When transferring information between different security domains, modify non-releasable information by implementing [organization-defined].
Skills in this repository
CyberStrikeus/CyberStrike - Page 118
SkillsMP has collected 7,442 skills from CyberStrikeus/CyberStrike. Open a skill to review its source and details.
CyberStrikeus/CyberStrikeShowing 40 of 7,442 collected skills.
When transferring information between different security domains, parse incoming data into an internal normalized format and regenerate the data to be
When transferring information between different security domains, sanitize data to minimize [organization-defined] in accordance with [organization-de
When transferring information between different security domains, record and audit content filtering actions and results for the information being fil
When transferring information between different security domains, implement content filtering solutions that provide redundant and independent filteri
When transferring information between different security domains, implement a linear content filter pipeline that is enforced with discretionary and m
When transferring information between different security domains, employ content filter orchestration engines to ensure that: Content filtering mechan
Enforce [organization-defined].
When transferring information between different security domains, implement content filtering mechanisms using multiple processes.
When transferring information between different security domains, prevent the transfer of failed content to the receiving domain.
When transferring information between different security domains, the process that transfers information between filter pipelines: Does not filter mes
Prevent encrypted information from bypassing [organization-defined] by [organization-defined].
Enforce [organization-defined] on embedding data types within other data types.
Enforce information flow control based on [organization-defined].
Enforce one-way information flows through hardware-based flow control mechanisms.
Enforce information flow control using [organization-defined] as a basis for flow control decisions for [organization-defined] ;
Enforce the use of human reviews for [organization-defined] under the following conditions: [organization-defined].
Enforce approved authorizations for controlling the flow of information within the system and between connected systems based on [organization-defined
Identify and document [organization-defined] ;
Authorize access for [organization-defined] to: [organization-defined] ; and [organization-defined].
Require that users of system accounts (or roles) with access to [organization-defined] use non-privileged accounts or roles, when accessing nonsecurit
Authorize network access to [organization-defined] only for [organization-defined] and document the rationale for such access in the security plan for
Provide separate processing domains to enable finer-grained allocation of user privileges.
Restrict privileged accounts on the system to [organization-defined].
Prohibit privileged access to the system by non-organizational users.
Review [organization-defined] the privileges assigned to [organization-defined] to validate the need for such privileges;
Prevent the following software from executing at higher privilege levels than users executing the software: [organization-defined].
Log the execution of privileged functions.
Employ the principle of least privilege, allowing only authorized accesses for users (or processes acting on behalf of users) that are necessary to ac
Automatic Account Lock
Purge or wipe information from [organization-defined] based on [organization-defined] after [organization-defined] consecutive, unsuccessful device lo
Limit the number of unsuccessful biometric logon attempts to [organization-defined].
Allow the use of [organization-defined] that are different from the primary authentication factors after the number of organization-defined consecu...
Enforce a limit of [organization-defined] consecutive invalid logon attempts by a user during a [organization-defined] ;
Display [organization-defined] to users before granting access to the system that provides privacy and security notices consistent with applicable law
Notify the user, upon successful logon, of the number of unsuccessful logon attempts since the last successful logon.
Notify the user, upon successful logon, of the number of [organization-defined] during [organization-defined].
Notify the user, upon successful logon, of changes to [organization-defined] during [organization-defined].
Notify the user, upon successful logon, of the following additional information: [organization-defined].
Notify the user, upon successful logon to the system, of the date and time of the last logon.