Processes for receiving, analyzing, and responding to vulnerability disclosures are established
لغة النص الأصلي: الإنجليزية
القائمة
Skills في هذا المستودع
جمع SkillsMP عدد ٧٬٤٤٢ من skills من CyberStrikeus/CyberStrike. افتح أي skill لمراجعة مصدره وتفاصيله.
CyberStrikeus/CyberStrikeعرض ٤٠ من أصل ٧٬٤٤٢ skills مجمعة.
Processes for receiving, analyzing, and responding to vulnerability disclosures are established
لغة النص الأصلي: الإنجليزية
The authenticity and integrity of hardware and software are assessed prior to acquisition and use
لغة النص الأصلي: الإنجليزية
Critical suppliers are assessed prior to acquisition
لغة النص الأصلي: الإنجليزية
Risk management processes are established, managed, and agreed to by organizational stakeholders
لغة النص الأصلي: الإنجليزية
Organizational risk tolerance is determined and clearly expressed
لغة النص الأصلي: الإنجليزية
The organization’s determination of risk tolerance is informed by its role in critical infrastructure and sector specific risk analysis
لغة النص الأصلي: الإنجليزية
Cyber supply chain risk management processes are identified, established, assessed, managed, and agreed to by organizational stakeholders
لغة النص الأصلي: الإنجليزية
Suppliers and third party partners of information systems, components, and services are identified, prioritized, and assessed using a cyber supply cha
لغة النص الأصلي: الإنجليزية
Contracts with suppliers and third-party partners are used to implement appropriate measures designed to meet the objectives of an organization’s cybe
لغة النص الأصلي: الإنجليزية
Suppliers and third-party partners are routinely assessed using audits, test results, or other forms of evaluations to confirm they are meeting their
لغة النص الأصلي: الإنجليزية
Response and recovery planning and testing are conducted with suppliers and third-party providers
لغة النص الأصلي: الإنجليزية
Improvements to organizational cybersecurity risk management processes, procedures and activities are identified across all CSF Functions
لغة النص الأصلي: الإنجليزية
The cybersecurity risk to the organization, assets, and individuals is understood by the organization
لغة النص الأصلي: الإنجليزية
Risk Management Strategy
لغة النص الأصلي: الإنجليزية
Supply Chain Risk Management
لغة النص الأصلي: الإنجليزية
The organization's personnel are provided with cybersecurity awareness and training so that they can perform their cybersecurity-related tasks
لغة النص الأصلي: الإنجليزية
Data are managed consistent with the organization's risk strategy to protect the confidentiality, integrity, and availability of information
لغة النص الأصلي: الإنجليزية
Maintenance
لغة النص الأصلي: الإنجليزية
The hardware, software (e.g., firmware, operating systems, applications), and services of physical and virtual platforms are managed consistent with t
لغة النص الأصلي: الإنجليزية
Identities and credentials for authorized users, services, and hardware are managed by the organization
لغة النص الأصلي: الإنجليزية
Identities are proofed and bound to credentials based on the context of interactions
لغة النص الأصلي: الإنجليزية
Users, services, and hardware are authenticated
لغة النص الأصلي: الإنجليزية
Identity assertions are protected, conveyed, and verified
لغة النص الأصلي: الإنجليزية
Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least
لغة النص الأصلي: الإنجليزية
Physical access to assets is managed, monitored, and enforced commensurate with risk
لغة النص الأصلي: الإنجليزية
Identities and credentials are issued, managed, verified, revoked, and audited for authorized devices, users and processes
لغة النص الأصلي: الإنجليزية
Physical access to assets is managed and protected
لغة النص الأصلي: الإنجليزية
Remote access is managed
لغة النص الأصلي: الإنجليزية
Access permissions and authorizations are managed, incorporating the principles of least privilege and separation of duties
لغة النص الأصلي: الإنجليزية
Network integrity is protected (e.g., network segregation, network segmentation)
لغة النص الأصلي: الإنجليزية
Identities are proofed and bound to credentials and asserted in interactions
لغة النص الأصلي: الإنجليزية
Users, devices, and other assets are authenticated (e.g., single-factor, multi-factor) commensurate with the risk of the transaction (e.g., individual
لغة النص الأصلي: الإنجليزية
Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in
لغة النص الأصلي: الإنجليزية
Individuals in specialized roles are provided with awareness and training so that they possess the knowledge and skills to perform relevant tasks with
لغة النص الأصلي: الإنجليزية
Third-party stakeholders (e.g., suppliers, customers, partners) understand their roles and responsibilities
لغة النص الأصلي: الإنجليزية
Senior executives understand their roles and responsibilities
لغة النص الأصلي: الإنجليزية
Physical and cybersecurity personnel understand their roles and responsibilities
لغة النص الأصلي: الإنجليزية
The confidentiality, integrity, and availability of data-at-rest are protected
لغة النص الأصلي: الإنجليزية
The confidentiality, integrity, and availability of data-in-transit are protected
لغة النص الأصلي: الإنجليزية
Assets are formally managed throughout removal, transfers, and disposition
لغة النص الأصلي: الإنجليزية