For password-based authentication: Maintain a list of commonly-used, expected, or compromised passwords and update the list [organization-defined] and
Quellsprache: Englisch
Menü
Skills in diesem Repository
SkillsMP hat 7.442 Skills aus CyberStrikeus/CyberStrike gesammelt. Öffne einen Skill, um Quelle und Details zu prüfen.
CyberStrikeus/CyberStrikeEs werden 40 von 7.442 gesammelten Skills angezeigt.
For password-based authentication: Maintain a list of commonly-used, expected, or compromised passwords and update the list [organization-defined] and
Quellsprache: Englisch
Bind identities and authenticators dynamically using the following rules: [organization-defined].
Quellsprache: Englisch
Hardware Token-based Authentication
Quellsprache: Englisch
For biometric-based authentication, employ mechanisms that satisfy the following biometric quality requirements [organization-defined].
Quellsprache: Englisch
Prohibit the use of cached authenticators after [organization-defined].
Quellsprache: Englisch
For PKI-based authentication, employ an organization-wide methodology for managing the content of PKI trust stores installed across all platforms, inc
Quellsprache: Englisch
Use only General Services Administration-approved products and services for identity, credential, and access management.
Quellsprache: Englisch
Employ [organization-defined] to generate and manage passwords;
Quellsprache: Englisch
For public key-based authentication: Enforce authorized access to the corresponding private key; and Map the authenticated identity to the account of
Quellsprache: Englisch
In-person or Trusted External Party Registration
Quellsprache: Englisch
Automated Support for Password Strength Determination
Quellsprache: Englisch
Require developers and installers of system components to provide unique authenticators or change default authenticators prior to delivery and install
Quellsprache: Englisch
Protect authenticators commensurate with the security category of the information to which use of the authenticator permits access.
Quellsprache: Englisch
Ensure that unencrypted static authenticators are not embedded in applications or other forms of static storage.
Quellsprache: Englisch
Implement [organization-defined] to manage the risk of compromise due to individuals having accounts on multiple systems.
Quellsprache: Englisch
Use the following external organizations to federate credentials: [organization-defined].
Quellsprache: Englisch
Manage system authenticators by: Verifying, as part of the initial authenticator distribution, the identity of the individual, group, role, service, o
Quellsprache: Englisch
Obscure feedback of authentication information during the authentication process to protect the information from possible exploitation and use by unau
Quellsprache: Englisch
Implement mechanisms for authentication to a cryptographic module that meet the requirements of applicable laws, executive orders, directives, policie
Quellsprache: Englisch
Accept and electronically verify Personal Identity Verification-compliant credentials from other federal agencies.
Quellsprache: Englisch
Accept only external authenticators that are NIST-compliant;
Quellsprache: Englisch
Use of FICAM-approved Products
Quellsprache: Englisch
Conform to the following profiles for identity management [organization-defined].
Quellsprache: Englisch
Accept and verify federated or PKI credentials that meet [organization-defined].
Quellsprache: Englisch
Implement the following measures to disassociate user attributes or identifier assertion relationships among individuals, credential service providers
Quellsprache: Englisch
Uniquely identify and authenticate non-organizational users or processes acting on behalf of non-organizational users.
Quellsprache: Englisch
Information Exchange
Quellsprache: Englisch
Transmission of Decisions
Quellsprache: Englisch
Uniquely identify and authenticate [organization-defined] before establishing communications with devices, users, or other services or applications.
Quellsprache: Englisch
Develop, document, and disseminate to [organization-defined]: [organization-defined] incident response policy that: Procedures to facilitate the imple
Quellsprache: Englisch
Integrated Information Security Analysis Team
Quellsprache: Englisch
Incorporate simulated events into incident response training to facilitate the required response by personnel in crisis situations.
Quellsprache: Englisch
Provide an incident response training environment using [organization-defined].
Quellsprache: Englisch
Provide incident response training on how to identify and respond to a breach, including the organization’s process for reporting a breach.
Quellsprache: Englisch
Provide incident response training to system users consistent with assigned roles and responsibilities: Within [organization-defined] of assuming an i
Quellsprache: Englisch
Test the incident response capability using [organization-defined].
Quellsprache: Englisch
Coordinate incident response testing with organizational elements responsible for related plans.
Quellsprache: Englisch
Use qualitative and quantitative data from testing to: Determine the effectiveness of incident response processes; Continuously improve incident respo
Quellsprache: Englisch
Test the effectiveness of the incident response capability for the system [organization-defined] using the following tests: [organization-defined].
Quellsprache: Englisch
Support the incident handling process using [organization-defined].
Quellsprache: Englisch