Categorize the system and information it processes, stores, and transmits;
Quellsprache: Englisch
Menü
Skills in diesem Repository
SkillsMP hat 7.442 Skills aus CyberStrikeus/CyberStrike gesammelt. Öffne einen Skill, um Quelle und Details zu prüfen.
CyberStrikeus/CyberStrikeEs werden 40 von 7.442 gesammelten Skills angezeigt.
Categorize the system and information it processes, stores, and transmits;
Quellsprache: Englisch
Assess supply chain risks associated with [organization-defined] ;
Quellsprache: Englisch
Use all-source intelligence to assist in the analysis of risk.
Quellsprache: Englisch
Determine the current cyber threat environment on an ongoing basis using [organization-defined].
Quellsprache: Englisch
Employ the following advanced automation and analytics capabilities to predict and identify risks to [organization-defined]: [organization-defined].
Quellsprache: Englisch
Conduct a risk assessment, including: Identifying threats to and vulnerabilities in the system; Determining the likelihood and magnitude of harm from
Quellsprache: Englisch
Risk Assessment Update
Quellsprache: Englisch
Update Tool Capability
Quellsprache: Englisch
Correlate the output from vulnerability scanning tools to determine the presence of multi-vulnerability and multi-hop attack vectors.
Quellsprache: Englisch
Establish a public reporting channel for receiving reports of vulnerabilities in organizational systems and system components.
Quellsprache: Englisch
Update the system vulnerabilities to be scanned [organization-defined].
Quellsprache: Englisch
Define the breadth and depth of vulnerability scanning coverage.
Quellsprache: Englisch
Determine information about the system that is discoverable and take [organization-defined].
Quellsprache: Englisch
Implement privileged access authorization to [organization-defined] for [organization-defined].
Quellsprache: Englisch
Compare the results of multiple vulnerability scans using [organization-defined].
Quellsprache: Englisch
Review historic audit logs to determine if a vulnerability identified in a [organization-defined] has been previously exploited within an [organizatio
Quellsprache: Englisch
Penetration Testing and Analyses
Quellsprache: Englisch
Monitor and scan for vulnerabilities in the system and hosted applications [organization-defined] and when new vulnerabilities potentially affectin...
Quellsprache: Englisch
Employ a technical surveillance countermeasures survey at [organization-defined] [organization-defined].
Quellsprache: Englisch
Respond to findings from security and privacy assessments, monitoring, and audits in accordance with organizational risk tolerance.
Quellsprache: Englisch
Conduct privacy impact assessments for systems, programs, or other activities before: Developing or procuring information technology that processes pe
Quellsprache: Englisch
Identify critical system components and functions by performing a criticality analysis for [organization-defined] at [organization-defined].
Quellsprache: Englisch
Develop, document, and disseminate to [organization-defined]: [organization-defined] system and services acquisition policy that: Procedures to facili
Quellsprache: Englisch
Require the developer of the system, system component, or system service to enable integrity verification of software and firmware components.
Quellsprache: Englisch
Provide an alternate configuration management process using organizational personnel in the absence of a dedicated developer configuration management
Quellsprache: Englisch
Require the developer of the system, system component, or system service to enable integrity verification of hardware components.
Quellsprache: Englisch
Require the developer of the system, system component, or system service to employ tools for comparing newly generated versions of security-relevant h
Quellsprache: Englisch
Require the developer of the system, system component, or system service to maintain the integrity of the mapping between the master build data descri
Quellsprache: Englisch
Require the developer of the system, system component, or system service to execute procedures for ensuring that security-relevant hardware, software,
Quellsprache: Englisch
Require [organization-defined] to be included in the [organization-defined].
Quellsprache: Englisch
Require the developer of the system, system component, or system service to: Perform configuration management during system, component, or service [or
Quellsprache: Englisch
Require the developer of the system, system component, or system service to employ static code analysis tools to identify common flaws and document th
Quellsprache: Englisch
Require the developer of the system, system component, or system service to perform threat modeling and vulnerability analyses during development and
Quellsprache: Englisch
Require the developer of the system, system component, or system service to perform a manual code review of [organization-defined] using the following
Quellsprache: Englisch
Require the developer of the system, system component, or system service to perform penetration testing: At the following level of rigor: [organizatio
Quellsprache: Englisch
Require the developer of the system, system component, or system service to perform attack surface reviews.
Quellsprache: Englisch
Require the developer of the system, system component, or system service to verify that the scope of testing and evaluation provides complete coverage
Quellsprache: Englisch
Require the developer of the system, system component, or system service to employ dynamic code analysis tools to identify common flaws and document t
Quellsprache: Englisch
Require the developer of the system, system component, or system service to employ interactive application security testing tools to identify flaws an
Quellsprache: Englisch
Require the developer of the system, system component, or system service, at all post-design stages of the system development life cycle, to: Develop
Quellsprache: Englisch