Require users to re-authenticate when [organization-defined].
Skills in this repository
CyberStrikeus/CyberStrike - Page 125
SkillsMP has collected 7,442 skills from CyberStrikeus/CyberStrike. Open a skill to review its source and details.
CyberStrikeus/CyberStrikeShowing 40 of 7,442 collected skills.
Require that the registration process to receive an account for logical access includes supervisor or sponsor authorization.
Require evidence of individual identification be presented to the registration authority.
Require that the presented identity evidence be validated and verified through [organization-defined].
Require that the validation and verification of identity evidence be conducted in person before a designated registration authority.
Require that a [organization-defined] be delivered through an out-of-band channel to verify the users address (physical or digital) of record.
Accept externally-proofed identities at [organization-defined].
Identity proof users that require accounts for logical access to systems based on appropriate identity assurance level requirements as specified in...
Cryptographic keys that protect access tokens are generated, managed, and protected from disclosure and misuse.
The source and integrity of identity assertions and access tokens are verified before granting access to system and information resources.
In accordance with [organization-defined], assertions and access tokens are: generated; issued; refreshed; revoked; time-restricted; and audience-rest
Employ identity providers and authorization servers to manage user, device, and non-person entity (NPE) identities, attributes, and access rights supp
Implement multi-factor authentication for access to privileged accounts.
Provide a single sign-on capability for [organization-defined].
Remote Access — Separate Device
Accept and electronically verify Personal Identity Verification-compliant credentials.
Implement the following out-of-band authentication mechanisms under [organization-defined]: [organization-defined].
Implement multi-factor authentication for access to non-privileged accounts.
Local Access to Privileged Accounts
Local Access to Non-privileged Accounts
When shared accounts or authenticators are employed, require users to be individually authenticated before granting access to the shared accounts or r
Implement multi-factor authentication for [organization-defined] access to [organization-defined] such that: One of the factors is provided by a devic
Network Access to Non-privileged Accounts — Separate Device
Implement replay-resistant authentication mechanisms for access to [organization-defined].
Uniquely identify and authenticate organizational users and associate that unique identification with processes acting on behalf of those users.
Authenticate [organization-defined] before establishing [organization-defined] connection using bidirectional authentication that is cryptographically
Cryptographic Bidirectional Network Authentication
Where addresses are allocated dynamically, standardize dynamic address allocation lease information and the lease duration assigned to devices in a...
Handle device identification and authentication based on attestation by [organization-defined].
Uniquely identify and authenticate [organization-defined] before establishing a [organization-defined] connection.
Prohibit the use of system account identifiers that are the same as public identifiers for individual accounts.
Supervisor Authorization
Multiple Forms of Certification
Manage individual identifiers by uniquely identifying each individual as [organization-defined].
Manage individual identifiers dynamically in accordance with [organization-defined].
Coordinate with the following external organizations for cross-organization management of identifiers: [organization-defined].
In-person Registration
Generate pairwise pseudonymous identifiers.
Maintain the attributes for each uniquely identified individual, device, or service in [organization-defined].
Manage system identifiers by: Receiving authorization from [organization-defined] to assign an individual, group, role, service, or device identifier;