03.13.05
Idioma del texto original: inglés
Menú
Skills en este repositorio
SkillsMP ha recopilado 7442 skills de CyberStrikeus/CyberStrike. Abre una skill para revisar su origen y sus detalles.
CyberStrikeus/CyberStrikeMostrando 40 de 7442 skills recopiladas.
03.13.05
Idioma del texto original: inglés
03.13.07
Idioma del texto original: inglés
03.13.14
Idioma del texto original: inglés
03.13.16
Idioma del texto original: inglés
Identify, report, and correct system flaws.
Idioma del texto original: inglés
Implement malicious code protection mechanisms at system entry and exit points to detect and eradicate malicious code.
Idioma del texto original: inglés
03.14.04
Idioma del texto original: inglés
03.14.05
Idioma del texto original: inglés
03.14.07
Idioma del texto original: inglés
Monitor the system to detect: Attacks and indicators of potential attacks and Unauthorized connections. Identify unauthorized use of the system. Monit
Idioma del texto original: inglés
Develop, document, and disseminate to organizational personnel or roles the policies and procedures needed to satisfy the security requirements for...
Idioma del texto original: inglés
Establish rules that describe the responsibilities and expected behavior for system usage and protecting CUI.
Idioma del texto original: inglés
Develop a system security plan that: Defines the constituent system components; Identifies the information types processed, stored, and transmitted by
Idioma del texto original: inglés
Require the providers of external system services used for the processing, storage, or transmission of CUI to comply with the following security re...
Idioma del texto original: inglés
Identify and document all security requirements for the organization’s software development infrastructures and processes, and maintain the requiremen
Idioma del texto original: inglés
Identify and document all security requirements for organization-developed software to meet, and maintain the requirements over time.
Idioma del texto original: inglés
Communicate requirements to all third parties who will provide commercial software components to the organization for reuse by the organization’s o...
Idioma del texto original: inglés
Create new roles and alter responsibilities for existing roles as needed to encompass all parts of the SDLC.
Idioma del texto original: inglés
Provide role-based training for all personnel with responsibilities that contribute to secure development.
Idioma del texto original: inglés
Obtain upper management or authorizing official commitment to secure development, and convey that commitment to all with development-related roles and
Idioma del texto original: inglés
Specify which tools or tool types must or should be included in each toolchain to mitigate identified risks, as well as how the toolchain components a
Idioma del texto original: inglés
Follow recommended security practices to deploy, operate, and maintain tools and toolchains.
Idioma del texto original: inglés
Configure tools to generate artifacts of their support of secure software development practices as defined by the organization.
Idioma del texto original: inglés
Define criteria for software security checks and track throughout the SDLC.
Idioma del texto original: inglés
Implement processes, mechanisms, etc.
Idioma del texto original: inglés
Separate and protect each environment involved in software development.
Idioma del texto original: inglés
Secure and harden development endpoints (i.e., endpoints for software designers, developers, testers, builders, etc.) to perform development-related t
Idioma del texto original: inglés
Store all forms of code – including source code, executable code, and configuration-as-code – based on the principle of least privilege so that onl...
Idioma del texto original: inglés
Make software integrity verification information available to software acquirers.
Idioma del texto original: inglés
Securely archive the necessary files and supporting data (e.g., integrity verification information, provenance data) to be retained for each software
Idioma del texto original: inglés
Collect, safeguard, maintain, and share provenance data for all components of each software release (e.g., in a software bill of materials .SBOM).
Idioma del texto original: inglés
Use forms of risk modeling – such as threat modeling, attack modeling, or attack surface mapping – to help assess the security risk for the software.
Idioma del texto original: inglés
Track and maintain the software’s security requirements, risks, and design decisions.
Idioma del texto original: inglés
Where appropriate, build in support for using standardized security features and services (e.g., enabling software to integrate with existing log m...
Idioma del texto original: inglés
Have 1) a qualified person (or people) who were not involved with the design and/or 2) automated processes instantiated in the toolchain review the so
Idioma del texto original: inglés
Acquire and maintain well-secured software components (e.g., software libraries, modules, middleware, frameworks) from commercial, open-source, and ot
Idioma del texto original: inglés
Create and maintain well-secured software components in-house following SDLC processes to meet common internal software development needs that cannot
Idioma del texto original: inglés
Verify that acquired commercial, open-source, and all other third-party software components comply with the requirements, as defined by the organizati
Idioma del texto original: inglés
Follow all secure coding practices that are appropriate to the development languages and environment to meet the organization’s requirements.
Idioma del texto original: inglés
Use compiler, interpreter, and build tools that offer features to improve executable security.
Idioma del texto original: inglés