← all publishers

cyberstrikeus

@cyberstrikeus source repo

7171 published skills · page 56 of 72

  1. Au 10 4 Validate Binding Of Information Reviewer Identity · cyberstrikeus
    Validate the binding of the information reviewer identity to the information at the transfer or release points prior to release or transfer between...
    0 installs
  2. Au 11 1 Long Term Retrieval Capability · cyberstrikeus
    Employ [organization-defined] to ensure that long-term audit records generated by the system can be retrieved.
    0 installs
  3. Au 12 1 System Wide And Time Correlated Audit Trail · cyberstrikeus
    Compile audit records from [organization-defined] into a system-wide (logical or physical) audit trail that is time-correlated to within [organization
    0 installs
  4. Au 6 8 Full Text Analysis Of Privileged Commands · cyberstrikeus
    Perform a full text analysis of logged privileged commands in a physically distinct component or subsystem of the system, or other system that is dedi
    0 installs
  5. Ca 3 2 Classified National Security System Connections · cyberstrikeus
    Classified National Security System Connections
    0 installs
  6. Cm 2 7 Configure Systems And Components For High Risk Areas · cyberstrikeus
    Issue [organization-defined] with [organization-defined] to individuals traveling to locations that the organization deems to be of significant risk;
    0 installs
  7. Cm 3 3 Automated Change Implementation · cyberstrikeus
    Implement changes to the current system baseline and deploy the updated baseline across the installed base using [organization-defined].
    0 installs
  8. Cm 5 1 Automated Access Enforcement And Audit Records · cyberstrikeus
    Enforce access restrictions using [organization-defined] ;
    0 installs
  9. Cm 6 1 Automated Management Application And Verification · cyberstrikeus
    Manage, apply, and verify configuration settings for [organization-defined] using [organization-defined].
    0 installs
  10. Cm 6 2 Respond To Unauthorized Changes · cyberstrikeus
    Take the following actions in response to unauthorized changes to [organization-defined]: [organization-defined].
    0 installs
  11. Cm 8 3 Automated Unauthorized Component Detection · cyberstrikeus
    Detect the presence of unauthorized hardware, software, and firmware components within the system using [organization-defined] [organization-define...
    0 installs
  12. Ia 3 Device Identification And Authentication · cyberstrikeus
    Uniquely identify and authenticate [organization-defined] before establishing a [organization-defined] connection.
    0 installs
  13. Ia 4 7 In Person Registration · cyberstrikeus
    In-person Registration
    0 installs
  14. Pe 1 Policy And Procedures · cyberstrikeus
    Develop, document, and disseminate to [organization-defined]: [organization-defined] physical and environmental protection policy that: Procedures to
    0 installs
  15. Pe 16 Delivery And Removal · cyberstrikeus
    Authorize and control [organization-defined] entering and exiting the facility;
    0 installs
  16. Pe 6 3 Video Surveillance · cyberstrikeus
    Employ video surveillance of [organization-defined];
    0 installs
  17. Pt 3 Personally Identifiable Information Processing Purposes · cyberstrikeus
    Identify and document the [organization-defined] for processing personally identifiable information;
    0 installs
  18. Pt 4 2 Just In Time Consent · cyberstrikeus
    Present [organization-defined] to individuals at [organization-defined] and in conjunction with [organization-defined].
    0 installs
  19. Sa 15 10 Incident Response Plan · cyberstrikeus
    Require the developer of the system, system component, or system service to provide, implement, and test an incident response plan.
    0 installs
  20. Sa 17 4 Informal Correspondence · cyberstrikeus
    Require the developer of the system, system component, or system service to: Produce, as an integral part of the development process, an informal desc
    0 installs
  21. Sa 18 2 Inspection Of Systems Or Components · cyberstrikeus
    Inspection of Systems or Components
    0 installs
  22. Sa 21 1 Validation Of Screening · cyberstrikeus
    Validation of Screening
    0 installs
  23. Sa 4 2 Design And Implementation Information For Controls · cyberstrikeus
    Require the developer of the system, system component, or system service to provide design and implementation information for the controls that includ
    0 installs
  24. Sa 6 Software Usage Restrictions · cyberstrikeus
    Software Usage Restrictions
    0 installs
  25. Sa 8 12 Hierarchical Protection · cyberstrikeus
    Implement the security design principle of hierarchical protection in [organization-defined].
    0 installs
  26. Sa 8 27 Human Factored Security · cyberstrikeus
    Implement the security design principle of human factored security in [organization-defined].
    0 installs
  27. Sc 13 4 Digital Signatures · cyberstrikeus
    Digital Signatures
    0 installs
  28. Sc 28 3 Cryptographic Keys · cyberstrikeus
    Provide protected storage for cryptographic keys [organization-defined].
    0 installs
  29. Sc 3 3 Minimize Nonsecurity Functionality · cyberstrikeus
    Minimize the number of nonsecurity functions included within the isolation boundary containing security functions.
    0 installs
  30. Sc 3 1 Hardware Separation · cyberstrikeus
    Employ hardware separation mechanisms to implement security function isolation.
    0 installs
  31. Sc 36 1 Polling Techniques · cyberstrikeus
    Employ polling techniques to identify potential faults, errors, or compromises to the following processing and storage components: [organization-de...
    0 installs
  32. Sc 8 4 Conceal Or Randomize Communications · cyberstrikeus
    Implement cryptographic mechanisms to conceal or randomize communication patterns unless otherwise protected by [organization-defined].
    0 installs
  33. Si 13 3 Manual Transfer Between Components · cyberstrikeus
    Manually initiate transfers between active and standby system components when the use of the active component reaches [organization-defined] of the me
    0 installs
  34. Si 23 Information Fragmentation · cyberstrikeus
    Based on [organization-defined]: Fragment the following information: [organization-defined] ; and Distribute the fragmented information across the fol
    0 installs
  35. Si 4 10 Visibility Of Encrypted Communications · cyberstrikeus
    Make provisions so that [organization-defined] is visible to [organization-defined].
    0 installs
  36. Si 4 8 Protection Of Monitoring Information · cyberstrikeus
    Protection of Monitoring Information
    0 installs
  37. Si 4 5 System Generated Alerts · cyberstrikeus
    Alert [organization-defined] when the following system-generated indications of compromise or potential compromise occur: [organization-defined].
    0 installs
  38. Si 7 12 Integrity Verification · cyberstrikeus
    Require that the integrity of the following user-installed software be verified prior to execution: [organization-defined].
    0 installs
  39. Cis Docker V160 1 1 1 · cyberstrikeus
    Ensure a separate partition for containers has been created
    0 installs
  40. Cis Docker V160 1 1 2 · cyberstrikeus
    Ensure only trusted users are allowed to control Docker daemon
    0 installs
  41. Cis Docker V160 1 1 3 · cyberstrikeus
    Ensure auditing is configured for the Docker daemon
    0 installs
  42. Cis Docker V160 1 1 4 · cyberstrikeus
    Ensure auditing is configured for Docker files and directories - /run/containerd
    0 installs
  43. Cis Docker V160 1 1 5 · cyberstrikeus
    Ensure auditing is configured for Docker files and directories - /var/lib/docker
    0 installs
  44. Cis Docker V160 1 1 6 · cyberstrikeus
    Ensure auditing is configured for Docker files and directories - /etc/docker
    0 installs
  45. Cis Docker V160 1 1 7 · cyberstrikeus
    Ensure auditing is configured for Docker files and directories - docker.service
    0 installs
  46. Cis Docker V160 1 1 8 · cyberstrikeus
    Ensure auditing is configured for Docker files and directories - containerd.sock
    0 installs
  47. Cis Docker V160 1 1 9 · cyberstrikeus
    Ensure auditing is configured for Docker files and directories - docker.socket
    0 installs
  48. Cis Docker V160 1 2 1 · cyberstrikeus
    Ensure the container host has been Hardened
    0 installs
  49. Cis Docker V160 1 2 2 · cyberstrikeus
    Ensure that the version of Docker is up to date
    0 installs
  50. Cis Docker V170 1 1 1 · cyberstrikeus
    Ensure a separate partition for containers has been created
    0 installs
  51. Cis Docker V170 1 1 2 · cyberstrikeus
    Ensure only trusted users are allowed to control Docker daemon
    0 installs
  52. Cis Docker V170 1 1 3 · cyberstrikeus
    Ensure auditing is configured for the Docker daemon
    0 installs
  53. Cis Docker V170 1 1 4 · cyberstrikeus
    Ensure auditing is configured for Docker files and directories - /run/containerd
    0 installs
  54. Cis Docker V170 1 1 5 · cyberstrikeus
    Ensure auditing is configured for Docker files and directories - /var/lib/docker
    0 installs
  55. Cis Docker V170 1 1 6 · cyberstrikeus
    Ensure auditing is configured for Docker files and directories - /etc/docker
    0 installs
  56. Cis Docker V170 1 1 7 · cyberstrikeus
    Ensure auditing is configured for Docker files and directories - docker.service
    0 installs
  57. Cis Docker V170 1 1 8 · cyberstrikeus
    Ensure auditing is configured for Docker files and directories - containerd.sock
    0 installs
  58. Cis Docker V170 1 1 9 · cyberstrikeus
    Ensure auditing is configured for Docker files and directories - docker.sock
    0 installs
  59. Cis Docker V170 1 2 1 · cyberstrikeus
    Ensure the container host has been Hardened
    0 installs
  60. Cis Docker V170 1 2 2 · cyberstrikeus
    Ensure that the version of Docker is up to date
    0 installs
  61. T1626 Abuse Elevation Control Mechanism · cyberstrikeus
    Adversaries may circumvent mechanisms designed to control elevated privileges to gain higher-level permissions.
    0 installs
  62. Collaborative Computing Devices And Applications 03 13 12 Co · cyberstrikeus
    Prohibit the remote activation of collaborative computing devices and applications with the following exceptions: [organization-defined].
    0 installs
  63. Cryptographic Key Establishment And Management 03 13 10 Cryp · cyberstrikeus
    Cryptographic Key Establishment and Management
    0 installs
  64. Network Disconnect 03 13 09 Network Disconnect · cyberstrikeus
    Network Disconnect
    0 installs
  65. Sp 800 171 03 12 04 031204 · cyberstrikeus
    03.12.04
    0 installs
  66. Acquisition Strategies Tools And Methods 03 17 02 Acquisitio · cyberstrikeus
    Acquisition Strategies, Tools, and Methods
    0 installs
  67. Implement Roles And Responsibilities Po 2 Implement Roles An · cyberstrikeus
    Ensure that everyone inside and outside of the organization involved in the SDLC is prepared to perform their SDLC-related roles and responsibilities
    0 installs
  68. Au 15 Alternate Audit Logging Capability · cyberstrikeus
    Alternate Audit Logging Capability
    0 installs
  69. Au 16 Cross Organizational Audit Logging · cyberstrikeus
    Employ [organization-defined] for coordinating [organization-defined] among external organizations when audit information is transmitted across organi
    0 installs
  70. Ca 8 3 Facility Penetration Testing · cyberstrikeus
    Employ a penetration testing process that includes [organization-defined] [organization-defined] attempts to bypass or circumvent controls associated
    0 installs
  71. Cm 2 6 Development And Test Environments · cyberstrikeus
    Maintain a baseline configuration for system development and test environments that is managed separately from the operational baseline configuration.
    0 installs
  72. Cm 7 8 Binary Or Machine Executable Code · cyberstrikeus
    Prohibit the use of binary or machine-executable code from sources with limited or no warranty or without the provision of source code;
    0 installs
  73. Ia 8 4 Use Of Defined Profiles · cyberstrikeus
    Conform to the following profiles for identity management [organization-defined].
    0 installs
  74. Ia 9 Service Identification And Authentication · cyberstrikeus
    Uniquely identify and authenticate [organization-defined] before establishing communications with devices, users, or other services or applications.
    0 installs
  75. Pe 14 1 Automatic Controls · cyberstrikeus
    Employ the following automatic environmental controls in the facility to prevent fluctuations potentially harmful to the system: [organization-defined
    0 installs
  76. Pe 15 1 Automation Support · cyberstrikeus
    Detect the presence of water near the system and alert [organization-defined] using [organization-defined].
    0 installs
  77. Pe 6 1 Intrusion Alarms And Surveillance Equipment · cyberstrikeus
    Monitor physical access to the facility where the system resides using physical intrusion alarms and surveillance equipment.
    0 installs
  78. Pe 8 Visitor Access Records · cyberstrikeus
    Maintain visitor access records to the facility where the system resides for [organization-defined];
    0 installs
  79. Pt 6 System Of Records Notice · cyberstrikeus
    For systems that process information that will be maintained in a Privacy Act system of records: Draft system of records notices in accordance with OM
    0 installs
  80. Sa 10 2 Alternative Configuration Management Processes · cyberstrikeus
    Provide an alternate configuration management process using organizational personnel in the absence of a dedicated developer configuration management
    0 installs
  81. Sa 15 5 Attack Surface Reduction · cyberstrikeus
    Require the developer of the system, system component, or system service to reduce attack surfaces to [organization-defined].
    0 installs
  82. Sa 16 Developer Provided Training · cyberstrikeus
    Require the developer of the system, system component, or system service to provide the following training on the correct use and operation of the imp
    0 installs
  83. Sa 18 1 Multiple Phases Of System Development Life Cycle · cyberstrikeus
    Multiple Phases of System Development Life Cycle
    0 installs
  84. Sa 19 2 Configuration Control For Component Service And Repa · cyberstrikeus
    Configuration Control for Component Service and Repair
    0 installs
  85. Sa 24 Design For Cyber Resiliency · cyberstrikeus
    Design organizational systems, system components, or system services to achieve cyber resiliency by: Defining the following cyber resiliency goals: [o
    0 installs
  86. Sa 5 2 Security Relevant External System Interfaces · cyberstrikeus
    Security-relevant External System Interfaces
    0 installs
  87. Sa 8 29 Repeatable And Documented Procedures · cyberstrikeus
    Implement the security design principle of repeatable and documented procedures in [organization-defined].
    0 installs
  88. Sa 8 32 Sufficient Documentation · cyberstrikeus
    Implement the security design principle of sufficient documentation in [organization-defined].
    0 installs
  89. Sc 31 3 Measure Bandwidth In Operational Environments · cyberstrikeus
    Measure the bandwidth of [organization-defined] in the operational environment of the system.
    0 installs
  90. Sc 34 1 No Writable Storage · cyberstrikeus
    Employ [organization-defined] with no writeable storage that is persistent across component restart or power on/off.
    0 installs
  91. Sc 39 1 Hardware Separation · cyberstrikeus
    Implement hardware separation mechanisms to facilitate process isolation.
    0 installs
  92. Sc 45 1 Synchronization With Authoritative Time Source · cyberstrikeus
    Compare the internal system clocks [organization-defined] with [organization-defined] ;
    0 installs
  93. Si 12 Information Management And Retention · cyberstrikeus
    Manage and retain information within the system and information output from the system in accordance with applicable laws, executive orders, directive
    0 installs
  94. Si 19 7 Validated Algorithms And Software · cyberstrikeus
    Perform de-identification using validated algorithms and software that is validated to implement the algorithms.
    0 installs
  95. Si 3 10 Malicious Code Analysis · cyberstrikeus
    Employ the following tools and techniques to analyze the characteristics and behavior of malicious code: [organization-defined] ;
    0 installs
  96. Si 3 5 Portable Storage Devices · cyberstrikeus
    Portable Storage Devices
    0 installs
  97. Si 3 6 Testing And Verification · cyberstrikeus
    Test malicious code protection mechanisms [organization-defined] by introducing known benign code into the system;
    0 installs
  98. Si 4 25 Optimize Network Traffic Analysis · cyberstrikeus
    Provide visibility into network traffic at external and key internal system interfaces to optimize the effectiveness of monitoring devices.
    0 installs
  99. Si 7 17 Runtime Application Self Protection · cyberstrikeus
    Implement [organization-defined] for application self-protection at runtime.
    0 installs
  100. Si 7 4 Tamper Evident Packaging · cyberstrikeus
    Tamper-evident Packaging
    0 installs