Processes for receiving, analyzing, and responding to vulnerability disclosures are established
Skills in this repository
CyberStrikeus/CyberStrike - Page 109
SkillsMP has collected 7,442 skills from CyberStrikeus/CyberStrike. Open a skill to review its source and details.
CyberStrikeus/CyberStrikeShowing 40 of 7,442 collected skills.
The authenticity and integrity of hardware and software are assessed prior to acquisition and use
Critical suppliers are assessed prior to acquisition
Risk management processes are established, managed, and agreed to by organizational stakeholders
Organizational risk tolerance is determined and clearly expressed
The organization’s determination of risk tolerance is informed by its role in critical infrastructure and sector specific risk analysis
Cyber supply chain risk management processes are identified, established, assessed, managed, and agreed to by organizational stakeholders
Suppliers and third party partners of information systems, components, and services are identified, prioritized, and assessed using a cyber supply cha
Contracts with suppliers and third-party partners are used to implement appropriate measures designed to meet the objectives of an organization’s cybe
Suppliers and third-party partners are routinely assessed using audits, test results, or other forms of evaluations to confirm they are meeting their
Response and recovery planning and testing are conducted with suppliers and third-party providers
Improvements to organizational cybersecurity risk management processes, procedures and activities are identified across all CSF Functions
The cybersecurity risk to the organization, assets, and individuals is understood by the organization
Risk Management Strategy
Supply Chain Risk Management
The organization's personnel are provided with cybersecurity awareness and training so that they can perform their cybersecurity-related tasks
Data are managed consistent with the organization's risk strategy to protect the confidentiality, integrity, and availability of information
Maintenance
The hardware, software (e.g., firmware, operating systems, applications), and services of physical and virtual platforms are managed consistent with t
Identities and credentials for authorized users, services, and hardware are managed by the organization
Identities are proofed and bound to credentials based on the context of interactions
Users, services, and hardware are authenticated
Identity assertions are protected, conveyed, and verified
Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least
Physical access to assets is managed, monitored, and enforced commensurate with risk
Identities and credentials are issued, managed, verified, revoked, and audited for authorized devices, users and processes
Physical access to assets is managed and protected
Remote access is managed
Access permissions and authorizations are managed, incorporating the principles of least privilege and separation of duties
Network integrity is protected (e.g., network segregation, network segmentation)
Identities are proofed and bound to credentials and asserted in interactions
Users, devices, and other assets are authenticated (e.g., single-factor, multi-factor) commensurate with the risk of the transaction (e.g., individual
Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in
Individuals in specialized roles are provided with awareness and training so that they possess the knowledge and skills to perform relevant tasks with
Third-party stakeholders (e.g., suppliers, customers, partners) understand their roles and responsibilities
Senior executives understand their roles and responsibilities
Physical and cybersecurity personnel understand their roles and responsibilities
The confidentiality, integrity, and availability of data-at-rest are protected
The confidentiality, integrity, and availability of data-in-transit are protected
Assets are formally managed throughout removal, transfers, and disposition