Categorize the system and information it processes, stores, and transmits;
Idioma del texto original: inglés
Menú
Skills en este repositorio
SkillsMP ha recopilado 7442 skills de CyberStrikeus/CyberStrike. Abre una skill para revisar su origen y sus detalles.
CyberStrikeus/CyberStrikeMostrando 40 de 7442 skills recopiladas.
Categorize the system and information it processes, stores, and transmits;
Idioma del texto original: inglés
Assess supply chain risks associated with [organization-defined] ;
Idioma del texto original: inglés
Use all-source intelligence to assist in the analysis of risk.
Idioma del texto original: inglés
Determine the current cyber threat environment on an ongoing basis using [organization-defined].
Idioma del texto original: inglés
Employ the following advanced automation and analytics capabilities to predict and identify risks to [organization-defined]: [organization-defined].
Idioma del texto original: inglés
Conduct a risk assessment, including: Identifying threats to and vulnerabilities in the system; Determining the likelihood and magnitude of harm from
Idioma del texto original: inglés
Risk Assessment Update
Idioma del texto original: inglés
Update Tool Capability
Idioma del texto original: inglés
Correlate the output from vulnerability scanning tools to determine the presence of multi-vulnerability and multi-hop attack vectors.
Idioma del texto original: inglés
Establish a public reporting channel for receiving reports of vulnerabilities in organizational systems and system components.
Idioma del texto original: inglés
Update the system vulnerabilities to be scanned [organization-defined].
Idioma del texto original: inglés
Define the breadth and depth of vulnerability scanning coverage.
Idioma del texto original: inglés
Determine information about the system that is discoverable and take [organization-defined].
Idioma del texto original: inglés
Implement privileged access authorization to [organization-defined] for [organization-defined].
Idioma del texto original: inglés
Compare the results of multiple vulnerability scans using [organization-defined].
Idioma del texto original: inglés
Review historic audit logs to determine if a vulnerability identified in a [organization-defined] has been previously exploited within an [organizatio
Idioma del texto original: inglés
Penetration Testing and Analyses
Idioma del texto original: inglés
Monitor and scan for vulnerabilities in the system and hosted applications [organization-defined] and when new vulnerabilities potentially affectin...
Idioma del texto original: inglés
Employ a technical surveillance countermeasures survey at [organization-defined] [organization-defined].
Idioma del texto original: inglés
Respond to findings from security and privacy assessments, monitoring, and audits in accordance with organizational risk tolerance.
Idioma del texto original: inglés
Conduct privacy impact assessments for systems, programs, or other activities before: Developing or procuring information technology that processes pe
Idioma del texto original: inglés
Identify critical system components and functions by performing a criticality analysis for [organization-defined] at [organization-defined].
Idioma del texto original: inglés
Develop, document, and disseminate to [organization-defined]: [organization-defined] system and services acquisition policy that: Procedures to facili
Idioma del texto original: inglés
Require the developer of the system, system component, or system service to enable integrity verification of software and firmware components.
Idioma del texto original: inglés
Provide an alternate configuration management process using organizational personnel in the absence of a dedicated developer configuration management
Idioma del texto original: inglés
Require the developer of the system, system component, or system service to enable integrity verification of hardware components.
Idioma del texto original: inglés
Require the developer of the system, system component, or system service to employ tools for comparing newly generated versions of security-relevant h
Idioma del texto original: inglés
Require the developer of the system, system component, or system service to maintain the integrity of the mapping between the master build data descri
Idioma del texto original: inglés
Require the developer of the system, system component, or system service to execute procedures for ensuring that security-relevant hardware, software,
Idioma del texto original: inglés
Require [organization-defined] to be included in the [organization-defined].
Idioma del texto original: inglés
Require the developer of the system, system component, or system service to: Perform configuration management during system, component, or service [or
Idioma del texto original: inglés
Require the developer of the system, system component, or system service to employ static code analysis tools to identify common flaws and document th
Idioma del texto original: inglés
Require the developer of the system, system component, or system service to perform threat modeling and vulnerability analyses during development and
Idioma del texto original: inglés
Require the developer of the system, system component, or system service to perform a manual code review of [organization-defined] using the following
Idioma del texto original: inglés
Require the developer of the system, system component, or system service to perform penetration testing: At the following level of rigor: [organizatio
Idioma del texto original: inglés
Require the developer of the system, system component, or system service to perform attack surface reviews.
Idioma del texto original: inglés
Require the developer of the system, system component, or system service to verify that the scope of testing and evaluation provides complete coverage
Idioma del texto original: inglés
Require the developer of the system, system component, or system service to employ dynamic code analysis tools to identify common flaws and document t
Idioma del texto original: inglés
Require the developer of the system, system component, or system service to employ interactive application security testing tools to identify flaws an
Idioma del texto original: inglés
Require the developer of the system, system component, or system service, at all post-design stages of the system development life cycle, to: Develop
Idioma del texto original: inglés