Define the types of system accounts allowed and prohibited.
Skills in this repository
CyberStrikeus/CyberStrike - Page 112
SkillsMP has collected 7,442 skills from CyberStrikeus/CyberStrike. Open a skill to review its source and details.
CyberStrikeus/CyberStrikeShowing 40 of 7,442 collected skills.
Prevent access to the system by [organization-defined].
Allow only authorized system access for users (or processes acting on behalf of users) that is necessary to accomplish assigned organizational tasks.
Train authorized individuals to ensure that publicly accessible information does not contain CUI.
Establish usage restrictions, configuration requirements, and connection requirements for each type of allowable remote system access.
Identify the duties of individuals requiring separation.
Session Termination
03.01.13
03.01.14
03.01.15
03.01.17
03.01.19
03.01.21
System Use Notification
Enforce a limit of [organization-defined] consecutive invalid logon attempts by a user during a [organization-defined].
Prohibit the use of external systems unless the systems are specifically authorized.
Establish usage restrictions, configuration requirements, and connection requirements for each type of wireless access to the system.
Provide role-based security training to organizational personnel: Before authorizing access to the system or CUI, before performing assigned duties, a
03.02.03
Include the following content in audit records: What type of event occurred When the event occurred Where the event occurred Source of the event Outco
Generate audit records for the selected event types and audit record content specified in 03.03.01 and 03.03.02.
Specify the following event types selected for logging within the system: [organization-defined].
03.03.09
Use internal system clocks to generate time stamps for audit records.
Develop and maintain under configuration control, a current baseline configuration of the system.
Establish, document, and implement the following configuration settings for the system that reflect the most restrictive mode consistent with opera...
Analyze changes to the system to determine potential security impacts prior to change implementation.
Identify and document the location of CUI and the system components on which the information is processed and stored.
Configure the system to provide only mission-essential capabilities.
03.04.07
03.04.09
Develop and document an inventory of system components.
Authentication Feedback
Verify the identity of the individual, group, role, service, or device receiving the authenticator as part of the initial authenticator distribution.
Receive authorization from organizational personnel or roles to assign an individual, group, role, service, or device identifier.
Multi-Factor Authentication
Maintain a list of commonly-used, expected, or compromised passwords, and update the list [organization-defined] and when organizational passwords ...
03.05.06
03.05.08
03.05.09