For password-based authentication: Maintain a list of commonly-used, expected, or compromised passwords and update the list [organization-defined] and
Idioma del texto original: inglés
Menú
Skills en este repositorio
SkillsMP ha recopilado 7442 skills de CyberStrikeus/CyberStrike. Abre una skill para revisar su origen y sus detalles.
CyberStrikeus/CyberStrikeMostrando 40 de 7442 skills recopiladas.
For password-based authentication: Maintain a list of commonly-used, expected, or compromised passwords and update the list [organization-defined] and
Idioma del texto original: inglés
Bind identities and authenticators dynamically using the following rules: [organization-defined].
Idioma del texto original: inglés
Hardware Token-based Authentication
Idioma del texto original: inglés
For biometric-based authentication, employ mechanisms that satisfy the following biometric quality requirements [organization-defined].
Idioma del texto original: inglés
Prohibit the use of cached authenticators after [organization-defined].
Idioma del texto original: inglés
For PKI-based authentication, employ an organization-wide methodology for managing the content of PKI trust stores installed across all platforms, inc
Idioma del texto original: inglés
Use only General Services Administration-approved products and services for identity, credential, and access management.
Idioma del texto original: inglés
Employ [organization-defined] to generate and manage passwords;
Idioma del texto original: inglés
For public key-based authentication: Enforce authorized access to the corresponding private key; and Map the authenticated identity to the account of
Idioma del texto original: inglés
In-person or Trusted External Party Registration
Idioma del texto original: inglés
Automated Support for Password Strength Determination
Idioma del texto original: inglés
Require developers and installers of system components to provide unique authenticators or change default authenticators prior to delivery and install
Idioma del texto original: inglés
Protect authenticators commensurate with the security category of the information to which use of the authenticator permits access.
Idioma del texto original: inglés
Ensure that unencrypted static authenticators are not embedded in applications or other forms of static storage.
Idioma del texto original: inglés
Implement [organization-defined] to manage the risk of compromise due to individuals having accounts on multiple systems.
Idioma del texto original: inglés
Use the following external organizations to federate credentials: [organization-defined].
Idioma del texto original: inglés
Manage system authenticators by: Verifying, as part of the initial authenticator distribution, the identity of the individual, group, role, service, o
Idioma del texto original: inglés
Obscure feedback of authentication information during the authentication process to protect the information from possible exploitation and use by unau
Idioma del texto original: inglés
Implement mechanisms for authentication to a cryptographic module that meet the requirements of applicable laws, executive orders, directives, policie
Idioma del texto original: inglés
Accept and electronically verify Personal Identity Verification-compliant credentials from other federal agencies.
Idioma del texto original: inglés
Accept only external authenticators that are NIST-compliant;
Idioma del texto original: inglés
Use of FICAM-approved Products
Idioma del texto original: inglés
Conform to the following profiles for identity management [organization-defined].
Idioma del texto original: inglés
Accept and verify federated or PKI credentials that meet [organization-defined].
Idioma del texto original: inglés
Implement the following measures to disassociate user attributes or identifier assertion relationships among individuals, credential service providers
Idioma del texto original: inglés
Uniquely identify and authenticate non-organizational users or processes acting on behalf of non-organizational users.
Idioma del texto original: inglés
Information Exchange
Idioma del texto original: inglés
Transmission of Decisions
Idioma del texto original: inglés
Uniquely identify and authenticate [organization-defined] before establishing communications with devices, users, or other services or applications.
Idioma del texto original: inglés
Develop, document, and disseminate to [organization-defined]: [organization-defined] incident response policy that: Procedures to facilitate the imple
Idioma del texto original: inglés
Integrated Information Security Analysis Team
Idioma del texto original: inglés
Incorporate simulated events into incident response training to facilitate the required response by personnel in crisis situations.
Idioma del texto original: inglés
Provide an incident response training environment using [organization-defined].
Idioma del texto original: inglés
Provide incident response training on how to identify and respond to a breach, including the organization’s process for reporting a breach.
Idioma del texto original: inglés
Provide incident response training to system users consistent with assigned roles and responsibilities: Within [organization-defined] of assuming an i
Idioma del texto original: inglés
Test the incident response capability using [organization-defined].
Idioma del texto original: inglés
Coordinate incident response testing with organizational elements responsible for related plans.
Idioma del texto original: inglés
Use qualitative and quantitative data from testing to: Determine the effectiveness of incident response processes; Continuously improve incident respo
Idioma del texto original: inglés
Test the effectiveness of the incident response capability for the system [organization-defined] using the following tests: [organization-defined].
Idioma del texto original: inglés
Support the incident handling process using [organization-defined].
Idioma del texto original: inglés