Authorize access to management of audit logging functionality to only [organization-defined].
Skills in this repository
CyberStrikeus/CyberStrike - Page 121
SkillsMP has collected 7,442 skills from CyberStrikeus/CyberStrike. Open a skill to review its source and details.
CyberStrikeus/CyberStrikeShowing 40 of 7,442 collected skills.
Enforce dual authorization for [organization-defined] of [organization-defined].
Authorize read-only access to audit information to [organization-defined].
Store audit information on a component running a different operating system than the system or component being audited.
Protect audit information and audit logging tools from unauthorized access, modification, and deletion;
Develop, document, and disseminate to [organization-defined]: [organization-defined] assessment, authorization, and monitoring policy that: Procedures
Employ independent assessors or assessment teams to conduct control assessments.
Include as part of control assessments, [organization-defined], [organization-defined], [organization-defined].
Leverage the results of control assessments performed by [organization-defined] on [organization-defined] when the assessment meets [organization-defi
Select the appropriate assessor or assessment team for the type of assessment to be conducted;
Unclassified National Security System Connections
Classified National Security System Connections
Unclassified Non-national Security System Connections
Connections to Public Networks
Restrictions on External System Connections
Verify that individuals or systems transferring data between interconnecting systems have the requisite authorizations (i.e., write permissions or pri
Identify transitive (downstream) information exchanges with other systems through the systems identified in [CA-3a](#ca-3_smt.a) ;
Approve and manage the exchange of information between the system and other systems using [organization-defined];
Security Certification
Ensure the accuracy, currency, and availability of the plan of action and milestones for the system using [organization-defined].
Develop a plan of action and milestones for the system to document the planned remediation actions of the organization to correct weaknesses or def...
Employ a joint authorization process for the system that includes multiple authorizing officials from the same organization conducting the authorizati
Employ a joint authorization process for the system that includes multiple authorizing officials with at least one authorizing official from an organi
Assign a senior official as the authorizing official for the system;
Employ independent assessors or assessment teams to monitor the controls in the system on an ongoing basis.
Types of Assessments
Employ trend analyses to determine if control implementations, the frequency of continuous monitoring activities, and the types of activities used in
Ensure risk monitoring is an integral part of the continuous monitoring strategy that includes the following: Effectiveness monitoring; Compliance mon
Employ the following actions to validate that policies are established and implemented controls are operating in a consistent manner: [organization-de
Ensure the accuracy, currency, and availability of monitoring results for the system using [organization-defined].
Develop a system-level continuous monitoring strategy and implement continuous monitoring in accordance with the organization-level continuous monitor
Employ an independent penetration testing agent or team to perform penetration testing on the system or system components.
Employ the following red-team exercises to simulate attempts by adversaries to compromise organizational systems in accordance with applicable rules o
Employ a penetration testing process that includes [organization-defined] [organization-defined] attempts to bypass or circumvent controls associated
Conduct penetration testing [organization-defined] on [organization-defined].
Perform security and privacy compliance checks on constituent system components prior to the establishment of the internal connection.
Authorize internal connections of [organization-defined] to the system;
Develop, document, and disseminate to [organization-defined]: [organization-defined] configuration management policy that: Procedures to facilitate th
Establish the following restrictions on the use of open-source software: [organization-defined].
Use software and associated documentation in accordance with contract agreements and copyright laws;