← all publishers

cyberstrikeus

@cyberstrikeus source repo

7171 published skills · page 53 of 72

  1. Cp 2 5 Continue Mission And Business Functions · cyberstrikeus
    Plan for the continuance of [organization-defined] mission and business functions with minimal or no loss of operational continuity and sustains that
    0 installs
  2. Cp 6 1 Separation From Primary Site · cyberstrikeus
    Identify an alternate storage site that is sufficiently separated from the primary storage site to reduce susceptibility to the same threats.
    0 installs
  3. Cp 7 1 Separation From Primary Site · cyberstrikeus
    Identify an alternate processing site that is sufficiently separated from the primary processing site to reduce susceptibility to the same threats.
    0 installs
  4. Cp 9 3 Separate Storage For Critical Information · cyberstrikeus
    Store backup copies of [organization-defined] in a separate facility or in a fire rated container that is not collocated with the operational system.
    0 installs
  5. Cp 9 5 Transfer To Alternate Storage Site · cyberstrikeus
    Transfer system backup information to the alternate storage site [organization-defined].
    0 installs
  6. Ia 11 Re Authentication · cyberstrikeus
    Require users to re-authenticate when [organization-defined].
    0 installs
  7. Ia 12 Identity Proofing · cyberstrikeus
    Identity proof users that require accounts for logical access to systems based on appropriate identity assurance level requirements as specified in...
    0 installs
  8. Ia 2 10 Single Sign On · cyberstrikeus
    Provide a single sign-on capability for [organization-defined].
    0 installs
  9. Ir 2 2 Automated Training Environments · cyberstrikeus
    Provide an incident response training environment using [organization-defined].
    0 installs
  10. Ir 3 2 Coordination With Related Plans · cyberstrikeus
    Coordinate incident response testing with organizational elements responsible for related plans.
    0 installs
  11. Ir 4 15 Public Relations And Reputation Repair · cyberstrikeus
    Manage public relations associated with an incident;
    0 installs
  12. Pm 1 Information Security Program Plan · cyberstrikeus
    Develop and disseminate an organization-wide information security program plan that: Provides an overview of the requirements for the security program
    0 installs
  13. Pm 20 Dissemination Of Privacy Program Information · cyberstrikeus
    Maintain a central resource webpage on the organization’s principal public website that serves as a central source of information about the organizati
    0 installs
  14. Sa 12 2 Supplier Reviews · cyberstrikeus
    Supplier Reviews
    0 installs
  15. Sa 15 9 Use Of Live Data · cyberstrikeus
    Use of Live Data
    0 installs
  16. Sa 17 9 Design Diversity · cyberstrikeus
    Use different designs for [organization-defined] to satisfy a common set of requirements or to provide equivalent functionality.
    0 installs
  17. Sa 21 Developer Screening · cyberstrikeus
    Require that the developer of [organization-defined]: Has appropriate access authorizations as determined by assigned [organization-defined] ; and Sat
    0 installs
  18. Sa 5 System Documentation · cyberstrikeus
    Obtain or develop administrator documentation for the system, system component, or system service that describes: Secure configuration, installation,
    0 installs
  19. Sa 5 3 High Level Design · cyberstrikeus
    High-level Design
    0 installs
  20. Sa 8 30 Procedural Rigor · cyberstrikeus
    Implement the security design principle of procedural rigor in [organization-defined].
    0 installs
  21. Sa 8 6 Minimized Sharing · cyberstrikeus
    Implement the security design principle of minimized sharing in [organization-defined].
    0 installs
  22. Sc 7 18 Fail Secure · cyberstrikeus
    Prevent systems from entering unsecure states in the event of an operational failure of a boundary protection device.
    0 installs
  23. Si 7 1 Integrity Checks · cyberstrikeus
    Perform an integrity check of [organization-defined] [organization-defined].
    0 installs
  24. Sr 11 Component Authenticity · cyberstrikeus
    Develop and implement anti-counterfeit policy and procedures that include the means to detect and prevent counterfeit components from entering the ...
    0 installs
  25. Sr 6 1 Testing And Analysis · cyberstrikeus
    Employ [organization-defined] of the following supply chain elements, processes, and actors associated with the system, system component, or system se
    0 installs
  26. Sr 8 Notification Agreements · cyberstrikeus
    Establish agreements and procedures with entities involved in the supply chain for the system, system component, or system service for the [organizati
    0 installs
  27. Cis Docker 2 1 · cyberstrikeus
    Run the Docker daemon as a non-root user, if possible
    0 installs
  28. Cis Docker 2 2 · cyberstrikeus
    Ensure network traffic is restricted between containers on the default bridge
    0 installs
  29. Cis Docker 2 3 · cyberstrikeus
    Ensure the logging level is set to 'info'
    0 installs
  30. Cis Docker 2 4 · cyberstrikeus
    Ensure Docker is allowed to make changes to iptables
    0 installs
  31. Cis Docker 2 5 · cyberstrikeus
    Ensure insecure registries are not used
    0 installs
  32. Cis Docker 2 6 · cyberstrikeus
    Ensure aufs storage driver is not used
    0 installs
  33. Cis Docker 2 7 · cyberstrikeus
    Ensure devicemapper storage driver is not used
    0 installs
  34. Cis Docker 2 8 · cyberstrikeus
    Ensure TLS authentication for Docker daemon is configured
    0 installs
  35. Cis Docker 2 9 · cyberstrikeus
    Ensure the default ulimit is configured appropriately
    0 installs
  36. Cis Docker 3 1 · cyberstrikeus
    Ensure that the docker.service file ownership is set to root:root
    0 installs
  37. Cis Docker 3 2 · cyberstrikeus
    Ensure that docker.service file permissions are appropriately set
    0 installs
  38. Cis Docker 3 3 · cyberstrikeus
    Ensure that docker.socket file ownership is set to root:root
    0 installs
  39. Cis Docker 3 4 · cyberstrikeus
    Ensure that docker.socket file permissions are set to 644 or more restrictive
    0 installs
  40. Cis Docker 3 5 · cyberstrikeus
    Ensure that the /etc/docker directory ownership is set to root:root
    0 installs
  41. Cis Docker 3 6 · cyberstrikeus
    Ensure that /etc/docker directory permissions are set to 755 or more restrictively
    0 installs
  42. Cis Docker 3 7 · cyberstrikeus
    Ensure that registry certificate file ownership is set to root:root
    0 installs
  43. Cis Docker 3 8 · cyberstrikeus
    Ensure that registry certificate file permissions are set to 444 or more restrictively
    0 installs
  44. Cis Docker 3 9 · cyberstrikeus
    Ensure that TLS CA certificate file ownership is set to root:root
    0 installs
  45. Cis Docker 4 1 · cyberstrikeus
    Ensure that a user for the container has been created
    0 installs
  46. Cis Docker 4 2 · cyberstrikeus
    Ensure that containers use only trusted base images
    0 installs
  47. Cis Docker 4 3 · cyberstrikeus
    Ensure that unnecessary packages are not installed in the container
    0 installs
  48. Id Im 02 Idim 02 · cyberstrikeus
    Improvements are identified from security tests and exercises, including those done in coordination with suppliers and relevant third parties
    0 installs
  49. Id Im 03 Idim 03 · cyberstrikeus
    Improvements are identified from execution of operational processes, procedures, and activities
    0 installs
  50. Id Im 04 Idim 04 · cyberstrikeus
    Incident response plans and other cybersecurity plans that affect operations are established, communicated, maintained, and improved
    0 installs
  51. Id Ra 01 Idra 01 · cyberstrikeus
    Vulnerabilities in assets are identified, validated, and recorded
    0 installs
  52. Id Ra 02 Idra 02 · cyberstrikeus
    Cyber threat intelligence is received from information sharing forums and sources
    0 installs
  53. Id Ra 03 Idra 03 · cyberstrikeus
    Internal and external threats to the organization are identified and recorded
    0 installs
  54. Id Ra 04 Idra 04 · cyberstrikeus
    Potential impacts and likelihoods of threats exploiting vulnerabilities are identified and recorded
    0 installs
  55. Id Ra 05 Idra 05 · cyberstrikeus
    Threats, vulnerabilities, likelihoods, and impacts are used to understand inherent risk and inform risk response prioritization
    0 installs
  56. Id Ra 06 Idra 06 · cyberstrikeus
    Risk responses are chosen, prioritized, planned, tracked, and communicated
    0 installs
  57. Id Ra 07 Idra 07 · cyberstrikeus
    Changes and exceptions are managed, assessed for risk impact, recorded, and tracked
    0 installs
  58. Id Ra 08 Idra 08 · cyberstrikeus
    Processes for receiving, analyzing, and responding to vulnerability disclosures are established
    0 installs
  59. Id Ra 09 Idra 09 · cyberstrikeus
    The authenticity and integrity of hardware and software are assessed prior to acquisition and use
    0 installs
  60. Id Ra 10 Idra 10 · cyberstrikeus
    Critical suppliers are assessed prior to acquisition
    0 installs
  61. Id Rm 01 Idrm 01 · cyberstrikeus
    Risk management processes are established, managed, and agreed to by organizational stakeholders
    0 installs
  62. Id Rm 02 Idrm 02 · cyberstrikeus
    Organizational risk tolerance is determined and clearly expressed
    0 installs
  63. Id Rm 03 Idrm 03 · cyberstrikeus
    The organization’s determination of risk tolerance is informed by its role in critical infrastructure and sector specific risk analysis
    0 installs
  64. Id Sc 01 Idsc 01 · cyberstrikeus
    Cyber supply chain risk management processes are identified, established, assessed, managed, and agreed to by organizational stakeholders
    0 installs
  65. Id Sc 02 Idsc 02 · cyberstrikeus
    Suppliers and third party partners of information systems, components, and services are identified, prioritized, and assessed using a cyber supply cha
    0 installs
  66. Id Sc 03 Idsc 03 · cyberstrikeus
    Contracts with suppliers and third-party partners are used to implement appropriate measures designed to meet the objectives of an organization’s cybe
    0 installs
  67. Id Sc 04 Idsc 04 · cyberstrikeus
    Suppliers and third-party partners are routinely assessed using audits, test results, or other forms of evaluations to confirm they are meeting their
    0 installs
  68. Id Sc 05 Idsc 05 · cyberstrikeus
    Response and recovery planning and testing are conducted with suppliers and third-party providers
    0 installs
  69. T1059 011 Lua · cyberstrikeus
    Adversaries may abuse Lua commands and scripts for execution.
    0 installs
  70. T1491 Defacement · cyberstrikeus
    Adversaries may modify visual content available internally or externally to an enterprise network, thus affecting the integrity of the original content.
    0 installs
  71. T1053 003 Cron · cyberstrikeus
    Adversaries may abuse the <code>cron</code> utility to perform task scheduling for initial or recurring execution of malicious code.
    0 installs
  72. T0851 Rootkit · cyberstrikeus
    Adversaries may deploy rootkits to hide the presence of programs, files, network connections, services, drivers, and other system components.
    0 installs
  73. T1574 001 Dll · cyberstrikeus
    Adversaries may abuse dynamic-link library files (DLLs) in order to achieve persistence, escalate privileges, and evade defenses.
    0 installs
  74. T1489 Service Stop · cyberstrikeus
    Adversaries may stop or disable services on a system to render those services unavailable to legitimate users.
    0 installs
  75. Policy Gv Po Policy · cyberstrikeus
    Organizational cybersecurity policy is established, communicated, and enforced
    0 installs
  76. T1059 006 Python · cyberstrikeus
    Adversaries may abuse Python commands and scripts for execution.
    0 installs
  77. T1106 Native API · cyberstrikeus
    Adversaries may interact with the native OS application programming interface (API) to execute behaviors.
    0 installs
  78. T1667 Email Bombing · cyberstrikeus
    Adversaries may flood targeted email addresses with an overwhelming volume of messages.
    0 installs
  79. T0874 Hooking · cyberstrikeus
    Adversaries may hook into application programming interface (API) functions used by processes to redirect calls for execution and privilege escalation means.
    0 installs
  80. T1074 Data Staged · cyberstrikeus
    Adversaries may stage collected data in a central location or directory prior to Exfiltration.
    0 installs
  81. T1496 003 Sms Pumping · cyberstrikeus
    Adversaries may leverage messaging services for SMS pumping, which may impact system and/or hosted service availability.
    0 installs
  82. T1657 Financial Theft · cyberstrikeus
    Adversaries may steal monetary resources from targets through extortion, social engineering, technical theft, or other methods aimed at their own financial gain at the expense of the availability o...
    0 installs
  83. T1590 002 Dns · cyberstrikeus
    Adversaries may gather information about the victim's DNS that can be used during targeting.
    0 installs
  84. T0877 Io Image · cyberstrikeus
    Adversaries may seek to capture process values related to the inputs and outputs of a PLC.
    0 installs
  85. T0853 Scripting · cyberstrikeus
    Adversaries may use scripting languages to execute arbitrary code in the form of a pre-written script or in the form of user-supplied code to an interpreter.
    0 installs
  86. T0829 Loss Of View · cyberstrikeus
    Adversaries may cause a sustained or permanent loss of view where the ICS equipment will require local, hands-on operator intervention; for instance, a restart or manual operation.
    0 installs
  87. T1566 Phishing · cyberstrikeus
    Adversaries may send phishing messages to gain access to victim systems.
    0 installs
  88. T1059 009 Cloud API · cyberstrikeus
    Adversaries may abuse cloud APIs to execute malicious commands.
    0 installs
  89. T1569 001 Launchctl · cyberstrikeus
    Adversaries may abuse launchctl to execute commands or programs.
    0 installs
  90. T1569 003 Systemctl · cyberstrikeus
    Adversaries may abuse systemctl to execute commands or programs.
    0 installs
  91. T1137 006 Add Ins · cyberstrikeus
    Adversaries may abuse Microsoft Office add-ins to obtain persistence on a compromised system.
    0 installs
  92. T1542 003 Bootkit · cyberstrikeus
    Adversaries may use bootkits to persist on systems.
    0 installs
  93. T1014 Rootkit · cyberstrikeus
    Adversaries may use rootkits to hide the presence of programs, files, network connections, services, drivers, and other system components.
    0 installs
  94. T1218 014 Mmc · cyberstrikeus
    Adversaries may abuse mmc.exe to proxy execution of malicious .msc files.
    0 installs
  95. T1485 Data Destruction · cyberstrikeus
    Adversaries may destroy data and files on specific systems or in large numbers on a network to interrupt availability to systems, services, and network resources.
    0 installs
  96. T1596 004 Cdns · cyberstrikeus
    Adversaries may search content delivery network (CDN) data about victims that can be used during targeting.
    0 installs
  97. T0849 Masquerading · cyberstrikeus
    Adversaries may use masquerading to disguise a malicious application or executable as another file, to avoid operator and engineer suspicion.
    0 installs
  98. T0834 Native API · cyberstrikeus
    Adversaries may directly interact with the native OS application programming interface (API) to access system functions.
    0 installs
  99. T1059 001 Powershell · cyberstrikeus
    Adversaries may abuse PowerShell commands and scripts for execution.
    0 installs
  100. T1059 004 Unix Shell · cyberstrikeus
    Adversaries may abuse Unix shell commands and scripts for execution.
    0 installs