Adequate capacity to ensure availability is maintained
Skills in this repository
CyberStrikeus/CyberStrike - Page 110
SkillsMP has collected 7,442 skills from CyberStrikeus/CyberStrike. Open a skill to review its source and details.
CyberStrikeus/CyberStrikeShowing 40 of 7,442 collected skills.
Protections against data leaks are implemented
Integrity checking mechanisms are used to verify software, firmware, and information integrity
The development and testing environment(s) are separate from the production environment
Integrity checking mechanisms are used to verify hardware integrity
The confidentiality, integrity, and availability of data-in-use are protected
Backups of data are created, protected, maintained, and tested
A baseline configuration of information technology/industrial control systems is created and maintained incorporating security principles (e.g.
A System Development Life Cycle to manage systems is implemented
Configuration change control processes are in place
Backups of information are conducted, maintained, and tested
Policy and regulations regarding the physical operating environment for organizational assets are met
Data is destroyed according to policy
Protection processes are improved
Effectiveness of protection technologies is shared
Response plans (Incident Response and Business Continuity) and recovery plans (Incident Recovery and Disaster Recovery) are in place and managed
Response and recovery plans are tested
Cybersecurity is included in human resources practices (e.g., deprovisioning, personnel screening)
A vulnerability management plan is developed and implemented
Networks and environments are protected from unauthorized logical access and usage
The organization's technology assets are protected from environmental threats
Mechanisms are implemented to achieve resilience requirements in normal and adverse situations
Adequate resource capacity to ensure availability is maintained
Maintenance and repair of organizational assets are performed and logged, with approved and controlled tools
Remote maintenance of organizational assets is approved, logged, and performed in a manner that prevents unauthorized access
Configuration management practices are established and applied
Software is maintained, replaced, and removed commensurate with risk
Hardware is maintained, replaced, and removed commensurate with risk
Log records are generated and made available for continuous monitoring
Installation and execution of unauthorized software are prevented
Secure software development practices are integrated, and their performance is monitored throughout the software development life cycle
Audit/log records are determined, documented, implemented, and reviewed in accordance with policy
Removable media is protected and its use restricted according to policy
The principle of least functionality is incorporated by configuring systems to provide only essential capabilities
Communications and control networks are protected
Mechanisms (e.g., failsafe, load balancing, hot swap) are implemented to achieve resilience requirements in normal and adverse situations
Protective Technology
Improvements
Public relations are managed
Reputation is repaired after an incident