cyberstrikeus
- 7.2k skills
- 0 followers
- 17 hours ago last updated
- ▌ Pr Ir 03 Prir 03 · cyberstrikeusMechanisms are implemented to achieve resilience requirements in normal and adverse situations
- ▌
- ▌ Pr Ma 01 Prma 01 · cyberstrikeusMaintenance and repair of organizational assets are performed and logged, with approved and controlled tools
- ▌ Pr Ma 02 Prma 02 · cyberstrikeusRemote maintenance of organizational assets is approved, logged, and performed in a manner that prevents unauthorized access
- ▌
- ▌ Pr Ps 02 Prps 02 · cyberstrikeusSoftware is maintained, replaced, and removed commensurate with risk
- ▌ Pr Ps 03 Prps 03 · cyberstrikeusHardware is maintained, replaced, and removed commensurate with risk
- ▌ Pr Ps 04 Prps 04 · cyberstrikeusLog records are generated and made available for continuous monitoring
- ▌
- ▌ Pr Ps 06 Prps 06 · cyberstrikeusSecure software development practices are integrated, and their performance is monitored throughout the software development life cycle
- ▌ Pr Pt 01 Prpt 01 · cyberstrikeusAudit/log records are determined, documented, implemented, and reviewed in accordance with policy
- ▌ Pr Pt 02 Prpt 02 · cyberstrikeusRemovable media is protected and its use restricted according to policy
- ▌ Pr Pt 03 Prpt 03 · cyberstrikeusThe principle of least functionality is incorporated by configuring systems to provide only essential capabilities
- ▌
- ▌ Pr Pt 05 Prpt 05 · cyberstrikeusMechanisms (e.g., failsafe, load balancing, hot swap) are implemented to achieve resilience requirements in normal and adverse situations
- ▌
- ▌
- ▌ Rc Co 03 Rcco 03 · cyberstrikeusRecovery activities and progress in restoring operational capabilities are communicated to designated internal and external stakeholders
- ▌ Rc Co 04 Rcco 04 · cyberstrikeusPublic updates on incident recovery are shared using approved methods and messaging
- ▌
- ▌
- ▌ Rc Rp 01 Rcrp 01 · cyberstrikeusThe recovery portion of the incident response plan is executed once initiated from the incident response process
- ▌
- ▌ Rc Rp 03 Rcrp 03 · cyberstrikeusThe integrity of backups and other restoration assets is verified before using them for restoration
- ▌ Rc Rp 04 Rcrp 04 · cyberstrikeusCritical mission functions and cybersecurity risk management are considered to establish post-incident operational norms
- ▌ Rc Rp 05 Rcrp 05 · cyberstrikeusThe integrity of restored assets is verified, systems and services are restored, and normal operating status is confirmed
- ▌ Rc Rp 06 Rcrp 06 · cyberstrikeusThe end of incident recovery is declared based on criteria, and incident-related documentation is completed
- ▌
- ▌
- ▌ Rs An 03 Rsan 03 · cyberstrikeusAnalysis is performed to establish what has taken place during an incident and the root cause of the incident
- ▌
- ▌ Rs An 05 Rsan 05 · cyberstrikeusProcesses are established to receive, analyze and respond to vulnerabilities disclosed to the organization from internal and external sources (e.g.
- ▌ Rs An 06 Rsan 06 · cyberstrikeusActions performed during an investigation are recorded, and the records' integrity and provenance are preserved
- ▌ Rs An 07 Rsan 07 · cyberstrikeusIncident data and metadata are collected, and their integrity and provenance are preserved
- ▌
- ▌ Rs Co 01 Rsco 01 · cyberstrikeusPersonnel know their roles and order of operations when a response is needed
- ▌
- ▌ Rs Co 03 Rsco 03 · cyberstrikeusInformation is shared with designated internal and external stakeholders
- ▌ Rs Co 04 Rsco 04 · cyberstrikeusCoordination with stakeholders occurs consistent with response plans
- ▌ Rs Co 05 Rsco 05 · cyberstrikeusVoluntary information sharing occurs with external stakeholders to achieve broader cybersecurity situational awareness
- ▌
- ▌
- ▌ Rs Ma 01 Rsma 01 · cyberstrikeusThe incident response plan is executed in coordination with relevant third parties once an incident is declared
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌ Rs Mi 03 Rsmi 03 · cyberstrikeusNewly identified vulnerabilities are mitigated or documented as accepted risks
- ▌
- ▌ T1053 002 At · cyberstrikeusAdversaries may abuse the at utility to perform task scheduling for initial or recurring execution of malicious code.
- ▌ T1561 Disk Wipe · cyberstrikeusAdversaries may wipe or corrupt raw disk data on specific systems or in large numbers in a network to interrupt availability to system and network resources.
- ▌
- ▌ Id Am 02 Idam 02 · cyberstrikeusInventories of software, services, and systems managed by the organization are maintained
- ▌ Id Am 03 Idam 03 · cyberstrikeusRepresentations of the organization's authorized network communication and internal and external network data flows are maintained
- ▌
- ▌ Id Am 05 Idam 05 · cyberstrikeusAssets are prioritized based on classification, criticality, resources, and impact on the mission
- ▌ Id Am 06 Idam 06 · cyberstrikeusCybersecurity roles and responsibilities for the entire workforce and third-party stakeholders (e.g., suppliers, customers, partners) are established
- ▌ Id Am 07 Idam 07 · cyberstrikeusInventories of data and corresponding metadata for designated data types are maintained
- ▌ Id Am 08 Idam 08 · cyberstrikeusSystems, hardware, software, services, and data are managed throughout their life cycles
- ▌ Id Be 01 Idbe 01 · cyberstrikeusThe organization’s role in the supply chain is identified and communicated
- ▌ Id Be 02 Idbe 02 · cyberstrikeusThe organization’s place in critical infrastructure and its industry sector is identified and communicated
- ▌ Id Be 03 Idbe 03 · cyberstrikeusPriorities for organizational mission, objectives, and activities are established and communicated
- ▌ Id Be 04 Idbe 04 · cyberstrikeusDependencies and critical functions for delivery of critical services are established
- ▌ Id Be 05 Idbe 05 · cyberstrikeusResilience requirements to support delivery of critical services are established for all operating states (e.g.
- ▌ Id Gv 01 Idgv 01 · cyberstrikeusOrganizational cybersecurity policy is established and communicated
- ▌ Id Gv 02 Idgv 02 · cyberstrikeusCybersecurity roles and responsibilities are coordinated and aligned with internal roles and external partners
- ▌ Id Gv 03 Idgv 03 · cyberstrikeusLegal and regulatory requirements regarding cybersecurity, including privacy and civil liberties obligations, are understood and managed
- ▌ Id Gv 04 Idgv 04 · cyberstrikeusGovernance and risk management processes address cybersecurity risks
- ▌