cyberstrikeus
- 7.2k skills
- 0 followers
- 22 hours ago last updated
- ▌
- ▌
- ▌ Wstg Auth Session · cyberstrikeusWSTG identity, authentication, authorization, and session management testing
- ▌ Wstg Recon Config · cyberstrikeusWSTG reconnaissance, configuration, error handling, and cryptography testing techniques
- ▌ De Ae 01 Deae 01 · cyberstrikeusA baseline of network operations and expected data flows for users and systems is established and managed
- ▌ De Ae 02 Deae 02 · cyberstrikeusPotentially adverse events are analyzed to better understand associated activities
- ▌
- ▌
- ▌
- ▌ De Ae 06 Deae 06 · cyberstrikeusInformation on adverse events is provided to authorized staff and tools
- ▌ De Ae 07 Deae 07 · cyberstrikeusCyber threat intelligence and other contextual information are integrated into the analysis
- ▌ De Ae 08 Deae 08 · cyberstrikeusIncidents are declared when adverse events meet the defined incident criteria
- ▌ De Cm 01 Decm 01 · cyberstrikeusNetworks and network services are monitored to find potentially adverse events
- ▌ De Cm 02 Decm 02 · cyberstrikeusThe physical environment is monitored to find potentially adverse events
- ▌ De Cm 03 Decm 03 · cyberstrikeusPersonnel activity and technology usage are monitored to find potentially adverse events
- ▌
- ▌
- ▌ De Cm 06 Decm 06 · cyberstrikeusExternal service provider activities and services are monitored to find potentially adverse events
- ▌ De Cm 07 Decm 07 · cyberstrikeusMonitoring for unauthorized personnel, connections, devices, and software is performed
- ▌
- ▌ De Cm 09 Decm 09 · cyberstrikeusComputing hardware and software, runtime environments, and their data are monitored to find potentially adverse events
- ▌ De Dp 01 Dedp 01 · cyberstrikeusRoles and responsibilities for detection are well defined to ensure accountability
- ▌
- ▌
- ▌
- ▌
- ▌ Gv Oc 01 Gvoc 01 · cyberstrikeusThe organizational mission is understood and informs cybersecurity risk management
- ▌ Gv Oc 02 Gvoc 02 · cyberstrikeusInternal and external stakeholders are understood, and their needs and expectations regarding cybersecurity risk management are understood and conside
- ▌ Gv Oc 03 Gvoc 03 · cyberstrikeusLegal, regulatory, and contractual requirements regarding cybersecurity - including privacy and civil liberties obligations - are understood and manag
- ▌ Gv Oc 04 Gvoc 04 · cyberstrikeusCritical objectives, capabilities, and services that external stakeholders depend on or expect from the organization are understood and communicated
- ▌ Gv Oc 05 Gvoc 05 · cyberstrikeusOutcomes, capabilities, and services that the organization depends on are understood and communicated
- ▌ Gv Ov 01 Gvov 01 · cyberstrikeusCybersecurity risk management strategy outcomes are reviewed to inform and adjust strategy and direction
- ▌ Gv Ov 02 Gvov 02 · cyberstrikeusThe cybersecurity risk management strategy is reviewed and adjusted to ensure coverage of organizational requirements and risks
- ▌ Gv Ov 03 Gvov 03 · cyberstrikeusOrganizational cybersecurity risk management performance is evaluated and reviewed for adjustments needed
- ▌ Gv Po 01 Gvpo 01 · cyberstrikeusPolicy for managing cybersecurity risks is established based on organizational context, cybersecurity strategy, and priorities and is communicated and
- ▌ Gv Po 02 Gvpo 02 · cyberstrikeusPolicy for managing cybersecurity risks is reviewed, updated, communicated, and enforced to reflect changes in requirements, threats, technology, and
- ▌ Gv Rm 01 Gvrm 01 · cyberstrikeusRisk management objectives are established and agreed to by organizational stakeholders
- ▌ Gv Rm 02 Gvrm 02 · cyberstrikeusRisk appetite and risk tolerance statements are established, communicated, and maintained
- ▌ Gv Rm 03 Gvrm 03 · cyberstrikeusCybersecurity risk management activities and outcomes are included in enterprise risk management processes
- ▌ Gv Rm 04 Gvrm 04 · cyberstrikeusStrategic direction that describes appropriate risk response options is established and communicated
- ▌ Gv Rm 05 Gvrm 05 · cyberstrikeusLines of communication across the organization are established for cybersecurity risks, including risks from suppliers and other third parties
- ▌ Gv Rm 06 Gvrm 06 · cyberstrikeusA standardized method for calculating, documenting, categorizing, and prioritizing cybersecurity risks is established and communicated
- ▌ Gv Rm 07 Gvrm 07 · cyberstrikeusStrategic opportunities (i.e., positive risks) are characterized and are included in organizational cybersecurity risk discussions
- ▌ Gv Rr 01 Gvrr 01 · cyberstrikeusOrganizational leadership is responsible and accountable for cybersecurity risk and fosters a culture that is risk-aware, ethical, and continually imp
- ▌ Gv Rr 02 Gvrr 02 · cyberstrikeusRoles, responsibilities, and authorities related to cybersecurity risk management are established, communicated, understood, and enforced
- ▌ Gv Rr 03 Gvrr 03 · cyberstrikeusAdequate resources are allocated commensurate with the cybersecurity risk strategy, roles, responsibilities, and policies
- ▌
- ▌ Gv Sc 01 Gvsc 01 · cyberstrikeusA cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational st
- ▌ Gv Sc 02 Gvsc 02 · cyberstrikeusCybersecurity roles and responsibilities for suppliers, customers, and partners are established, communicated, and coordinated internally and external
- ▌ Gv Sc 03 Gvsc 03 · cyberstrikeusCybersecurity supply chain risk management is integrated into cybersecurity and enterprise risk management, risk assessment, and improvement processes
- ▌
- ▌ Gv Sc 05 Gvsc 05 · cyberstrikeusRequirements to address cybersecurity risks in supply chains are established, prioritized, and integrated into contracts and other types of agreements
- ▌ Gv Sc 06 Gvsc 06 · cyberstrikeusPlanning and due diligence are performed to reduce risks before entering into formal supplier or other third-party relationships
- ▌ Gv Sc 07 Gvsc 07 · cyberstrikeusThe risks posed by a supplier, their products and services, and other third parties are understood, recorded, prioritized, assessed, responded to, and
- ▌ Gv Sc 08 Gvsc 08 · cyberstrikeusRelevant suppliers and other third parties are included in incident planning, response, and recovery activities
- ▌ Gv Sc 09 Gvsc 09 · cyberstrikeusSupply chain security practices are integrated into cybersecurity and enterprise risk management programs, and their performance is monitored througho
- ▌ Gv Sc 10 Gvsc 10 · cyberstrikeusCybersecurity supply chain risk management plans include provisions for activities that occur after the conclusion of a partnership or service agreeme
- ▌
- ▌ Pr Aa 01 Praa 01 · cyberstrikeusIdentities and credentials for authorized users, services, and hardware are managed by the organization
- ▌ Pr Aa 02 Praa 02 · cyberstrikeusIdentities are proofed and bound to credentials based on the context of interactions
- ▌
- ▌
- ▌ Pr Aa 05 Praa 05 · cyberstrikeusAccess permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least
- ▌ Pr Aa 06 Praa 06 · cyberstrikeusPhysical access to assets is managed, monitored, and enforced commensurate with risk
- ▌ Pr Ac 01 Prac 01 · cyberstrikeusIdentities and credentials are issued, managed, verified, revoked, and audited for authorized devices, users and processes
- ▌
- ▌
- ▌ Pr Ac 04 Prac 04 · cyberstrikeusAccess permissions and authorizations are managed, incorporating the principles of least privilege and separation of duties
- ▌ Pr Ac 05 Prac 05 · cyberstrikeusNetwork integrity is protected (e.g., network segregation, network segmentation)
- ▌ Pr Ac 06 Prac 06 · cyberstrikeusIdentities are proofed and bound to credentials and asserted in interactions
- ▌ Pr Ac 07 Prac 07 · cyberstrikeusUsers, devices, and other assets are authenticated (e.g., single-factor, multi-factor) commensurate with the risk of the transaction (e.g., individual
- ▌ Pr At 01 Prat 01 · cyberstrikeusPersonnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in
- ▌ Pr At 02 Prat 02 · cyberstrikeusIndividuals in specialized roles are provided with awareness and training so that they possess the knowledge and skills to perform relevant tasks with
- ▌ Pr At 03 Prat 03 · cyberstrikeusThird-party stakeholders (e.g., suppliers, customers, partners) understand their roles and responsibilities
- ▌
- ▌ Pr At 05 Prat 05 · cyberstrikeusPhysical and cybersecurity personnel understand their roles and responsibilities
- ▌ Pr Ds 01 Prds 01 · cyberstrikeusThe confidentiality, integrity, and availability of data-at-rest are protected
- ▌ Pr Ds 02 Prds 02 · cyberstrikeusThe confidentiality, integrity, and availability of data-in-transit are protected
- ▌ Pr Ds 03 Prds 03 · cyberstrikeusAssets are formally managed throughout removal, transfers, and disposition
- ▌
- ▌
- ▌ Pr Ds 06 Prds 06 · cyberstrikeusIntegrity checking mechanisms are used to verify software, firmware, and information integrity
- ▌ Pr Ds 07 Prds 07 · cyberstrikeusThe development and testing environment(s) are separate from the production environment
- ▌ Pr Ds 08 Prds 08 · cyberstrikeusIntegrity checking mechanisms are used to verify hardware integrity
- ▌ Pr Ds 10 Prds 10 · cyberstrikeusThe confidentiality, integrity, and availability of data-in-use are protected
- ▌
- ▌ Pr Ip 01 Prip 01 · cyberstrikeusA baseline configuration of information technology/industrial control systems is created and maintained incorporating security principles (e.g.
- ▌
- ▌
- ▌
- ▌ Pr Ip 05 Prip 05 · cyberstrikeusPolicy and regulations regarding the physical operating environment for organizational assets are met
- ▌
- ▌
- ▌
- ▌ Pr Ip 09 Prip 09 · cyberstrikeusResponse plans (Incident Response and Business Continuity) and recovery plans (Incident Recovery and Disaster Recovery) are in place and managed
- ▌
- ▌ Pr Ip 11 Prip 11 · cyberstrikeusCybersecurity is included in human resources practices (e.g., deprovisioning, personnel screening)
- ▌
- ▌ Pr Ir 01 Prir 01 · cyberstrikeusNetworks and environments are protected from unauthorized logical access and usage
- ▌ Pr Ir 02 Prir 02 · cyberstrikeusThe organization's technology assets are protected from environmental threats