Categorize the system and information it processes, stores, and transmits;
Skills in this repository
CyberStrikeus/CyberStrike - Page 133
SkillsMP has collected 7,442 skills from CyberStrikeus/CyberStrike. Open a skill to review its source and details.
CyberStrikeus/CyberStrikeShowing 40 of 7,442 collected skills.
Assess supply chain risks associated with [organization-defined] ;
Use all-source intelligence to assist in the analysis of risk.
Determine the current cyber threat environment on an ongoing basis using [organization-defined].
Employ the following advanced automation and analytics capabilities to predict and identify risks to [organization-defined]: [organization-defined].
Conduct a risk assessment, including: Identifying threats to and vulnerabilities in the system; Determining the likelihood and magnitude of harm from
Risk Assessment Update
Update Tool Capability
Correlate the output from vulnerability scanning tools to determine the presence of multi-vulnerability and multi-hop attack vectors.
Establish a public reporting channel for receiving reports of vulnerabilities in organizational systems and system components.
Update the system vulnerabilities to be scanned [organization-defined].
Define the breadth and depth of vulnerability scanning coverage.
Determine information about the system that is discoverable and take [organization-defined].
Implement privileged access authorization to [organization-defined] for [organization-defined].
Compare the results of multiple vulnerability scans using [organization-defined].
Review historic audit logs to determine if a vulnerability identified in a [organization-defined] has been previously exploited within an [organizatio
Penetration Testing and Analyses
Monitor and scan for vulnerabilities in the system and hosted applications [organization-defined] and when new vulnerabilities potentially affectin...
Employ a technical surveillance countermeasures survey at [organization-defined] [organization-defined].
Respond to findings from security and privacy assessments, monitoring, and audits in accordance with organizational risk tolerance.
Conduct privacy impact assessments for systems, programs, or other activities before: Developing or procuring information technology that processes pe
Identify critical system components and functions by performing a criticality analysis for [organization-defined] at [organization-defined].
Develop, document, and disseminate to [organization-defined]: [organization-defined] system and services acquisition policy that: Procedures to facili
Require the developer of the system, system component, or system service to enable integrity verification of software and firmware components.
Provide an alternate configuration management process using organizational personnel in the absence of a dedicated developer configuration management
Require the developer of the system, system component, or system service to enable integrity verification of hardware components.
Require the developer of the system, system component, or system service to employ tools for comparing newly generated versions of security-relevant h
Require the developer of the system, system component, or system service to maintain the integrity of the mapping between the master build data descri
Require the developer of the system, system component, or system service to execute procedures for ensuring that security-relevant hardware, software,
Require [organization-defined] to be included in the [organization-defined].
Require the developer of the system, system component, or system service to: Perform configuration management during system, component, or service [or
Require the developer of the system, system component, or system service to employ static code analysis tools to identify common flaws and document th
Require the developer of the system, system component, or system service to perform threat modeling and vulnerability analyses during development and
Require the developer of the system, system component, or system service to perform a manual code review of [organization-defined] using the following
Require the developer of the system, system component, or system service to perform penetration testing: At the following level of rigor: [organizatio
Require the developer of the system, system component, or system service to perform attack surface reviews.
Require the developer of the system, system component, or system service to verify that the scope of testing and evaluation provides complete coverage
Require the developer of the system, system component, or system service to employ dynamic code analysis tools to identify common flaws and document t
Require the developer of the system, system component, or system service to employ interactive application security testing tools to identify flaws an
Require the developer of the system, system component, or system service, at all post-design stages of the system development life cycle, to: Develop