Design [organization-defined] with coordinated behavior to implement the following capabilities: [organization-defined].
Skills in this repository
CyberStrikeus/CyberStrike - Page 135
SkillsMP has collected 7,442 skills from CyberStrikeus/CyberStrike. Open a skill to review its source and details.
CyberStrikeus/CyberStrikeShowing 40 of 7,442 collected skills.
Use different designs for [organization-defined] to satisfy a common set of requirements or to provide equivalent functionality.
Require the developer of the system, system component, or system service to produce a design specification and security and privacy architecture that:
Multiple Phases of System Development Life Cycle
Inspection of Systems or Components
Tamper Resistance and Detection
Anti-counterfeit Training
Configuration Control for Component Service and Repair
Component Disposal
Anti-counterfeit Scanning
Component Authenticity
Determine the high-level information security and privacy requirements for the system or system service in mission and business process planning;
Reimplement or custom develop the following critical system components: [organization-defined].
Validation of Screening
Require that the developer of [organization-defined]: Has appropriate access authorizations as determined by assigned [organization-defined] ; and Sat
Alternative Sources for Continued Support
Replace system components when support for the components is no longer available from the developer, vendor, or manufacturer;
Employ [organization-defined] on [organization-defined] supporting mission essential services or functions to increase the trustworthiness in those sy
Design organizational systems, system components, or system services to achieve cyber resiliency by: Defining the following cyber resiliency goals: [o
Protect system preproduction environments commensurate with risk throughout the system development life cycle for the system, system component, or sys
Approve, document, and control the use of live data in preproduction environments for the system, system component, or system service;
Plan for and implement a technology refresh schedule for the system throughout the system development life cycle.
Acquire, develop, and manage the system using [organization-defined] that incorporates information security and privacy considerations;
Require the developer of the system, system component, or system service to provide a description of the functional properties of the controls to be i
Employ only information technology products on the FIPS 201-approved products list for Personal Identity Verification (PIV) capability implemented wit
Include [organization-defined] in the acquisition contract for the operation of a system of records on behalf of an organization to accomplish an orga
Include organizational data ownership requirements in the acquisition contract;
Require the developer of the system, system component, or system service to provide design and implementation information for the controls that includ
Require the developer of the system, system component, or system service to demonstrate the use of a system development life cycle process that includ
Assignment of Components to Systems
Require the developer of the system, system component, or system service to: Deliver the system, component, or service with [organization-defined] imp
Employ only government off-the-shelf or commercial off-the-shelf information assurance and information assurance-enabled information technology pro...
Limit the use of commercially provided information assurance and information assurance-enabled information technology products to those products th...
Require the developer of the system, system component, or system service to produce a plan for continuous monitoring of control effectiveness that is
Require the developer of the system, system component, or system service to identify the functions, ports, protocols, and services intended for organi
Include the following requirements, descriptions, and criteria, explicitly or by reference, using [organization-defined] in the acquisition contract f
Functional Properties of Security Controls
Security-relevant External System Interfaces
High-level Design
Low-level Design