.
    0 installs
  27. T1577 Compromise Application Executable · cyberstrikeus
    Adversaries may modify applications installed on a device to establish persistent access to a victim.
    0 installs
  28. T1645 Compromise Client Software Binary · cyberstrikeus
    Adversaries may modify system software binaries to establish persistent access to devices.
    0 installs
  29. T1626 001 Device Administrator Permissions · cyberstrikeus
    Adversaries may abuse Android’s device administration API to obtain a higher degree of control over the device.
    0 installs
  30. T1628 001 Suppress Application Icon · cyberstrikeus
    A malicious application could suppress its icon from being displayed to the user in the application launcher.
    0 installs
  31. T1633 Virtualizationsandbox Evasion · cyberstrikeus
    Adversaries may employ various means to detect and avoid virtualization and analysis environments.
    0 installs
  32. T1481 003 One Way Communication · cyberstrikeus
    Adversaries may use an existing, legitimate external Web service channel as a means for sending commands to a compromised system without receiving return output.
    0 installs
  33. T1548 002 Bypass User Account Control · cyberstrikeus
    Adversaries may bypass UAC mechanisms to elevate process privileges on system.
    0 installs
  34. T1212 Exploitation For Credential Access · cyberstrikeus
    Adversaries may exploit software vulnerabilities in an attempt to collect credentials.
    0 installs
  35. T1568 002 Domain Generation Algorithms · cyberstrikeus
    Adversaries may make use of Domain Generation Algorithms (DGAs) to dynamically identify a destination domain for command and control traffic rather than relying on a list of static IP addresses or ...
    0 installs
  36. T1608 003 Install Digital Certificate · cyberstrikeus
    Adversaries may install SSL/TLS certificates that can be used during targeting.
    0 installs
  37. Sp 800 171 03 13 02 031302 · cyberstrikeus
    03.13.02
    0 installs
  38. Sp 800 171 03 13 03 031303 · cyberstrikeus
    03.13.03
    0 installs
  39. Sp 800 171 03 13 05 031305 · cyberstrikeus
    03.13.05
    0 installs
  40. Sp 800 171 03 13 07 031307 · cyberstrikeus
    03.13.07
    0 installs
  41. Sp 800 171 03 13 14 031314 · cyberstrikeus
    03.13.14
    0 installs
  42. Sp 800 171 03 13 16 031316 · cyberstrikeus
    03.13.16
    0 installs
  43. Information Flow Enforcement 03 01 03 Information Flow Enfor · cyberstrikeus
    Information Flow Enforcement
    0 installs
  44. Incident Response Testing 03 06 03 Incident Response Testing · cyberstrikeus
    Incident Response Testing
    0 installs
  45. Physical Access Control 03 10 07 Physical Access Control · cyberstrikeus
    Enforce physical access authorizations at entry and exit points to the facility where the system resides by: Verifying individual physical access auth
    0 installs
  46. Au 13 1 Use Of Automated Tools · cyberstrikeus
    Monitor open-source information and information sites using [organization-defined].
    0 installs
  47. Au 4 Audit Log Storage Capacity · cyberstrikeus
    Allocate audit log storage capacity to accommodate [organization-defined].
    0 installs
  48. Au 6 10 Audit Level Adjustment · cyberstrikeus
    Audit Level Adjustment
    0 installs
  49. Ca 4 Security Certification · cyberstrikeus
    Security Certification
    0 installs
  50. Cm 11 1 Alerts For Unauthorized Installations · cyberstrikeus
    Alerts for Unauthorized Installations
    0 installs
  51. Cm 3 6 Cryptography Management · cyberstrikeus
    Ensure that cryptographic mechanisms used to provide the following controls are under configuration management: [organization-defined].
    0 installs
  52. Cm 5 5 Privilege Limitation For Production And Operation · cyberstrikeus
    Limit privileges to change system components and system-related information within a production or operational environment;
    0 installs
  53. Cm 7 3 Registration Compliance · cyberstrikeus
    Ensure compliance with [organization-defined].
    0 installs
  54. Cm 8 System Component Inventory · cyberstrikeus
    Develop and document an inventory of system components that: Accurately reflects the system; Includes all components within the system; Does not inclu
    0 installs
  55. Cp 10 4 Restore Within Time Period · cyberstrikeus
    Provide the capability to restore system components within [organization-defined] from configuration-controlled and integrity-protected information re
    0 installs
  56. Cp 9 4 Protection From Unauthorized Modification · cyberstrikeus
    Protection from Unauthorized Modification
    0 installs
  57. Mp 5 1 Protection Outside Of Controlled Areas · cyberstrikeus
    Protection Outside of Controlled Areas
    0 installs
  58. Pm 14 Testing Training And Monitoring · cyberstrikeus
    Implement a process for ensuring that organizational plans for conducting security and privacy testing, training, and monitoring activities associated
    0 installs
  59. Pm 15 Security And Privacy Groups And Associations · cyberstrikeus
    Establish and institutionalize contact with selected groups and associations within the security and privacy communities: To facilitate ongoing securi
    0 installs
  60. Pm 19 Privacy Program Leadership Role · cyberstrikeus
    Appoint a senior agency official for privacy with the authority, mission, accountability, and resources to coordinate, develop, and implement, applica
    0 installs
  61. Pm 3 Information Security And Privacy Resources · cyberstrikeus
    Include the resources needed to implement the information security and privacy programs in capital planning and investment requests and document al...
    0 installs
  62. Pt 2 1 Data Tagging · cyberstrikeus
    Attach data tags containing [organization-defined] to [organization-defined].
    0 installs
  63. Pt 3 1 Data Tagging · cyberstrikeus
    Attach data tags containing the following purposes to [organization-defined]: [organization-defined].
    0 installs
  64. Pt 6 1 Routine Uses · cyberstrikeus
    Review all routine uses published in the system of records notice at [organization-defined] to ensure continued accuracy, and to ensure that routine u
    0 installs
  65. Ra 5 9 Penetration Testing And Analyses · cyberstrikeus
    Penetration Testing and Analyses
    0 installs
  66. Sa 15 1 Quality Metrics · cyberstrikeus
    Require the developer of the system, system component, or system service to: Define quality metrics at the beginning of the development process; and P
    0 installs
  67. Sa 15 13 Logging Syntax · cyberstrikeus
    Require the developer of the system or system component to minimize the use of personally identifiable information in development and test environment
    0 installs
  68. Sa 4 Acquisition Process · cyberstrikeus
    Include the following requirements, descriptions, and criteria, explicitly or by reference, using [organization-defined] in the acquisition contract f
    0 installs
  69. Sa 5 4 Low Level Design · cyberstrikeus
    Low-level Design
    0 installs
  70. Sa 8 14 Least Privilege · cyberstrikeus
    Implement the security design principle of least privilege in [organization-defined].
    0 installs
  71. Sa 8 23 Secure Defaults · cyberstrikeus
    Implement the security design principle of secure defaults in [organization-defined].
    0 installs
  72. Sc 29 Heterogeneity · cyberstrikeus
    Employ a diverse set of information technologies for the following system components in the implementation of the system: [organization-defined].
    0 installs
  73. Sc 30 2 Randomness · cyberstrikeus
    Employ [organization-defined] to introduce randomness into organizational operations and assets.
    0 installs
  74. Si 16 Memory Protection · cyberstrikeus
    Implement the following controls to protect the system memory from unauthorized code execution: [organization-defined].
    0 installs
  75. Si 19 De Identification · cyberstrikeus
    Remove the following elements of personally identifiable information from datasets: [organization-defined] ;
    0 installs
  76. Sr 2 1 Establish Scrm Team · cyberstrikeus
    Establish a supply chain risk management team consisting of [organization-defined] to lead and support the following SCRM activities: [organization-de
    0 installs
  77. Sr 3 1 Diverse Supply Base · cyberstrikeus
    Employ a diverse set of sources for the following system components and services: [organization-defined].
    0 installs
  78. T0804 Block Reporting Message · cyberstrikeus
    Adversaries may block or prevent a reporting message from reaching its intended target.
    0 installs
  79. T1664 Exploitation For Initial Access · cyberstrikeus
    Adversaries may exploit software vulnerabilities to gain initial access to a mobile device.
    0 installs
  80. T1639 001 Exfiltration Over Unencrypted Non C2 Protocol · cyberstrikeus
    Adversaries may steal data by exfiltrating it over an un-encrypted network protocol other than that of the existing command and control channel.
    0 installs
  81. T1437 Application Layer Protocol · cyberstrikeus
    Adversaries may communicate using application layer protocols to avoid detection/network filtering by blending in with existing traffic.
    0 installs
  82. T1521 001 Symmetric Cryptography · cyberstrikeus
    Adversaries may employ a known symmetric encryption algorithm to conceal command and control traffic, rather than relying on any inherent protections provided by a communication protocol.
    0 installs
  83. T1546 012 Image File Execution Options Injection · cyberstrikeus
    Adversaries may establish persistence and/or elevate privileges by executing malicious content triggered by Image File Execution Options (IFEO) debuggers.
    0 installs
  84. Least Privilege Privileged Accounts 03 01 06 Least Privilege · cyberstrikeus
    Restrict privileged accounts on the system to [organization-defined]..
    0 installs
  85. Remote Access 03 01 12 Remote Access · cyberstrikeus
    Establish usage restrictions, configuration requirements, and connection requirements for each type of allowable remote system access.
    0 installs
  86. Incident Handling 03 06 01 Incident Handling · cyberstrikeus
    Incident Handling
    0 installs
  87. Incident Response Training 03 06 04 Incident Response Traini · cyberstrikeus
    Provide incident response training to system users consistent with assigned roles and responsibilities: Within [organization-defined] of assuming an i
    0 installs
  88. Media Access 03 08 02 Media Access · cyberstrikeus
    Media Access
    0 installs
  89. Vulnerability Monitoring And Scanning 03 11 02 Vulnerability · cyberstrikeus
    Monitor and scan the system for vulnerabilities [organization-defined] and when new vulnerabilities affecting the system are identified.
    0 installs
  90. At 2 5 Advanced Persistent Threat · cyberstrikeus
    Provide literacy training on the advanced persistent threat.
    0 installs
  91. At 3 2 Physical Security Controls · cyberstrikeus
    Provide [organization-defined] with initial and [organization-defined] training in the employment and operation of physical security controls.
    0 installs
  92. Au 13 Monitoring For Information Disclosure · cyberstrikeus
    Monitor [organization-defined] [organization-defined] for evidence of unauthorized disclosure of organizational information;
    0 installs
  93. Au 3 2 Centralized Management Of Planned Audit Record Conten · cyberstrikeus
    Centralized Management of Planned Audit Record Content
    0 installs
  94. Au 5 1 Storage Capacity Warning · cyberstrikeus
    Provide a warning to [organization-defined] within [organization-defined] when allocated audit log storage volume reaches [organization-defined] of re
    0 installs
  95. Au 6 6 Correlation With Physical Monitoring · cyberstrikeus
    Correlate information from audit records with information obtained from monitoring physical access to further enhance the ability to identify suspicio
    0 installs
  96. Au 9 3 Cryptographic Protection · cyberstrikeus
    Implement cryptographic mechanisms to protect the integrity of audit information and audit tools.
    0 installs
  97. Ca 7 2 Types Of Assessments · cyberstrikeus
    Types of Assessments
    0 installs
  98. Ca 7 5 Consistency Analysis · cyberstrikeus
    Employ the following actions to validate that policies are established and implemented controls are operating in a consistent manner: [organization-de
    0 installs
  99. Cm 4 2 Verification Of Controls · cyberstrikeus
    After system changes, verify that the impacted controls are implemented correctly, operating as intended, and producing the desired outcome with regar
    0 installs
  100. Cm 5 6 Limit Library Privileges · cyberstrikeus
    Limit privileges to change software resident within software libraries.
    0 installs