Determine which compiler, interpreter, and build tool features should be used and how each should be configured, then implement and use the approved c
Skills in this repository
CyberStrikeus/CyberStrike - Page 115
SkillsMP has collected 7,442 skills from CyberStrikeus/CyberStrike. Open a skill to review its source and details.
CyberStrikeus/CyberStrikeShowing 40 of 7,442 collected skills.
Determine whether code review (a person looks directly at the code to find issues) and/or code analysis (tools are used to find issues in code, either
Perform the code review and/or code analysis based on the organization’s secure coding standards, and record and triage all discovered issues and reco
Determine whether executable code testing should be performed to find vulnerabilities not identified by previous reviews, analysis, or testing and, if
Scope the testing, design the tests, perform the testing, and document the results, including recording and triaging all discovered issues and recomme
Define a secure baseline by determining how to configure each setting that has an effect on security or a security-related setting so that the default
Implement the default settings (or groups of default settings, if applicable), and document each setting for software administrators.
Gather information from software acquirers, users, and public sources on potential vulnerabilities in the software and third-party components that the
Review, analyze, and/or test the software’s code to identify or confirm the presence of previously undetected vulnerabilities.
Have a policy that addresses vulnerability disclosure and remediation, and implement the roles, responsibilities, and processes needed to support that
Analyze each vulnerability to gather sufficient information about risk to plan its remediation or other risk response.
Plan and implement risk responses for vulnerabilities.
Analyze identified vulnerabilities to determine their root causes.
Analyze the root causes over time to identify patterns, such as a particular secure coding practice not being followed consistently.
Review the software for similar vulnerabilities to eradicate a class of vulnerabilities, and proactively fix them rather than waiting for external rep
Review the SDLC process, and update it if appropriate to prevent (or reduce the likelihood of) the root cause recurring in updates to the software or
Develop, document, and disseminate to [organization-defined]: [organization-defined] access control policy that: Procedures to facilitate the implemen
Limit the number of concurrent sessions for each [organization-defined] to [organization-defined].
Conceal, via the device lock, information previously visible on the display with a publicly viewable image.
Prevent further access to the system by [organization-defined] ;
Provide a logout capability for user-initiated communications sessions whenever authentication is used to gain access to [organization-defined].
Display an explicit logout message to users indicating the termination of authenticated communications sessions.
Display an explicit message to users indicating that the session will end in [organization-defined].
Automatically terminate a user session after [organization-defined].
Supervision and Review — Access Control
Necessary Uses
Identify [organization-defined] that can be performed on the system without identification or authentication consistent with organizational mission...
Automated Marking
Dynamically associate security and privacy attributes with [organization-defined] in accordance with the following security and privacy policies as in
Provide authorized individuals the capability to define or change the type and value of security and privacy attributes available for association with
Provide authorized individuals (or processes acting on behalf of individuals) the capability to define or change the value of associated security and
Maintain the association and integrity of [organization-defined] to [organization-defined].
Provide the capability to associate [organization-defined] with [organization-defined] by authorized individuals (or processes acting on behalf of ind
Display security and privacy attributes in human-readable form on each object that the system transmits to output devices to identify [organization-de
Require personnel to associate and maintain the association of [organization-defined] with [organization-defined] in accordance with [organization-def
Provide a consistent interpretation of security and privacy attributes transmitted between distributed system components.
Implement [organization-defined] in associating security and privacy attributes to information.
Change security and privacy attributes associated with information only via regrading mechanisms validated using [organization-defined].
Provide the means to associate [organization-defined] with [organization-defined] for information in storage, in process, and/or in transmission;
Employ automated mechanisms to monitor and control remote access methods.