The physical environment is monitored to find potentially adverse events
Skills in this repository
CyberStrikeus/CyberStrike - Page 107
SkillsMP has collected 7,442 skills from CyberStrikeus/CyberStrike. Open a skill to review its source and details.
CyberStrikeus/CyberStrikeShowing 40 of 7,442 collected skills.
Personnel activity and technology usage are monitored to find potentially adverse events
Malicious code is detected
Unauthorized mobile code is detected
External service provider activities and services are monitored to find potentially adverse events
Monitoring for unauthorized personnel, connections, devices, and software is performed
Vulnerability scans are performed
Computing hardware and software, runtime environments, and their data are monitored to find potentially adverse events
Roles and responsibilities for detection are well defined to ensure accountability
Detection activities comply with all applicable requirements
Detection processes are tested
Event detection information is communicated
Detection processes are continuously improved
Detection Processes
The organizational mission is understood and informs cybersecurity risk management
Internal and external stakeholders are understood, and their needs and expectations regarding cybersecurity risk management are understood and conside
Legal, regulatory, and contractual requirements regarding cybersecurity - including privacy and civil liberties obligations - are understood and manag
Critical objectives, capabilities, and services that external stakeholders depend on or expect from the organization are understood and communicated
Outcomes, capabilities, and services that the organization depends on are understood and communicated
Cybersecurity risk management strategy outcomes are reviewed to inform and adjust strategy and direction
The cybersecurity risk management strategy is reviewed and adjusted to ensure coverage of organizational requirements and risks
Organizational cybersecurity risk management performance is evaluated and reviewed for adjustments needed
Policy for managing cybersecurity risks is established based on organizational context, cybersecurity strategy, and priorities and is communicated and
Policy for managing cybersecurity risks is reviewed, updated, communicated, and enforced to reflect changes in requirements, threats, technology, and
Risk management objectives are established and agreed to by organizational stakeholders
Risk appetite and risk tolerance statements are established, communicated, and maintained
Cybersecurity risk management activities and outcomes are included in enterprise risk management processes
Strategic direction that describes appropriate risk response options is established and communicated
Lines of communication across the organization are established for cybersecurity risks, including risks from suppliers and other third parties
A standardized method for calculating, documenting, categorizing, and prioritizing cybersecurity risks is established and communicated
Strategic opportunities (i.e., positive risks) are characterized and are included in organizational cybersecurity risk discussions
Organizational leadership is responsible and accountable for cybersecurity risk and fosters a culture that is risk-aware, ethical, and continually imp
Roles, responsibilities, and authorities related to cybersecurity risk management are established, communicated, understood, and enforced
Adequate resources are allocated commensurate with the cybersecurity risk strategy, roles, responsibilities, and policies
Cybersecurity is included in human resources practices
A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational st
Cybersecurity roles and responsibilities for suppliers, customers, and partners are established, communicated, and coordinated internally and external
Cybersecurity supply chain risk management is integrated into cybersecurity and enterprise risk management, risk assessment, and improvement processes
Suppliers are known and prioritized by criticality
Requirements to address cybersecurity risks in supply chains are established, prioritized, and integrated into contracts and other types of agreements