Determine which compiler, interpreter, and build tool features should be used and how each should be configured, then implement and use the approved c
Quellsprache: Englisch
Menü
Skills in diesem Repository
SkillsMP hat 7.442 Skills aus CyberStrikeus/CyberStrike gesammelt. Öffne einen Skill, um Quelle und Details zu prüfen.
CyberStrikeus/CyberStrikeEs werden 40 von 7.442 gesammelten Skills angezeigt.
Determine which compiler, interpreter, and build tool features should be used and how each should be configured, then implement and use the approved c
Quellsprache: Englisch
Determine whether code review (a person looks directly at the code to find issues) and/or code analysis (tools are used to find issues in code, either
Quellsprache: Englisch
Perform the code review and/or code analysis based on the organization’s secure coding standards, and record and triage all discovered issues and reco
Quellsprache: Englisch
Determine whether executable code testing should be performed to find vulnerabilities not identified by previous reviews, analysis, or testing and, if
Quellsprache: Englisch
Scope the testing, design the tests, perform the testing, and document the results, including recording and triaging all discovered issues and recomme
Quellsprache: Englisch
Define a secure baseline by determining how to configure each setting that has an effect on security or a security-related setting so that the default
Quellsprache: Englisch
Implement the default settings (or groups of default settings, if applicable), and document each setting for software administrators.
Quellsprache: Englisch
Gather information from software acquirers, users, and public sources on potential vulnerabilities in the software and third-party components that the
Quellsprache: Englisch
Review, analyze, and/or test the software’s code to identify or confirm the presence of previously undetected vulnerabilities.
Quellsprache: Englisch
Have a policy that addresses vulnerability disclosure and remediation, and implement the roles, responsibilities, and processes needed to support that
Quellsprache: Englisch
Analyze each vulnerability to gather sufficient information about risk to plan its remediation or other risk response.
Quellsprache: Englisch
Plan and implement risk responses for vulnerabilities.
Quellsprache: Englisch
Analyze identified vulnerabilities to determine their root causes.
Quellsprache: Englisch
Analyze the root causes over time to identify patterns, such as a particular secure coding practice not being followed consistently.
Quellsprache: Englisch
Review the software for similar vulnerabilities to eradicate a class of vulnerabilities, and proactively fix them rather than waiting for external rep
Quellsprache: Englisch
Review the SDLC process, and update it if appropriate to prevent (or reduce the likelihood of) the root cause recurring in updates to the software or
Quellsprache: Englisch
Develop, document, and disseminate to [organization-defined]: [organization-defined] access control policy that: Procedures to facilitate the implemen
Quellsprache: Englisch
Limit the number of concurrent sessions for each [organization-defined] to [organization-defined].
Quellsprache: Englisch
Conceal, via the device lock, information previously visible on the display with a publicly viewable image.
Quellsprache: Englisch
Prevent further access to the system by [organization-defined] ;
Quellsprache: Englisch
Provide a logout capability for user-initiated communications sessions whenever authentication is used to gain access to [organization-defined].
Quellsprache: Englisch
Display an explicit logout message to users indicating the termination of authenticated communications sessions.
Quellsprache: Englisch
Display an explicit message to users indicating that the session will end in [organization-defined].
Quellsprache: Englisch
Automatically terminate a user session after [organization-defined].
Quellsprache: Englisch
Supervision and Review — Access Control
Quellsprache: Englisch
Necessary Uses
Quellsprache: Englisch
Identify [organization-defined] that can be performed on the system without identification or authentication consistent with organizational mission...
Quellsprache: Englisch
Automated Marking
Quellsprache: Englisch
Dynamically associate security and privacy attributes with [organization-defined] in accordance with the following security and privacy policies as in
Quellsprache: Englisch
Provide authorized individuals the capability to define or change the type and value of security and privacy attributes available for association with
Quellsprache: Englisch
Provide authorized individuals (or processes acting on behalf of individuals) the capability to define or change the value of associated security and
Quellsprache: Englisch
Maintain the association and integrity of [organization-defined] to [organization-defined].
Quellsprache: Englisch
Provide the capability to associate [organization-defined] with [organization-defined] by authorized individuals (or processes acting on behalf of ind
Quellsprache: Englisch
Display security and privacy attributes in human-readable form on each object that the system transmits to output devices to identify [organization-de
Quellsprache: Englisch
Require personnel to associate and maintain the association of [organization-defined] with [organization-defined] in accordance with [organization-def
Quellsprache: Englisch
Provide a consistent interpretation of security and privacy attributes transmitted between distributed system components.
Quellsprache: Englisch
Implement [organization-defined] in associating security and privacy attributes to information.
Quellsprache: Englisch
Change security and privacy attributes associated with information only via regrading mechanisms validated using [organization-defined].
Quellsprache: Englisch
Provide the means to associate [organization-defined] with [organization-defined] for information in storage, in process, and/or in transmission;
Quellsprache: Englisch
Employ automated mechanisms to monitor and control remote access methods.
Quellsprache: Englisch