cyberstrikeus
- 7.2k skills
- 0 followers
- 1 day ago last updated
- ▌ Si 7 6 Cryptographic Protection · cyberstrikeusImplement cryptographic mechanisms to detect unauthorized changes to software, firmware, and information.
- ▌ Sr 9 Tamper Resistance And Detection · cyberstrikeusImplement a tamper protection program for the system, system component, or system service.
- ▌ Cis Docker V160 1 1 10 · cyberstrikeusEnsure auditing is configured for Docker files and directories - /etc/default/docker
- ▌ Cis Docker V160 1 1 11 · cyberstrikeusEnsure auditing is configured for Docker files and directories - /etc/docker/daemon.json
- ▌ Cis Docker V160 1 1 12 · cyberstrikeusEnsure auditing is configured for Docker files and directories - /etc/containerd/config.toml
- ▌ Cis Docker V160 1 1 13 · cyberstrikeusEnsure auditing is configured for Docker files and directories - /etc/sysconfig/docker
- ▌ Cis Docker V160 1 1 14 · cyberstrikeusEnsure auditing is configured for Docker files and directories - /usr/bin/containerd
- ▌ Cis Docker V160 1 1 15 · cyberstrikeusEnsure auditing is configured for Docker files and directories - /usr/bin/containerd-shim
- ▌ Cis Docker V160 1 1 16 · cyberstrikeusEnsure auditing is configured for Docker files and directories - /usr/bin/containerd-shim-runc-v1
- ▌ Cis Docker V160 1 1 17 · cyberstrikeusEnsure auditing is configured for Docker files and directories - /usr/bin/containerd-shim-runc-v2
- ▌ Cis Docker V160 1 1 18 · cyberstrikeusEnsure auditing is configured for Docker files and directories - /usr/bin/runc
- ▌ Cis Docker V170 1 1 10 · cyberstrikeusEnsure auditing is configured for Docker files and directories - /etc/default/docker
- ▌ Cis Docker V170 1 1 11 · cyberstrikeusEnsure auditing is configured for Docker files and directories - /etc/docker/daemon.json
- ▌ Cis Docker V170 1 1 12 · cyberstrikeusEnsure auditing is configured for Docker files and directories - /etc/containerd/config.toml
- ▌ Cis Docker V170 1 1 13 · cyberstrikeusEnsure auditing is configured for Docker files and directories - /etc/sysconfig/docker
- ▌ Cis Docker V170 1 1 14 · cyberstrikeusEnsure auditing is configured for Docker files and directories - /usr/bin/containerd
- ▌ Cis Docker V170 1 1 15 · cyberstrikeusEnsure auditing is configured for Docker files and directories - /usr/bin/containerd-shim
- ▌ Cis Docker V170 1 1 16 · cyberstrikeusEnsure auditing is configured for Docker files and directories - /usr/bin/containerd-shim-runc-v1
- ▌ Cis Docker V170 1 1 17 · cyberstrikeusEnsure auditing is configured for Docker files and directories - /usr/bin/containerd-shim-runc-v2
- ▌ Cis Docker V170 1 1 18 · cyberstrikeusEnsure auditing is configured for Docker files and directories - /usr/bin/runc
- ▌ Role Based Training 03 02 02 Role Based Training · cyberstrikeusProvide role-based security training to organizational personnel: Before authorizing access to the system or CUI, before performing assigned duties, a
- ▌ Protection Of Audit Information 03 03 08 Protection Of Audit · cyberstrikeusProtect audit information and audit logging tools from unauthorized access, modification, and deletion.
- ▌ Configuration Change Control 03 04 03 Configuration Change C · cyberstrikeusDefine the types of changes to the system that are configuration-controlled.
- ▌ Ca 3 1 Unclassified National Security System Connections · cyberstrikeusUnclassified National Security System Connections
- ▌ Ia 12 4 In Person Validation And Verification · cyberstrikeusRequire that the validation and verification of identity evidence be conducted in person before a designated registration authority.
- ▌ Ia 13 2 Verification Of Identity Assertions And Access Token · cyberstrikeusThe source and integrity of identity assertions and access tokens are verified before granting access to system and information resources.
- ▌ Ia 2 8 Access To Accounts Replay Resistant · cyberstrikeusImplement replay-resistant authentication mechanisms for access to [organization-defined].
- ▌ Ia 4 9 Attribute Maintenance And Protection · cyberstrikeusMaintain the attributes for each uniquely identified individual, device, or service in [organization-defined].
- ▌
- ▌ Ia 5 12 Biometric Authentication Performance · cyberstrikeusFor biometric-based authentication, employ mechanisms that satisfy the following biometric quality requirements [organization-defined].
- ▌ Ia 5 8 Multiple System Accounts · cyberstrikeusImplement [organization-defined] to manage the risk of compromise due to individuals having accounts on multiple systems.
- ▌ Pe 14 Environmental Controls · cyberstrikeusMaintain [organization-defined] levels within the facility where the system resides at [organization-defined] ;
- ▌ Pe 3 Physical Access Control · cyberstrikeusEnforce physical access authorizations at [organization-defined] by: Verifying individual access authorizations before granting access to the facility
- ▌ Pe 3 2 Facility And Systems · cyberstrikeusPerform security checks [organization-defined] at the physical perimeter of the facility or system for exfiltration of information or removal of syste
- ▌ Pt 5 2 Privacy Act Statements · cyberstrikeusInclude Privacy Act statements on forms that collect information that will be maintained in a Privacy Act system of records, or provide Privacy Act st
- ▌
- ▌
- ▌ Sa 3 System Development Life Cycle · cyberstrikeusAcquire, develop, and manage the system using [organization-defined] that incorporates information security and privacy considerations;
- ▌
- ▌ Sa 9 2 Identification Of Functions Ports Protocols And Servi · cyberstrikeusRequire providers of the following external system services to identify the functions, ports, protocols, and other services required for the use of su
- ▌ Sc 31 Covert Channel Analysis · cyberstrikeusPerform a covert channel analysis to identify those aspects of communications within the system that are potential avenues for covert [organization...
- ▌ Sc 35 External Malicious Code Identification · cyberstrikeusInclude system components that proactively seek to identify network-based malicious code or malicious websites.
- ▌ Sc 42 4 Notice Of Collection · cyberstrikeusEmploy the following measures to facilitate an individual’s awareness that personally identifiable information is being collected by [organization-def
- ▌ Sc 7 20 Dynamic Isolation And Segregation · cyberstrikeusProvide the capability to dynamically isolate [organization-defined] from other system components.
- ▌
- ▌ Si 4 13 Analyze Traffic And Event Patterns · cyberstrikeusAnalyze communications traffic and event patterns for the system;
- ▌ Si 4 24 Indicators Of Compromise · cyberstrikeusDiscover, collect, and distribute to [organization-defined] , indicators of compromise provided by [organization-defined].
- ▌ T1070 001 Clear Windows Event Logs · cyberstrikeusAdversaries may clear Windows Event Logs to hide the activity of an intrusion.
- ▌ T1134 001 Token Impersonationtheft · cyberstrikeusAdversaries may duplicate then impersonate another user's existing token to escalate privileges and bypass access controls.
- ▌ T1216 002 Syncappvpublishingserver · cyberstrikeusAdversaries may abuse SyncAppvPublishingServer.vbs to proxy execution of malicious PowerShell commands.
- ▌ T1550 Use Alternate Authentication Material · cyberstrikeusAdversaries may use alternate authentication material, such as password hashes, Kerberos tickets, and application access tokens, in order to move laterally within an environment and bypass normal s...
- ▌ T1550 001 Application Access Token · cyberstrikeusAdversaries may use stolen application access tokens to bypass the typical authentication process and access restricted accounts, information, or services on remote systems.
- ▌ T1553 004 Install Root Certificate · cyberstrikeusAdversaries may install a root certificate on a compromised system to avoid warnings when connecting to adversary controlled web servers.
- ▌ T1562 004 Disable Or Modify System Firewall · cyberstrikeusAdversaries may disable or modify system firewalls in order to bypass controls limiting network usage.
- ▌ T1021 001 Remote Desktop Protocol · cyberstrikeusAdversaries may use Valid Accounts to log into a computer using the Remote Desktop Protocol (RDP).
- ▌ T1021 002 Smbwindows Admin Shares · cyberstrikeusAdversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).
- ▌ T1011 Exfiltration Over Other Network Medium · cyberstrikeusAdversaries may attempt to exfiltrate data over a different network medium than the command and control channel.
- ▌ T1011 001 Exfiltration Over Bluetooth · cyberstrikeusAdversaries may attempt to exfiltrate data over Bluetooth rather than the command and control channel.
- ▌ T1048 001 Exfiltration Over Symmetric Encrypted Non C2 Proto · cyberstrikeusAdversaries may steal data by exfiltrating it over a symmetrically encrypted network protocol other than that of the existing command and control channel.
- ▌ T1591 Gather Victim Org Information · cyberstrikeusAdversaries may gather information about the victim's organization that can be used during targeting.
- ▌ Separation Of Duties 03 01 04 Separation Of Duties · cyberstrikeusIdentify the duties of individuals requiring separation.
- ▌ Rules Of Behavior 03 15 03 Rules Of Behavior · cyberstrikeusEstablish rules that describe the responsibilities and expected behavior for system usage and protecting CUI.
- ▌ Protect All Forms Of Code From Unauthorized Access And Tampe · cyberstrikeusHelp prevent unauthorized changes to code, both inadvertent and intentional, which could circumvent or negate the intended security characteristics...
- ▌ Ac 17 7 Additional Protection For Security Function Access · cyberstrikeusAdditional Protection for Security Function Access
- ▌
- ▌ Ac 20 1 Limits On Authorized Use · cyberstrikeusPermit authorized individuals to use an external system to access the system or to process, store, or transmit organization-controlled information onl
- ▌ Ac 22 Publicly Accessible Content · cyberstrikeusDesignate individuals authorized to make information publicly accessible;
- ▌ Ac 3 7 Role Based Access Control · cyberstrikeusEnforce a role-based access control policy over defined subjects and objects and control access based upon [organization-defined].
- ▌ Ac 4 Information Flow Enforcement · cyberstrikeusEnforce approved authorizations for controlling the flow of information within the system and between connected systems based on [organization-defined
- ▌ Ac 4 13 Decomposition Into Policy Relevant Subcomponents · cyberstrikeusWhen transferring information between different security domains, decompose information into [organization-defined] for submission to policy enforceme
- ▌ Ac 4 15 Detection Of Unsanctioned Information · cyberstrikeusWhen transferring information between different security domains, examine the information for the presence of [organization-defined] and prohibit the
- ▌ Ac 6 7 Review Of User Privileges · cyberstrikeusReview [organization-defined] the privileges assigned to [organization-defined] to validate the need for such privileges;
- ▌ Cm 14 Signed Components · cyberstrikeusPrevent the installation of [organization-defined] without verification that the component has been digitally signed using a certificate that is recog
- ▌ Cm 7 1 Periodic Review · cyberstrikeusReview the system [organization-defined] to identify unnecessary and/or nonsecure functions, ports, protocols, software, and services;
- ▌ Cp 6 Alternate Storage Site · cyberstrikeusEstablish an alternate storage site, including necessary agreements to permit the storage and retrieval of system backup information;
- ▌ Cp 7 3 Priority Of Service · cyberstrikeusDevelop alternate processing site agreements that contain priority-of-service provisions in accordance with availability requirements (including recov
- ▌ Cp 7 4 Preparation For Use · cyberstrikeusPrepare the alternate processing site so that the site can serve as the operational site supporting essential mission and business functions.
- ▌ Ir 3 Incident Response Testing · cyberstrikeusTest the effectiveness of the incident response capability for the system [organization-defined] using the following tests: [organization-defined].
- ▌ Ir 3 3 Continuous Improvement · cyberstrikeusUse qualitative and quantitative data from testing to: Determine the effectiveness of incident response processes; Continuously improve incident respo
- ▌ Ir 5 1 Automated Tracking Data Collection And Analysis · cyberstrikeusTrack incidents and collect and analyze incident information using [organization-defined].
- ▌ Ma 3 3 Prevent Unauthorized Removal · cyberstrikeusPrevent the removal of maintenance equipment containing organizational information by: Verifying that there is no organizational information contained
- ▌ Ma 3 6 Software Updates And Patches · cyberstrikeusInspect maintenance tools to ensure the latest software updates and patches are installed.
- ▌
- ▌ Pl 8 Security And Privacy Architectures · cyberstrikeusDevelop security and privacy architectures for the system that: Describe the requirements and approach to be taken for protecting the confidentiality,
- ▌ Pm 22 Personally Identifiable Information Quality Management · cyberstrikeusDevelop and document organization-wide policies and procedures for: Reviewing for the accuracy, relevance, timeliness, and completeness of personally
- ▌ Pm 29 Risk Management Program Leadership Roles · cyberstrikeusAppoint a Senior Accountable Official for Risk Management to align organizational information security and privacy management processes with strate...
- ▌ Pm 9 Risk Management Strategy · cyberstrikeusDevelops a comprehensive strategy to manage: Security risk to organizational operations and assets, individuals, other organizations, and the Nation a
- ▌ Ps 3 2 Formal Indoctrination · cyberstrikeusVerify that individuals accessing a system processing, storing, or transmitting types of classified information that require formal indoctrination, ar
- ▌ Pt 4 Consent · cyberstrikeusImplement [organization-defined] for individuals to consent to the processing of their personally identifiable information prior to its collection tha
- ▌ Ra 3 3 Dynamic Threat Awareness · cyberstrikeusDetermine the current cyber threat environment on an ongoing basis using [organization-defined].
- ▌ Ra 5 4 Discoverable Information · cyberstrikeusDetermine information about the system that is discoverable and take [organization-defined].
- ▌ Ra 5 6 Automated Trend Analyses · cyberstrikeusCompare the results of multiple vulnerability scans using [organization-defined].
- ▌ T0883 Internet Accessible Device · cyberstrikeusAdversaries may gain access into industrial environments through systems exposed directly to the internet for remote access rather than through External Remote Services.
- ▌ T1474 Supply Chain Compromise · cyberstrikeusAdversaries may manipulate products or product delivery mechanisms prior to receipt by a final consumer for the purpose of data or system compromise.
- ▌ T1474 001 Compromise Software Dependencies And Development T · cyberstrikeusAdversaries may manipulate products or product delivery mechanisms prior to receipt by a final consumer for the purpose of data or system compromise.
- ▌ T1541 Foreground Persistence · cyberstrikeusAdversaries may abuse Android's `startForeground()` API method to maintain continuous sensor access.
- ▌ T1632 Subvert Trust Controls · cyberstrikeusAdversaries may undermine security controls that will either warn users of untrusted activity or prevent execution of untrusted applications.
- ▌ T1420 File And Directory Discovery · cyberstrikeusAdversaries may enumerate files and directories or search in specific device locations for desired information within a filesystem.
- ▌ T1422 System Network Configuration Discovery · cyberstrikeusAdversaries may look for details about the network configuration and settings, such as IP and/or MAC addresses, of devices they access or through information discovery of remote systems.
- ▌ T1426 System Information Discovery · cyberstrikeusAdversaries may attempt to get detailed information about a device’s operating system and hardware, including versions, patches, and architecture.