cyberstrikeus
- 7.2k skills
- 0 followers
- 1 day ago last updated
- ▌ Cp 2 5 Continue Mission And Business Functions · cyberstrikeusPlan for the continuance of [organization-defined] mission and business functions with minimal or no loss of operational continuity and sustains that
- ▌ Cp 6 1 Separation From Primary Site · cyberstrikeusIdentify an alternate storage site that is sufficiently separated from the primary storage site to reduce susceptibility to the same threats.
- ▌ Cp 7 1 Separation From Primary Site · cyberstrikeusIdentify an alternate processing site that is sufficiently separated from the primary processing site to reduce susceptibility to the same threats.
- ▌ Cp 9 3 Separate Storage For Critical Information · cyberstrikeusStore backup copies of [organization-defined] in a separate facility or in a fire rated container that is not collocated with the operational system.
- ▌ Cp 9 5 Transfer To Alternate Storage Site · cyberstrikeusTransfer system backup information to the alternate storage site [organization-defined].
- ▌ Ia 11 Re Authentication · cyberstrikeusRequire users to re-authenticate when [organization-defined].
- ▌ Ia 12 Identity Proofing · cyberstrikeusIdentity proof users that require accounts for logical access to systems based on appropriate identity assurance level requirements as specified in...
- ▌ Ia 2 10 Single Sign On · cyberstrikeusProvide a single sign-on capability for [organization-defined].
- ▌ Ir 2 2 Automated Training Environments · cyberstrikeusProvide an incident response training environment using [organization-defined].
- ▌ Ir 3 2 Coordination With Related Plans · cyberstrikeusCoordinate incident response testing with organizational elements responsible for related plans.
- ▌ Ir 4 15 Public Relations And Reputation Repair · cyberstrikeusManage public relations associated with an incident;
- ▌ Pm 1 Information Security Program Plan · cyberstrikeusDevelop and disseminate an organization-wide information security program plan that: Provides an overview of the requirements for the security program
- ▌ Pm 20 Dissemination Of Privacy Program Information · cyberstrikeusMaintain a central resource webpage on the organization’s principal public website that serves as a central source of information about the organizati
- ▌
- ▌
- ▌ Sa 17 9 Design Diversity · cyberstrikeusUse different designs for [organization-defined] to satisfy a common set of requirements or to provide equivalent functionality.
- ▌ Sa 21 Developer Screening · cyberstrikeusRequire that the developer of [organization-defined]: Has appropriate access authorizations as determined by assigned [organization-defined] ; and Sat
- ▌ Sa 5 System Documentation · cyberstrikeusObtain or develop administrator documentation for the system, system component, or system service that describes: Secure configuration, installation,
- ▌
- ▌ Sa 8 30 Procedural Rigor · cyberstrikeusImplement the security design principle of procedural rigor in [organization-defined].
- ▌ Sa 8 6 Minimized Sharing · cyberstrikeusImplement the security design principle of minimized sharing in [organization-defined].
- ▌ Sc 7 18 Fail Secure · cyberstrikeusPrevent systems from entering unsecure states in the event of an operational failure of a boundary protection device.
- ▌ Si 7 1 Integrity Checks · cyberstrikeusPerform an integrity check of [organization-defined] [organization-defined].
- ▌ Sr 11 Component Authenticity · cyberstrikeusDevelop and implement anti-counterfeit policy and procedures that include the means to detect and prevent counterfeit components from entering the ...
- ▌ Sr 6 1 Testing And Analysis · cyberstrikeusEmploy [organization-defined] of the following supply chain elements, processes, and actors associated with the system, system component, or system se
- ▌ Sr 8 Notification Agreements · cyberstrikeusEstablish agreements and procedures with entities involved in the supply chain for the system, system component, or system service for the [organizati
- ▌
- ▌ Cis Docker 2 2 · cyberstrikeusEnsure network traffic is restricted between containers on the default bridge
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌ Cis Docker 3 4 · cyberstrikeusEnsure that docker.socket file permissions are set to 644 or more restrictive
- ▌
- ▌ Cis Docker 3 6 · cyberstrikeusEnsure that /etc/docker directory permissions are set to 755 or more restrictively
- ▌
- ▌ Cis Docker 3 8 · cyberstrikeusEnsure that registry certificate file permissions are set to 444 or more restrictively
- ▌
- ▌
- ▌
- ▌
- ▌ Id Im 02 Idim 02 · cyberstrikeusImprovements are identified from security tests and exercises, including those done in coordination with suppliers and relevant third parties
- ▌ Id Im 03 Idim 03 · cyberstrikeusImprovements are identified from execution of operational processes, procedures, and activities
- ▌ Id Im 04 Idim 04 · cyberstrikeusIncident response plans and other cybersecurity plans that affect operations are established, communicated, maintained, and improved
- ▌
- ▌ Id Ra 02 Idra 02 · cyberstrikeusCyber threat intelligence is received from information sharing forums and sources
- ▌ Id Ra 03 Idra 03 · cyberstrikeusInternal and external threats to the organization are identified and recorded
- ▌ Id Ra 04 Idra 04 · cyberstrikeusPotential impacts and likelihoods of threats exploiting vulnerabilities are identified and recorded
- ▌ Id Ra 05 Idra 05 · cyberstrikeusThreats, vulnerabilities, likelihoods, and impacts are used to understand inherent risk and inform risk response prioritization
- ▌ Id Ra 06 Idra 06 · cyberstrikeusRisk responses are chosen, prioritized, planned, tracked, and communicated
- ▌ Id Ra 07 Idra 07 · cyberstrikeusChanges and exceptions are managed, assessed for risk impact, recorded, and tracked
- ▌ Id Ra 08 Idra 08 · cyberstrikeusProcesses for receiving, analyzing, and responding to vulnerability disclosures are established
- ▌ Id Ra 09 Idra 09 · cyberstrikeusThe authenticity and integrity of hardware and software are assessed prior to acquisition and use
- ▌
- ▌ Id Rm 01 Idrm 01 · cyberstrikeusRisk management processes are established, managed, and agreed to by organizational stakeholders
- ▌
- ▌ Id Rm 03 Idrm 03 · cyberstrikeusThe organization’s determination of risk tolerance is informed by its role in critical infrastructure and sector specific risk analysis
- ▌ Id Sc 01 Idsc 01 · cyberstrikeusCyber supply chain risk management processes are identified, established, assessed, managed, and agreed to by organizational stakeholders
- ▌ Id Sc 02 Idsc 02 · cyberstrikeusSuppliers and third party partners of information systems, components, and services are identified, prioritized, and assessed using a cyber supply cha
- ▌ Id Sc 03 Idsc 03 · cyberstrikeusContracts with suppliers and third-party partners are used to implement appropriate measures designed to meet the objectives of an organization’s cybe
- ▌ Id Sc 04 Idsc 04 · cyberstrikeusSuppliers and third-party partners are routinely assessed using audits, test results, or other forms of evaluations to confirm they are meeting their
- ▌ Id Sc 05 Idsc 05 · cyberstrikeusResponse and recovery planning and testing are conducted with suppliers and third-party providers
- ▌
- ▌ T1491 Defacement · cyberstrikeusAdversaries may modify visual content available internally or externally to an enterprise network, thus affecting the integrity of the original content.
- ▌ T1053 003 Cron · cyberstrikeusAdversaries may abuse the <code>cron</code> utility to perform task scheduling for initial or recurring execution of malicious code.
- ▌ T0851 Rootkit · cyberstrikeusAdversaries may deploy rootkits to hide the presence of programs, files, network connections, services, drivers, and other system components.
- ▌ T1574 001 Dll · cyberstrikeusAdversaries may abuse dynamic-link library files (DLLs) in order to achieve persistence, escalate privileges, and evade defenses.
- ▌ T1489 Service Stop · cyberstrikeusAdversaries may stop or disable services on a system to render those services unavailable to legitimate users.
- ▌ Policy Gv Po Policy · cyberstrikeusOrganizational cybersecurity policy is established, communicated, and enforced
- ▌
- ▌ T1106 Native API · cyberstrikeusAdversaries may interact with the native OS application programming interface (API) to execute behaviors.
- ▌ T1667 Email Bombing · cyberstrikeusAdversaries may flood targeted email addresses with an overwhelming volume of messages.
- ▌ T0874 Hooking · cyberstrikeusAdversaries may hook into application programming interface (API) functions used by processes to redirect calls for execution and privilege escalation means.
- ▌ T1074 Data Staged · cyberstrikeusAdversaries may stage collected data in a central location or directory prior to Exfiltration.
- ▌ T1496 003 Sms Pumping · cyberstrikeusAdversaries may leverage messaging services for SMS pumping, which may impact system and/or hosted service availability.
- ▌ T1657 Financial Theft · cyberstrikeusAdversaries may steal monetary resources from targets through extortion, social engineering, technical theft, or other methods aimed at their own financial gain at the expense of the availability o...
- ▌ T1590 002 Dns · cyberstrikeusAdversaries may gather information about the victim's DNS that can be used during targeting.
- ▌ T0877 Io Image · cyberstrikeusAdversaries may seek to capture process values related to the inputs and outputs of a PLC.
- ▌ T0853 Scripting · cyberstrikeusAdversaries may use scripting languages to execute arbitrary code in the form of a pre-written script or in the form of user-supplied code to an interpreter.
- ▌ T0829 Loss Of View · cyberstrikeusAdversaries may cause a sustained or permanent loss of view where the ICS equipment will require local, hands-on operator intervention; for instance, a restart or manual operation.
- ▌ T1566 Phishing · cyberstrikeusAdversaries may send phishing messages to gain access to victim systems.
- ▌
- ▌ T1569 001 Launchctl · cyberstrikeusAdversaries may abuse launchctl to execute commands or programs.
- ▌ T1569 003 Systemctl · cyberstrikeusAdversaries may abuse systemctl to execute commands or programs.
- ▌ T1137 006 Add Ins · cyberstrikeusAdversaries may abuse Microsoft Office add-ins to obtain persistence on a compromised system.
- ▌
- ▌ T1014 Rootkit · cyberstrikeusAdversaries may use rootkits to hide the presence of programs, files, network connections, services, drivers, and other system components.
- ▌ T1218 014 Mmc · cyberstrikeusAdversaries may abuse mmc.exe to proxy execution of malicious .msc files.
- ▌ T1485 Data Destruction · cyberstrikeusAdversaries may destroy data and files on specific systems or in large numbers on a network to interrupt availability to systems, services, and network resources.
- ▌ T1596 004 Cdns · cyberstrikeusAdversaries may search content delivery network (CDN) data about victims that can be used during targeting.
- ▌ T0849 Masquerading · cyberstrikeusAdversaries may use masquerading to disguise a malicious application or executable as another file, to avoid operator and engineer suspicion.
- ▌ T0834 Native API · cyberstrikeusAdversaries may directly interact with the native OS application programming interface (API) to access system functions.
- ▌ T1059 001 Powershell · cyberstrikeusAdversaries may abuse PowerShell commands and scripts for execution.
- ▌ T1059 004 Unix Shell · cyberstrikeusAdversaries may abuse Unix shell commands and scripts for execution.