← all publishers

cyberstrikeus

@cyberstrikeus source repo

7171 published skills · page 71 of 72

  1. Wstg Authz 05 1 · cyberstrikeus
    Testing OAuth Authorization Server Weaknesses
    0
    installs
  2. Wstg Authz 05 2 · cyberstrikeus
    Testing OAuth Client Weaknesses
    0
    installs
  3. Wstg Auth Session · cyberstrikeus
    WSTG identity, authentication, authorization, and session management testing
    0
    installs
  4. Wstg Recon Config · cyberstrikeus
    WSTG reconnaissance, configuration, error handling, and cryptography testing techniques
    0
    installs
  5. De Ae 01 Deae 01 · cyberstrikeus
    A baseline of network operations and expected data flows for users and systems is established and managed
    0
    installs
  6. De Ae 02 Deae 02 · cyberstrikeus
    Potentially adverse events are analyzed to better understand associated activities
    0
    installs
  7. De Ae 03 Deae 03 · cyberstrikeus
    Information is correlated from multiple sources
    0
    installs
  8. De Ae 04 Deae 04 · cyberstrikeus
    The estimated impact and scope of adverse events are understood
    0
    installs
  9. De Ae 05 Deae 05 · cyberstrikeus
    Incident alert thresholds are established
    0
    installs
  10. De Ae 06 Deae 06 · cyberstrikeus
    Information on adverse events is provided to authorized staff and tools
    0
    installs
  11. De Ae 07 Deae 07 · cyberstrikeus
    Cyber threat intelligence and other contextual information are integrated into the analysis
    0
    installs
  12. De Ae 08 Deae 08 · cyberstrikeus
    Incidents are declared when adverse events meet the defined incident criteria
    0
    installs
  13. De Cm 01 Decm 01 · cyberstrikeus
    Networks and network services are monitored to find potentially adverse events
    0
    installs
  14. De Cm 02 Decm 02 · cyberstrikeus
    The physical environment is monitored to find potentially adverse events
    0
    installs
  15. De Cm 03 Decm 03 · cyberstrikeus
    Personnel activity and technology usage are monitored to find potentially adverse events
    0
    installs
  16. De Cm 04 Decm 04 · cyberstrikeus
    Malicious code is detected
    0
    installs
  17. De Cm 05 Decm 05 · cyberstrikeus
    Unauthorized mobile code is detected
    0
    installs
  18. De Cm 06 Decm 06 · cyberstrikeus
    External service provider activities and services are monitored to find potentially adverse events
    0
    installs
  19. De Cm 07 Decm 07 · cyberstrikeus
    Monitoring for unauthorized personnel, connections, devices, and software is performed
    0
    installs
  20. De Cm 08 Decm 08 · cyberstrikeus
    Vulnerability scans are performed
    0
    installs
  21. De Cm 09 Decm 09 · cyberstrikeus
    Computing hardware and software, runtime environments, and their data are monitored to find potentially adverse events
    0
    installs
  22. De Dp 01 Dedp 01 · cyberstrikeus
    Roles and responsibilities for detection are well defined to ensure accountability
    0
    installs
  23. De Dp 02 Dedp 02 · cyberstrikeus
    Detection activities comply with all applicable requirements
    0
    installs
  24. De Dp 03 Dedp 03 · cyberstrikeus
    Detection processes are tested
    0
    installs
  25. De Dp 04 Dedp 04 · cyberstrikeus
    Event detection information is communicated
    0
    installs
  26. De Dp 05 Dedp 05 · cyberstrikeus
    Detection processes are continuously improved
    0
    installs
  27. Gv Oc 01 Gvoc 01 · cyberstrikeus
    The organizational mission is understood and informs cybersecurity risk management
    0
    installs
  28. Gv Oc 02 Gvoc 02 · cyberstrikeus
    Internal and external stakeholders are understood, and their needs and expectations regarding cybersecurity risk management are understood and conside
    0
    installs
  29. Gv Oc 03 Gvoc 03 · cyberstrikeus
    Legal, regulatory, and contractual requirements regarding cybersecurity - including privacy and civil liberties obligations - are understood and manag
    0
    installs
  30. Gv Oc 04 Gvoc 04 · cyberstrikeus
    Critical objectives, capabilities, and services that external stakeholders depend on or expect from the organization are understood and communicated
    0
    installs
  31. Gv Oc 05 Gvoc 05 · cyberstrikeus
    Outcomes, capabilities, and services that the organization depends on are understood and communicated
    0
    installs
  32. Gv Ov 01 Gvov 01 · cyberstrikeus
    Cybersecurity risk management strategy outcomes are reviewed to inform and adjust strategy and direction
    0
    installs
  33. Gv Ov 02 Gvov 02 · cyberstrikeus
    The cybersecurity risk management strategy is reviewed and adjusted to ensure coverage of organizational requirements and risks
    0
    installs
  34. Gv Ov 03 Gvov 03 · cyberstrikeus
    Organizational cybersecurity risk management performance is evaluated and reviewed for adjustments needed
    0
    installs
  35. Gv Po 01 Gvpo 01 · cyberstrikeus
    Policy for managing cybersecurity risks is established based on organizational context, cybersecurity strategy, and priorities and is communicated and
    0
    installs
  36. Gv Po 02 Gvpo 02 · cyberstrikeus
    Policy for managing cybersecurity risks is reviewed, updated, communicated, and enforced to reflect changes in requirements, threats, technology, and
    0
    installs
  37. Gv Rm 01 Gvrm 01 · cyberstrikeus
    Risk management objectives are established and agreed to by organizational stakeholders
    0
    installs
  38. Gv Rm 02 Gvrm 02 · cyberstrikeus
    Risk appetite and risk tolerance statements are established, communicated, and maintained
    0
    installs
  39. Gv Rm 03 Gvrm 03 · cyberstrikeus
    Cybersecurity risk management activities and outcomes are included in enterprise risk management processes
    0
    installs
  40. Gv Rm 04 Gvrm 04 · cyberstrikeus
    Strategic direction that describes appropriate risk response options is established and communicated
    0
    installs
  41. Gv Rm 05 Gvrm 05 · cyberstrikeus
    Lines of communication across the organization are established for cybersecurity risks, including risks from suppliers and other third parties
    0
    installs
  42. Gv Rm 06 Gvrm 06 · cyberstrikeus
    A standardized method for calculating, documenting, categorizing, and prioritizing cybersecurity risks is established and communicated
    0
    installs
  43. Gv Rm 07 Gvrm 07 · cyberstrikeus
    Strategic opportunities (i.e., positive risks) are characterized and are included in organizational cybersecurity risk discussions
    0
    installs
  44. Gv Rr 01 Gvrr 01 · cyberstrikeus
    Organizational leadership is responsible and accountable for cybersecurity risk and fosters a culture that is risk-aware, ethical, and continually imp
    0
    installs
  45. Gv Rr 02 Gvrr 02 · cyberstrikeus
    Roles, responsibilities, and authorities related to cybersecurity risk management are established, communicated, understood, and enforced
    0
    installs
  46. Gv Rr 03 Gvrr 03 · cyberstrikeus
    Adequate resources are allocated commensurate with the cybersecurity risk strategy, roles, responsibilities, and policies
    0
    installs
  47. Gv Rr 04 Gvrr 04 · cyberstrikeus
    Cybersecurity is included in human resources practices
    0
    installs
  48. Gv Sc 01 Gvsc 01 · cyberstrikeus
    A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational st
    0
    installs
  49. Gv Sc 02 Gvsc 02 · cyberstrikeus
    Cybersecurity roles and responsibilities for suppliers, customers, and partners are established, communicated, and coordinated internally and external
    0
    installs
  50. Gv Sc 03 Gvsc 03 · cyberstrikeus
    Cybersecurity supply chain risk management is integrated into cybersecurity and enterprise risk management, risk assessment, and improvement processes
    0
    installs
  51. Gv Sc 04 Gvsc 04 · cyberstrikeus
    Suppliers are known and prioritized by criticality
    0
    installs
  52. Gv Sc 05 Gvsc 05 · cyberstrikeus
    Requirements to address cybersecurity risks in supply chains are established, prioritized, and integrated into contracts and other types of agreements
    0
    installs
  53. Gv Sc 06 Gvsc 06 · cyberstrikeus
    Planning and due diligence are performed to reduce risks before entering into formal supplier or other third-party relationships
    0
    installs
  54. Gv Sc 07 Gvsc 07 · cyberstrikeus
    The risks posed by a supplier, their products and services, and other third parties are understood, recorded, prioritized, assessed, responded to, and
    0
    installs
  55. Gv Sc 08 Gvsc 08 · cyberstrikeus
    Relevant suppliers and other third parties are included in incident planning, response, and recovery activities
    0
    installs
  56. Gv Sc 09 Gvsc 09 · cyberstrikeus
    Supply chain security practices are integrated into cybersecurity and enterprise risk management programs, and their performance is monitored througho
    0
    installs
  57. Gv Sc 10 Gvsc 10 · cyberstrikeus
    Cybersecurity supply chain risk management plans include provisions for activities that occur after the conclusion of a partnership or service agreeme
    0
    installs
  58. Wstg Logic Client API · cyberstrikeus
    WSTG business logic, client-side, and API security testing
    0
    installs
  59. Pr Aa 01 Praa 01 · cyberstrikeus
    Identities and credentials for authorized users, services, and hardware are managed by the organization
    0
    installs
  60. Pr Aa 02 Praa 02 · cyberstrikeus
    Identities are proofed and bound to credentials based on the context of interactions
    0
    installs
  61. Pr Aa 03 Praa 03 · cyberstrikeus
    Users, services, and hardware are authenticated
    0
    installs
  62. Pr Aa 04 Praa 04 · cyberstrikeus
    Identity assertions are protected, conveyed, and verified
    0
    installs
  63. Pr Aa 05 Praa 05 · cyberstrikeus
    Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least
    0
    installs
  64. Pr Aa 06 Praa 06 · cyberstrikeus
    Physical access to assets is managed, monitored, and enforced commensurate with risk
    0
    installs
  65. Pr Ac 01 Prac 01 · cyberstrikeus
    Identities and credentials are issued, managed, verified, revoked, and audited for authorized devices, users and processes
    0
    installs
  66. Pr Ac 02 Prac 02 · cyberstrikeus
    Physical access to assets is managed and protected
    0
    installs
  67. Pr Ac 03 Prac 03 · cyberstrikeus
    Remote access is managed
    0
    installs
  68. Pr Ac 04 Prac 04 · cyberstrikeus
    Access permissions and authorizations are managed, incorporating the principles of least privilege and separation of duties
    0
    installs
  69. Pr Ac 05 Prac 05 · cyberstrikeus
    Network integrity is protected (e.g., network segregation, network segmentation)
    0
    installs
  70. Pr Ac 06 Prac 06 · cyberstrikeus
    Identities are proofed and bound to credentials and asserted in interactions
    0
    installs
  71. Pr Ac 07 Prac 07 · cyberstrikeus
    Users, devices, and other assets are authenticated (e.g., single-factor, multi-factor) commensurate with the risk of the transaction (e.g., individual
    0
    installs
  72. Pr At 01 Prat 01 · cyberstrikeus
    Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in
    0
    installs
  73. Pr At 02 Prat 02 · cyberstrikeus
    Individuals in specialized roles are provided with awareness and training so that they possess the knowledge and skills to perform relevant tasks with
    0
    installs
  74. Pr At 03 Prat 03 · cyberstrikeus
    Third-party stakeholders (e.g., suppliers, customers, partners) understand their roles and responsibilities
    0
    installs
  75. Pr At 04 Prat 04 · cyberstrikeus
    Senior executives understand their roles and responsibilities
    0
    installs
  76. Pr At 05 Prat 05 · cyberstrikeus
    Physical and cybersecurity personnel understand their roles and responsibilities
    0
    installs
  77. Pr Ds 01 Prds 01 · cyberstrikeus
    The confidentiality, integrity, and availability of data-at-rest are protected
    0
    installs
  78. Pr Ds 02 Prds 02 · cyberstrikeus
    The confidentiality, integrity, and availability of data-in-transit are protected
    0
    installs
  79. Pr Ds 03 Prds 03 · cyberstrikeus
    Assets are formally managed throughout removal, transfers, and disposition
    0
    installs
  80. Pr Ds 04 Prds 04 · cyberstrikeus
    Adequate capacity to ensure availability is maintained
    0
    installs
  81. Pr Ds 05 Prds 05 · cyberstrikeus
    Protections against data leaks are implemented
    0
    installs
  82. Pr Ds 06 Prds 06 · cyberstrikeus
    Integrity checking mechanisms are used to verify software, firmware, and information integrity
    0
    installs
  83. Pr Ds 07 Prds 07 · cyberstrikeus
    The development and testing environment(s) are separate from the production environment
    0
    installs
  84. Pr Ds 08 Prds 08 · cyberstrikeus
    Integrity checking mechanisms are used to verify hardware integrity
    0
    installs
  85. Pr Ds 10 Prds 10 · cyberstrikeus
    The confidentiality, integrity, and availability of data-in-use are protected
    0
    installs
  86. Pr Ds 11 Prds 11 · cyberstrikeus
    Backups of data are created, protected, maintained, and tested
    0
    installs
  87. Pr Ip 01 Prip 01 · cyberstrikeus
    A baseline configuration of information technology/industrial control systems is created and maintained incorporating security principles (e.g.
    0
    installs
  88. Pr Ip 02 Prip 02 · cyberstrikeus
    A System Development Life Cycle to manage systems is implemented
    0
    installs
  89. Pr Ip 03 Prip 03 · cyberstrikeus
    Configuration change control processes are in place
    0
    installs
  90. Pr Ip 04 Prip 04 · cyberstrikeus
    Backups of information are conducted, maintained, and tested
    0
    installs
  91. Pr Ip 05 Prip 05 · cyberstrikeus
    Policy and regulations regarding the physical operating environment for organizational assets are met
    0
    installs
  92. Pr Ip 06 Prip 06 · cyberstrikeus
    Data is destroyed according to policy
    0
    installs
  93. Pr Ip 07 Prip 07 · cyberstrikeus
    Protection processes are improved
    0
    installs
  94. Pr Ip 08 Prip 08 · cyberstrikeus
    Effectiveness of protection technologies is shared
    0
    installs
  95. Pr Ip 09 Prip 09 · cyberstrikeus
    Response plans (Incident Response and Business Continuity) and recovery plans (Incident Recovery and Disaster Recovery) are in place and managed
    0
    installs
  96. Pr Ip 10 Prip 10 · cyberstrikeus
    Response and recovery plans are tested
    0
    installs
  97. Pr Ip 11 Prip 11 · cyberstrikeus
    Cybersecurity is included in human resources practices (e.g., deprovisioning, personnel screening)
    0
    installs
  98. Pr Ip 12 Prip 12 · cyberstrikeus
    A vulnerability management plan is developed and implemented
    0
    installs
  99. Pr Ir 01 Prir 01 · cyberstrikeus
    Networks and environments are protected from unauthorized logical access and usage
    0
    installs
  100. Pr Ir 02 Prir 02 · cyberstrikeus
    The organization's technology assets are protected from environmental threats
    0
    installs