For password-based authentication: Maintain a list of commonly-used, expected, or compromised passwords and update the list [organization-defined] and
Skills in this repository
CyberStrikeus/CyberStrike - Page 126
SkillsMP has collected 7,442 skills from CyberStrikeus/CyberStrike. Open a skill to review its source and details.
CyberStrikeus/CyberStrikeShowing 40 of 7,442 collected skills.
Bind identities and authenticators dynamically using the following rules: [organization-defined].
Hardware Token-based Authentication
For biometric-based authentication, employ mechanisms that satisfy the following biometric quality requirements [organization-defined].
Prohibit the use of cached authenticators after [organization-defined].
For PKI-based authentication, employ an organization-wide methodology for managing the content of PKI trust stores installed across all platforms, inc
Use only General Services Administration-approved products and services for identity, credential, and access management.
Employ [organization-defined] to generate and manage passwords;
For public key-based authentication: Enforce authorized access to the corresponding private key; and Map the authenticated identity to the account of
In-person or Trusted External Party Registration
Automated Support for Password Strength Determination
Require developers and installers of system components to provide unique authenticators or change default authenticators prior to delivery and install
Protect authenticators commensurate with the security category of the information to which use of the authenticator permits access.
Ensure that unencrypted static authenticators are not embedded in applications or other forms of static storage.
Implement [organization-defined] to manage the risk of compromise due to individuals having accounts on multiple systems.
Use the following external organizations to federate credentials: [organization-defined].
Manage system authenticators by: Verifying, as part of the initial authenticator distribution, the identity of the individual, group, role, service, o
Obscure feedback of authentication information during the authentication process to protect the information from possible exploitation and use by unau
Implement mechanisms for authentication to a cryptographic module that meet the requirements of applicable laws, executive orders, directives, policie
Accept and electronically verify Personal Identity Verification-compliant credentials from other federal agencies.
Accept only external authenticators that are NIST-compliant;
Use of FICAM-approved Products
Conform to the following profiles for identity management [organization-defined].
Accept and verify federated or PKI credentials that meet [organization-defined].
Implement the following measures to disassociate user attributes or identifier assertion relationships among individuals, credential service providers
Uniquely identify and authenticate non-organizational users or processes acting on behalf of non-organizational users.
Information Exchange
Transmission of Decisions
Uniquely identify and authenticate [organization-defined] before establishing communications with devices, users, or other services or applications.
Develop, document, and disseminate to [organization-defined]: [organization-defined] incident response policy that: Procedures to facilitate the imple
Integrated Information Security Analysis Team
Incorporate simulated events into incident response training to facilitate the required response by personnel in crisis situations.
Provide an incident response training environment using [organization-defined].
Provide incident response training on how to identify and respond to a breach, including the organization’s process for reporting a breach.
Provide incident response training to system users consistent with assigned roles and responsibilities: Within [organization-defined] of assuming an i
Test the incident response capability using [organization-defined].
Coordinate incident response testing with organizational elements responsible for related plans.
Use qualitative and quantitative data from testing to: Determine the effectiveness of incident response processes; Continuously improve incident respo
Test the effectiveness of the incident response capability for the system [organization-defined] using the following tests: [organization-defined].
Support the incident handling process using [organization-defined].