← all publishers

cyberstrikeus

@cyberstrikeus source repo

7171 published skills · page 72 of 72

  1. Pr Ir 03 Prir 03 · cyberstrikeus
    Mechanisms are implemented to achieve resilience requirements in normal and adverse situations
    0
    installs
  2. Pr Ir 04 Prir 04 · cyberstrikeus
    Adequate resource capacity to ensure availability is maintained
    0
    installs
  3. Pr Ma 01 Prma 01 · cyberstrikeus
    Maintenance and repair of organizational assets are performed and logged, with approved and controlled tools
    0
    installs
  4. Pr Ma 02 Prma 02 · cyberstrikeus
    Remote maintenance of organizational assets is approved, logged, and performed in a manner that prevents unauthorized access
    0
    installs
  5. Pr Ps 01 Prps 01 · cyberstrikeus
    Configuration management practices are established and applied
    0
    installs
  6. Pr Ps 02 Prps 02 · cyberstrikeus
    Software is maintained, replaced, and removed commensurate with risk
    0
    installs
  7. Pr Ps 03 Prps 03 · cyberstrikeus
    Hardware is maintained, replaced, and removed commensurate with risk
    0
    installs
  8. Pr Ps 04 Prps 04 · cyberstrikeus
    Log records are generated and made available for continuous monitoring
    0
    installs
  9. Pr Ps 05 Prps 05 · cyberstrikeus
    Installation and execution of unauthorized software are prevented
    0
    installs
  10. Pr Ps 06 Prps 06 · cyberstrikeus
    Secure software development practices are integrated, and their performance is monitored throughout the software development life cycle
    0
    installs
  11. Pr Pt 01 Prpt 01 · cyberstrikeus
    Audit/log records are determined, documented, implemented, and reviewed in accordance with policy
    0
    installs
  12. Pr Pt 02 Prpt 02 · cyberstrikeus
    Removable media is protected and its use restricted according to policy
    0
    installs
  13. Pr Pt 03 Prpt 03 · cyberstrikeus
    The principle of least functionality is incorporated by configuring systems to provide only essential capabilities
    0
    installs
  14. Pr Pt 04 Prpt 04 · cyberstrikeus
    Communications and control networks are protected
    0
    installs
  15. Pr Pt 05 Prpt 05 · cyberstrikeus
    Mechanisms (e.g., failsafe, load balancing, hot swap) are implemented to achieve resilience requirements in normal and adverse situations
    0
    installs
  16. Rc Co 01 Rcco 01 · cyberstrikeus
    Public relations are managed
    0
    installs
  17. Rc Co 02 Rcco 02 · cyberstrikeus
    Reputation is repaired after an incident
    0
    installs
  18. Rc Co 03 Rcco 03 · cyberstrikeus
    Recovery activities and progress in restoring operational capabilities are communicated to designated internal and external stakeholders
    0
    installs
  19. Rc Co 04 Rcco 04 · cyberstrikeus
    Public updates on incident recovery are shared using approved methods and messaging
    0
    installs
  20. Rc Im 01 Rcim 01 · cyberstrikeus
    Recovery plans incorporate lessons learned
    0
    installs
  21. Rc Im 02 Rcim 02 · cyberstrikeus
    Recovery strategies are updated
    0
    installs
  22. Rc Rp 01 Rcrp 01 · cyberstrikeus
    The recovery portion of the incident response plan is executed once initiated from the incident response process
    0
    installs
  23. Rc Rp 02 Rcrp 02 · cyberstrikeus
    Recovery actions are selected, scoped, prioritized, and performed
    0
    installs
  24. Rc Rp 03 Rcrp 03 · cyberstrikeus
    The integrity of backups and other restoration assets is verified before using them for restoration
    0
    installs
  25. Rc Rp 04 Rcrp 04 · cyberstrikeus
    Critical mission functions and cybersecurity risk management are considered to establish post-incident operational norms
    0
    installs
  26. Rc Rp 05 Rcrp 05 · cyberstrikeus
    The integrity of restored assets is verified, systems and services are restored, and normal operating status is confirmed
    0
    installs
  27. Rc Rp 06 Rcrp 06 · cyberstrikeus
    The end of incident recovery is declared based on criteria, and incident-related documentation is completed
    0
    installs
  28. Rs An 01 Rsan 01 · cyberstrikeus
    Notifications from detection systems are investigated
    0
    installs
  29. Rs An 02 Rsan 02 · cyberstrikeus
    The impact of the incident is understood
    0
    installs
  30. Rs An 03 Rsan 03 · cyberstrikeus
    Analysis is performed to establish what has taken place during an incident and the root cause of the incident
    0
    installs
  31. Rs An 04 Rsan 04 · cyberstrikeus
    Incidents are categorized consistent with response plans
    0
    installs
  32. Rs An 05 Rsan 05 · cyberstrikeus
    Processes are established to receive, analyze and respond to vulnerabilities disclosed to the organization from internal and external sources (e.g.
    0
    installs
  33. Rs An 06 Rsan 06 · cyberstrikeus
    Actions performed during an investigation are recorded, and the records' integrity and provenance are preserved
    0
    installs
  34. Rs An 07 Rsan 07 · cyberstrikeus
    Incident data and metadata are collected, and their integrity and provenance are preserved
    0
    installs
  35. Rs An 08 Rsan 08 · cyberstrikeus
    An incident's magnitude is estimated and validated
    0
    installs
  36. Rs Co 01 Rsco 01 · cyberstrikeus
    Personnel know their roles and order of operations when a response is needed
    0
    installs
  37. Rs Co 02 Rsco 02 · cyberstrikeus
    Internal and external stakeholders are notified of incidents
    0
    installs
  38. Rs Co 03 Rsco 03 · cyberstrikeus
    Information is shared with designated internal and external stakeholders
    0
    installs
  39. Rs Co 04 Rsco 04 · cyberstrikeus
    Coordination with stakeholders occurs consistent with response plans
    0
    installs
  40. Rs Co 05 Rsco 05 · cyberstrikeus
    Voluntary information sharing occurs with external stakeholders to achieve broader cybersecurity situational awareness
    0
    installs
  41. Rs Im 01 Rsim 01 · cyberstrikeus
    Response plans incorporate lessons learned
    0
    installs
  42. Rs Im 02 Rsim 02 · cyberstrikeus
    Response strategies are updated
    0
    installs
  43. Rs Ma 01 Rsma 01 · cyberstrikeus
    The incident response plan is executed in coordination with relevant third parties once an incident is declared
    0
    installs
  44. Rs Ma 02 Rsma 02 · cyberstrikeus
    Incident reports are triaged and validated
    0
    installs
  45. Rs Ma 03 Rsma 03 · cyberstrikeus
    Incidents are categorized and prioritized
    0
    installs
  46. Rs Ma 04 Rsma 04 · cyberstrikeus
    Incidents are escalated or elevated as needed
    0
    installs
  47. Rs Ma 05 Rsma 05 · cyberstrikeus
    The criteria for initiating incident recovery are applied
    0
    installs
  48. Rs Mi 01 Rsmi 01 · cyberstrikeus
    Incidents are contained
    0
    installs
  49. Rs Mi 02 Rsmi 02 · cyberstrikeus
    Incidents are eradicated
    0
    installs
  50. Rs Mi 03 Rsmi 03 · cyberstrikeus
    Newly identified vulnerabilities are mitigated or documented as accepted risks
    0
    installs
  51. Rs Rp 01 Rsrp 01 · cyberstrikeus
    Response plan is executed during or after an incident
    0
    installs
  52. T1053 002 At · cyberstrikeus
    Adversaries may abuse the at utility to perform task scheduling for initial or recurring execution of malicious code.
    0
    installs
  53. T1561 Disk Wipe · cyberstrikeus
    Adversaries may wipe or corrupt raw disk data on specific systems or in large numbers in a network to interrupt availability to system and network resources.
    0
    installs
  54. Id Am 01 Idam 01 · cyberstrikeus
    Inventories of hardware managed by the organization are maintained
    0
    installs
  55. Id Am 02 Idam 02 · cyberstrikeus
    Inventories of software, services, and systems managed by the organization are maintained
    0
    installs
  56. Id Am 03 Idam 03 · cyberstrikeus
    Representations of the organization's authorized network communication and internal and external network data flows are maintained
    0
    installs
  57. Id Am 04 Idam 04 · cyberstrikeus
    Inventories of services provided by suppliers are maintained
    0
    installs
  58. Id Am 05 Idam 05 · cyberstrikeus
    Assets are prioritized based on classification, criticality, resources, and impact on the mission
    0
    installs
  59. Id Am 06 Idam 06 · cyberstrikeus
    Cybersecurity roles and responsibilities for the entire workforce and third-party stakeholders (e.g., suppliers, customers, partners) are established
    0
    installs
  60. Id Am 07 Idam 07 · cyberstrikeus
    Inventories of data and corresponding metadata for designated data types are maintained
    0
    installs
  61. Id Am 08 Idam 08 · cyberstrikeus
    Systems, hardware, software, services, and data are managed throughout their life cycles
    0
    installs
  62. Id Be 01 Idbe 01 · cyberstrikeus
    The organization’s role in the supply chain is identified and communicated
    0
    installs
  63. Id Be 02 Idbe 02 · cyberstrikeus
    The organization’s place in critical infrastructure and its industry sector is identified and communicated
    0
    installs
  64. Id Be 03 Idbe 03 · cyberstrikeus
    Priorities for organizational mission, objectives, and activities are established and communicated
    0
    installs
  65. Id Be 04 Idbe 04 · cyberstrikeus
    Dependencies and critical functions for delivery of critical services are established
    0
    installs
  66. Id Be 05 Idbe 05 · cyberstrikeus
    Resilience requirements to support delivery of critical services are established for all operating states (e.g.
    0
    installs
  67. Id Gv 01 Idgv 01 · cyberstrikeus
    Organizational cybersecurity policy is established and communicated
    0
    installs
  68. Id Gv 02 Idgv 02 · cyberstrikeus
    Cybersecurity roles and responsibilities are coordinated and aligned with internal roles and external partners
    0
    installs
  69. Id Gv 03 Idgv 03 · cyberstrikeus
    Legal and regulatory requirements regarding cybersecurity, including privacy and civil liberties obligations, are understood and managed
    0
    installs
  70. Id Gv 04 Idgv 04 · cyberstrikeus
    Governance and risk management processes address cybersecurity risks
    0
    installs
  71. Id Im 01 Idim 01 · cyberstrikeus
    Improvements are identified from evaluations
    0
    installs