Planning and due diligence are performed to reduce risks before entering into formal supplier or other third-party relationships
Skills in this repository
CyberStrikeus/CyberStrike - Page 108
SkillsMP has collected 7,442 skills from CyberStrikeus/CyberStrike. Open a skill to review its source and details.
CyberStrikeus/CyberStrikeShowing 40 of 7,442 collected skills.
The risks posed by a supplier, their products and services, and other third parties are understood, recorded, prioritized, assessed, responded to, and
Relevant suppliers and other third parties are included in incident planning, response, and recovery activities
Supply chain security practices are integrated into cybersecurity and enterprise risk management programs, and their performance is monitored througho
Cybersecurity supply chain risk management plans include provisions for activities that occur after the conclusion of a partnership or service agreeme
The circumstances - mission, stakeholder expectations, dependencies, and legal, regulatory, and contractual requirements - surrounding the organizatio
Results of organization-wide cybersecurity risk management activities and performance are used to inform, improve, and adjust the risk management stra
Organizational cybersecurity policy is established, communicated, and enforced
The organization's priorities, constraints, risk tolerance and appetite statements, and assumptions are established, communicated, and used to support
Assets (e.g., data, hardware, software, systems, facilities, services, people) that enable the organization to achieve business purposes are identifie
Business Environment
Governance
Inventories of hardware managed by the organization are maintained
Inventories of software, services, and systems managed by the organization are maintained
Representations of the organization's authorized network communication and internal and external network data flows are maintained
Inventories of services provided by suppliers are maintained
Assets are prioritized based on classification, criticality, resources, and impact on the mission
Cybersecurity roles and responsibilities for the entire workforce and third-party stakeholders (e.g., suppliers, customers, partners) are established
Inventories of data and corresponding metadata for designated data types are maintained
Systems, hardware, software, services, and data are managed throughout their life cycles
The organization’s role in the supply chain is identified and communicated
The organization’s place in critical infrastructure and its industry sector is identified and communicated
Priorities for organizational mission, objectives, and activities are established and communicated
Dependencies and critical functions for delivery of critical services are established
Resilience requirements to support delivery of critical services are established for all operating states (e.g.
Organizational cybersecurity policy is established and communicated
Cybersecurity roles and responsibilities are coordinated and aligned with internal roles and external partners
Legal and regulatory requirements regarding cybersecurity, including privacy and civil liberties obligations, are understood and managed
Governance and risk management processes address cybersecurity risks
Improvements are identified from evaluations
Improvements are identified from security tests and exercises, including those done in coordination with suppliers and relevant third parties
Improvements are identified from execution of operational processes, procedures, and activities
Incident response plans and other cybersecurity plans that affect operations are established, communicated, maintained, and improved
Vulnerabilities in assets are identified, validated, and recorded
Cyber threat intelligence is received from information sharing forums and sources
Internal and external threats to the organization are identified and recorded
Potential impacts and likelihoods of threats exploiting vulnerabilities are identified and recorded
Threats, vulnerabilities, likelihoods, and impacts are used to understand inherent risk and inform risk response prioritization
Risk responses are chosen, prioritized, planned, tracked, and communicated
Changes and exceptions are managed, assessed for risk impact, recorded, and tracked