03.13.05
Skills in this repository
CyberStrikeus/CyberStrike - Page 114
SkillsMP has collected 7,442 skills from CyberStrikeus/CyberStrike. Open a skill to review its source and details.
CyberStrikeus/CyberStrikeShowing 40 of 7,442 collected skills.
03.13.07
03.13.14
03.13.16
Identify, report, and correct system flaws.
Implement malicious code protection mechanisms at system entry and exit points to detect and eradicate malicious code.
03.14.04
03.14.05
03.14.07
Monitor the system to detect: Attacks and indicators of potential attacks and Unauthorized connections. Identify unauthorized use of the system. Monit
Develop, document, and disseminate to organizational personnel or roles the policies and procedures needed to satisfy the security requirements for...
Establish rules that describe the responsibilities and expected behavior for system usage and protecting CUI.
Develop a system security plan that: Defines the constituent system components; Identifies the information types processed, stored, and transmitted by
Require the providers of external system services used for the processing, storage, or transmission of CUI to comply with the following security re...
Identify and document all security requirements for the organization’s software development infrastructures and processes, and maintain the requiremen
Identify and document all security requirements for organization-developed software to meet, and maintain the requirements over time.
Communicate requirements to all third parties who will provide commercial software components to the organization for reuse by the organization’s o...
Create new roles and alter responsibilities for existing roles as needed to encompass all parts of the SDLC.
Provide role-based training for all personnel with responsibilities that contribute to secure development.
Obtain upper management or authorizing official commitment to secure development, and convey that commitment to all with development-related roles and
Specify which tools or tool types must or should be included in each toolchain to mitigate identified risks, as well as how the toolchain components a
Follow recommended security practices to deploy, operate, and maintain tools and toolchains.
Configure tools to generate artifacts of their support of secure software development practices as defined by the organization.
Define criteria for software security checks and track throughout the SDLC.
Implement processes, mechanisms, etc.
Separate and protect each environment involved in software development.
Secure and harden development endpoints (i.e., endpoints for software designers, developers, testers, builders, etc.) to perform development-related t
Store all forms of code – including source code, executable code, and configuration-as-code – based on the principle of least privilege so that onl...
Make software integrity verification information available to software acquirers.
Securely archive the necessary files and supporting data (e.g., integrity verification information, provenance data) to be retained for each software
Collect, safeguard, maintain, and share provenance data for all components of each software release (e.g., in a software bill of materials .SBOM).
Use forms of risk modeling – such as threat modeling, attack modeling, or attack surface mapping – to help assess the security risk for the software.
Track and maintain the software’s security requirements, risks, and design decisions.
Where appropriate, build in support for using standardized security features and services (e.g., enabling software to integrate with existing log m...
Have 1) a qualified person (or people) who were not involved with the design and/or 2) automated processes instantiated in the toolchain review the so
Acquire and maintain well-secured software components (e.g., software libraries, modules, middleware, frameworks) from commercial, open-source, and ot
Create and maintain well-secured software components in-house following SDLC processes to meet common internal software development needs that cannot
Verify that acquired commercial, open-source, and all other third-party software components comply with the requirements, as defined by the organizati
Follow all secure coding practices that are appropriate to the development languages and environment to meet the organization’s requirements.
Use compiler, interpreter, and build tools that offer features to improve executable security.