Establish, document, and maintain trust relationships with external service providers based on the following requirements, properties, factors, or con
Skills in this repository
CyberStrikeus/CyberStrike - Page 137
SkillsMP has collected 7,442 skills from CyberStrikeus/CyberStrike. Open a skill to review its source and details.
CyberStrikeus/CyberStrikeShowing 40 of 7,442 collected skills.
Take the following actions to verify that the interests of [organization-defined] are consistent with and reflect organizational interests: [organizat
Restrict the location of [organization-defined] to [organization-defined] based on [organization-defined].
Maintain exclusive control of cryptographic keys for encrypted material stored or transmitted through an external system.
Provide the capability to check the integrity of information while it resides in the external system.
Restrict the geographic location of information processing and data storage to facilities located within in the legal jurisdictional boundary of the U
Require that providers of external system services comply with organizational security and privacy requirements and employ the following controls: ...
Develop, document, and disseminate to [organization-defined]: [organization-defined] system and communications protection policy that: Procedures to f
Terminate the network connection associated with a communications session at the end of the session or after [organization-defined] of inactivity.
Provide a trusted communications path that is irrefutably distinguishable from other communications paths;
Provide a [organization-defined] isolated trusted communications path for communications between the user and the trusted components of the system;
Maintain availability of information in the event of the loss of cryptographic keys by users.
Produce, control, and distribute symmetric cryptographic keys using [organization-defined] key management technology and processes.
Produce, control, and distribute asymmetric cryptographic keys using [organization-defined].
PKI Certificates
PKI Certificates / Hardware Tokens
Maintain physical control of cryptographic keys when stored information is encrypted by external service providers.
Establish and manage cryptographic keys when cryptography is employed within the system in accordance with the following key management requirements:
FIPS-validated Cryptography
NSA-approved Cryptography
Individuals Without Formal Access Approvals
Digital Signatures
Determine the [organization-defined] ;
Public Access Protections
Provide [organization-defined] disconnect of collaborative computing devices in a manner that supports ease of use.
Blocking Inbound and Outbound Communications Traffic
Disable or remove collaborative computing devices and applications from [organization-defined] in [organization-defined].
Provide an explicit indication of current participants in [organization-defined].
Prohibit remote activation of collaborative computing devices and applications with the following exceptions: [organization-defined] ;
Verify the integrity of transmitted security and privacy attributes.
Implement anti-spoofing mechanisms to prevent adversaries from falsifying the security attributes indicating the successful application of the securit
Implement [organization-defined] to bind security and privacy attributes to transmitted information.
Associate [organization-defined] with information exchanged between systems and between system components.
Issue public key certificates under an [organization-defined] or obtain public key certificates from an approved service provider;
Identify [organization-defined] and take [organization-defined].
Verify that the acquisition, development, and use of mobile code to be deployed in the system meets [organization-defined].
Prevent the download and execution of [organization-defined].
Prevent the automatic execution of mobile code in [organization-defined] and enforce [organization-defined] prior to executing the code.
Allow execution of permitted mobile code only in confined virtual machine environments.
Define acceptable and unacceptable mobile code and mobile code technologies;