cyberstrikeus
- 7.2k skills
- 0 followers
- 1 day ago last updated
- ▌ Au 10 4 Validate Binding Of Information Reviewer Identity · cyberstrikeusValidate the binding of the information reviewer identity to the information at the transfer or release points prior to release or transfer between...
- ▌ Au 11 1 Long Term Retrieval Capability · cyberstrikeusEmploy [organization-defined] to ensure that long-term audit records generated by the system can be retrieved.
- ▌ Au 12 1 System Wide And Time Correlated Audit Trail · cyberstrikeusCompile audit records from [organization-defined] into a system-wide (logical or physical) audit trail that is time-correlated to within [organization
- ▌ Au 6 8 Full Text Analysis Of Privileged Commands · cyberstrikeusPerform a full text analysis of logged privileged commands in a physically distinct component or subsystem of the system, or other system that is dedi
- ▌ Ca 3 2 Classified National Security System Connections · cyberstrikeusClassified National Security System Connections
- ▌ Cm 2 7 Configure Systems And Components For High Risk Areas · cyberstrikeusIssue [organization-defined] with [organization-defined] to individuals traveling to locations that the organization deems to be of significant risk;
- ▌ Cm 3 3 Automated Change Implementation · cyberstrikeusImplement changes to the current system baseline and deploy the updated baseline across the installed base using [organization-defined].
- ▌ Cm 5 1 Automated Access Enforcement And Audit Records · cyberstrikeusEnforce access restrictions using [organization-defined] ;
- ▌ Cm 6 1 Automated Management Application And Verification · cyberstrikeusManage, apply, and verify configuration settings for [organization-defined] using [organization-defined].
- ▌ Cm 6 2 Respond To Unauthorized Changes · cyberstrikeusTake the following actions in response to unauthorized changes to [organization-defined]: [organization-defined].
- ▌ Cm 8 3 Automated Unauthorized Component Detection · cyberstrikeusDetect the presence of unauthorized hardware, software, and firmware components within the system using [organization-defined] [organization-define...
- ▌ Ia 3 Device Identification And Authentication · cyberstrikeusUniquely identify and authenticate [organization-defined] before establishing a [organization-defined] connection.
- ▌
- ▌ Pe 1 Policy And Procedures · cyberstrikeusDevelop, document, and disseminate to [organization-defined]: [organization-defined] physical and environmental protection policy that: Procedures to
- ▌ Pe 16 Delivery And Removal · cyberstrikeusAuthorize and control [organization-defined] entering and exiting the facility;
- ▌
- ▌ Pt 3 Personally Identifiable Information Processing Purposes · cyberstrikeusIdentify and document the [organization-defined] for processing personally identifiable information;
- ▌ Pt 4 2 Just In Time Consent · cyberstrikeusPresent [organization-defined] to individuals at [organization-defined] and in conjunction with [organization-defined].
- ▌ Sa 15 10 Incident Response Plan · cyberstrikeusRequire the developer of the system, system component, or system service to provide, implement, and test an incident response plan.
- ▌ Sa 17 4 Informal Correspondence · cyberstrikeusRequire the developer of the system, system component, or system service to: Produce, as an integral part of the development process, an informal desc
- ▌
- ▌
- ▌ Sa 4 2 Design And Implementation Information For Controls · cyberstrikeusRequire the developer of the system, system component, or system service to provide design and implementation information for the controls that includ
- ▌
- ▌ Sa 8 12 Hierarchical Protection · cyberstrikeusImplement the security design principle of hierarchical protection in [organization-defined].
- ▌ Sa 8 27 Human Factored Security · cyberstrikeusImplement the security design principle of human factored security in [organization-defined].
- ▌
- ▌ Sc 28 3 Cryptographic Keys · cyberstrikeusProvide protected storage for cryptographic keys [organization-defined].
- ▌ Sc 3 3 Minimize Nonsecurity Functionality · cyberstrikeusMinimize the number of nonsecurity functions included within the isolation boundary containing security functions.
- ▌ Sc 3 1 Hardware Separation · cyberstrikeusEmploy hardware separation mechanisms to implement security function isolation.
- ▌ Sc 36 1 Polling Techniques · cyberstrikeusEmploy polling techniques to identify potential faults, errors, or compromises to the following processing and storage components: [organization-de...
- ▌ Sc 8 4 Conceal Or Randomize Communications · cyberstrikeusImplement cryptographic mechanisms to conceal or randomize communication patterns unless otherwise protected by [organization-defined].
- ▌ Si 13 3 Manual Transfer Between Components · cyberstrikeusManually initiate transfers between active and standby system components when the use of the active component reaches [organization-defined] of the me
- ▌ Si 23 Information Fragmentation · cyberstrikeusBased on [organization-defined]: Fragment the following information: [organization-defined] ; and Distribute the fragmented information across the fol
- ▌ Si 4 10 Visibility Of Encrypted Communications · cyberstrikeusMake provisions so that [organization-defined] is visible to [organization-defined].
- ▌
- ▌ Si 4 5 System Generated Alerts · cyberstrikeusAlert [organization-defined] when the following system-generated indications of compromise or potential compromise occur: [organization-defined].
- ▌ Si 7 12 Integrity Verification · cyberstrikeusRequire that the integrity of the following user-installed software be verified prior to execution: [organization-defined].
- ▌
- ▌ Cis Docker V160 1 1 2 · cyberstrikeusEnsure only trusted users are allowed to control Docker daemon
- ▌
- ▌ Cis Docker V160 1 1 4 · cyberstrikeusEnsure auditing is configured for Docker files and directories - /run/containerd
- ▌ Cis Docker V160 1 1 5 · cyberstrikeusEnsure auditing is configured for Docker files and directories - /var/lib/docker
- ▌ Cis Docker V160 1 1 6 · cyberstrikeusEnsure auditing is configured for Docker files and directories - /etc/docker
- ▌ Cis Docker V160 1 1 7 · cyberstrikeusEnsure auditing is configured for Docker files and directories - docker.service
- ▌ Cis Docker V160 1 1 8 · cyberstrikeusEnsure auditing is configured for Docker files and directories - containerd.sock
- ▌ Cis Docker V160 1 1 9 · cyberstrikeusEnsure auditing is configured for Docker files and directories - docker.socket
- ▌
- ▌
- ▌
- ▌ Cis Docker V170 1 1 2 · cyberstrikeusEnsure only trusted users are allowed to control Docker daemon
- ▌
- ▌ Cis Docker V170 1 1 4 · cyberstrikeusEnsure auditing is configured for Docker files and directories - /run/containerd
- ▌ Cis Docker V170 1 1 5 · cyberstrikeusEnsure auditing is configured for Docker files and directories - /var/lib/docker
- ▌ Cis Docker V170 1 1 6 · cyberstrikeusEnsure auditing is configured for Docker files and directories - /etc/docker
- ▌ Cis Docker V170 1 1 7 · cyberstrikeusEnsure auditing is configured for Docker files and directories - docker.service
- ▌ Cis Docker V170 1 1 8 · cyberstrikeusEnsure auditing is configured for Docker files and directories - containerd.sock
- ▌ Cis Docker V170 1 1 9 · cyberstrikeusEnsure auditing is configured for Docker files and directories - docker.sock
- ▌
- ▌
- ▌ T1626 Abuse Elevation Control Mechanism · cyberstrikeusAdversaries may circumvent mechanisms designed to control elevated privileges to gain higher-level permissions.
- ▌ Collaborative Computing Devices And Applications 03 13 12 Co · cyberstrikeusProhibit the remote activation of collaborative computing devices and applications with the following exceptions: [organization-defined].
- ▌ Cryptographic Key Establishment And Management 03 13 10 Cryp · cyberstrikeusCryptographic Key Establishment and Management
- ▌
- ▌
- ▌ Acquisition Strategies Tools And Methods 03 17 02 Acquisitio · cyberstrikeusAcquisition Strategies, Tools, and Methods
- ▌ Implement Roles And Responsibilities Po 2 Implement Roles An · cyberstrikeusEnsure that everyone inside and outside of the organization involved in the SDLC is prepared to perform their SDLC-related roles and responsibilities
- ▌
- ▌ Au 16 Cross Organizational Audit Logging · cyberstrikeusEmploy [organization-defined] for coordinating [organization-defined] among external organizations when audit information is transmitted across organi
- ▌ Ca 8 3 Facility Penetration Testing · cyberstrikeusEmploy a penetration testing process that includes [organization-defined] [organization-defined] attempts to bypass or circumvent controls associated
- ▌ Cm 2 6 Development And Test Environments · cyberstrikeusMaintain a baseline configuration for system development and test environments that is managed separately from the operational baseline configuration.
- ▌ Cm 7 8 Binary Or Machine Executable Code · cyberstrikeusProhibit the use of binary or machine-executable code from sources with limited or no warranty or without the provision of source code;
- ▌ Ia 8 4 Use Of Defined Profiles · cyberstrikeusConform to the following profiles for identity management [organization-defined].
- ▌ Ia 9 Service Identification And Authentication · cyberstrikeusUniquely identify and authenticate [organization-defined] before establishing communications with devices, users, or other services or applications.
- ▌ Pe 14 1 Automatic Controls · cyberstrikeusEmploy the following automatic environmental controls in the facility to prevent fluctuations potentially harmful to the system: [organization-defined
- ▌ Pe 15 1 Automation Support · cyberstrikeusDetect the presence of water near the system and alert [organization-defined] using [organization-defined].
- ▌ Pe 6 1 Intrusion Alarms And Surveillance Equipment · cyberstrikeusMonitor physical access to the facility where the system resides using physical intrusion alarms and surveillance equipment.
- ▌ Pe 8 Visitor Access Records · cyberstrikeusMaintain visitor access records to the facility where the system resides for [organization-defined];
- ▌ Pt 6 System Of Records Notice · cyberstrikeusFor systems that process information that will be maintained in a Privacy Act system of records: Draft system of records notices in accordance with OM
- ▌ Sa 10 2 Alternative Configuration Management Processes · cyberstrikeusProvide an alternate configuration management process using organizational personnel in the absence of a dedicated developer configuration management
- ▌ Sa 15 5 Attack Surface Reduction · cyberstrikeusRequire the developer of the system, system component, or system service to reduce attack surfaces to [organization-defined].
- ▌ Sa 16 Developer Provided Training · cyberstrikeusRequire the developer of the system, system component, or system service to provide the following training on the correct use and operation of the imp
- ▌ Sa 18 1 Multiple Phases Of System Development Life Cycle · cyberstrikeusMultiple Phases of System Development Life Cycle
- ▌ Sa 19 2 Configuration Control For Component Service And Repa · cyberstrikeusConfiguration Control for Component Service and Repair
- ▌ Sa 24 Design For Cyber Resiliency · cyberstrikeusDesign organizational systems, system components, or system services to achieve cyber resiliency by: Defining the following cyber resiliency goals: [o
- ▌ Sa 5 2 Security Relevant External System Interfaces · cyberstrikeusSecurity-relevant External System Interfaces
- ▌ Sa 8 29 Repeatable And Documented Procedures · cyberstrikeusImplement the security design principle of repeatable and documented procedures in [organization-defined].
- ▌ Sa 8 32 Sufficient Documentation · cyberstrikeusImplement the security design principle of sufficient documentation in [organization-defined].
- ▌ Sc 31 3 Measure Bandwidth In Operational Environments · cyberstrikeusMeasure the bandwidth of [organization-defined] in the operational environment of the system.
- ▌ Sc 34 1 No Writable Storage · cyberstrikeusEmploy [organization-defined] with no writeable storage that is persistent across component restart or power on/off.
- ▌ Sc 39 1 Hardware Separation · cyberstrikeusImplement hardware separation mechanisms to facilitate process isolation.
- ▌ Sc 45 1 Synchronization With Authoritative Time Source · cyberstrikeusCompare the internal system clocks [organization-defined] with [organization-defined] ;
- ▌ Si 12 Information Management And Retention · cyberstrikeusManage and retain information within the system and information output from the system in accordance with applicable laws, executive orders, directive
- ▌ Si 19 7 Validated Algorithms And Software · cyberstrikeusPerform de-identification using validated algorithms and software that is validated to implement the algorithms.
- ▌ Si 3 10 Malicious Code Analysis · cyberstrikeusEmploy the following tools and techniques to analyze the characteristics and behavior of malicious code: [organization-defined] ;
- ▌
- ▌ Si 3 6 Testing And Verification · cyberstrikeusTest malicious code protection mechanisms [organization-defined] by introducing known benign code into the system;
- ▌ Si 4 25 Optimize Network Traffic Analysis · cyberstrikeusProvide visibility into network traffic at external and key internal system interfaces to optimize the effectiveness of monitoring devices.
- ▌ Si 7 17 Runtime Application Self Protection · cyberstrikeusImplement [organization-defined] for application self-protection at runtime.
- ▌