03.13.05
Langue du texte source : anglais
Menu
Skills dans ce dépôt
SkillsMP a collecté 7 442 skills depuis CyberStrikeus/CyberStrike. Ouvrez un skill pour examiner sa source et ses détails.
CyberStrikeus/CyberStrikeAffichage de 40 skills collectés sur 7 442.
03.13.05
Langue du texte source : anglais
03.13.07
Langue du texte source : anglais
03.13.14
Langue du texte source : anglais
03.13.16
Langue du texte source : anglais
Identify, report, and correct system flaws.
Langue du texte source : anglais
Implement malicious code protection mechanisms at system entry and exit points to detect and eradicate malicious code.
Langue du texte source : anglais
03.14.04
Langue du texte source : anglais
03.14.05
Langue du texte source : anglais
03.14.07
Langue du texte source : anglais
Monitor the system to detect: Attacks and indicators of potential attacks and Unauthorized connections. Identify unauthorized use of the system. Monit
Langue du texte source : anglais
Develop, document, and disseminate to organizational personnel or roles the policies and procedures needed to satisfy the security requirements for...
Langue du texte source : anglais
Establish rules that describe the responsibilities and expected behavior for system usage and protecting CUI.
Langue du texte source : anglais
Develop a system security plan that: Defines the constituent system components; Identifies the information types processed, stored, and transmitted by
Langue du texte source : anglais
Require the providers of external system services used for the processing, storage, or transmission of CUI to comply with the following security re...
Langue du texte source : anglais
Identify and document all security requirements for the organization’s software development infrastructures and processes, and maintain the requiremen
Langue du texte source : anglais
Identify and document all security requirements for organization-developed software to meet, and maintain the requirements over time.
Langue du texte source : anglais
Communicate requirements to all third parties who will provide commercial software components to the organization for reuse by the organization’s o...
Langue du texte source : anglais
Create new roles and alter responsibilities for existing roles as needed to encompass all parts of the SDLC.
Langue du texte source : anglais
Provide role-based training for all personnel with responsibilities that contribute to secure development.
Langue du texte source : anglais
Obtain upper management or authorizing official commitment to secure development, and convey that commitment to all with development-related roles and
Langue du texte source : anglais
Specify which tools or tool types must or should be included in each toolchain to mitigate identified risks, as well as how the toolchain components a
Langue du texte source : anglais
Follow recommended security practices to deploy, operate, and maintain tools and toolchains.
Langue du texte source : anglais
Configure tools to generate artifacts of their support of secure software development practices as defined by the organization.
Langue du texte source : anglais
Define criteria for software security checks and track throughout the SDLC.
Langue du texte source : anglais
Implement processes, mechanisms, etc.
Langue du texte source : anglais
Separate and protect each environment involved in software development.
Langue du texte source : anglais
Secure and harden development endpoints (i.e., endpoints for software designers, developers, testers, builders, etc.) to perform development-related t
Langue du texte source : anglais
Store all forms of code – including source code, executable code, and configuration-as-code – based on the principle of least privilege so that onl...
Langue du texte source : anglais
Make software integrity verification information available to software acquirers.
Langue du texte source : anglais
Securely archive the necessary files and supporting data (e.g., integrity verification information, provenance data) to be retained for each software
Langue du texte source : anglais
Collect, safeguard, maintain, and share provenance data for all components of each software release (e.g., in a software bill of materials .SBOM).
Langue du texte source : anglais
Use forms of risk modeling – such as threat modeling, attack modeling, or attack surface mapping – to help assess the security risk for the software.
Langue du texte source : anglais
Track and maintain the software’s security requirements, risks, and design decisions.
Langue du texte source : anglais
Where appropriate, build in support for using standardized security features and services (e.g., enabling software to integrate with existing log m...
Langue du texte source : anglais
Have 1) a qualified person (or people) who were not involved with the design and/or 2) automated processes instantiated in the toolchain review the so
Langue du texte source : anglais
Acquire and maintain well-secured software components (e.g., software libraries, modules, middleware, frameworks) from commercial, open-source, and ot
Langue du texte source : anglais
Create and maintain well-secured software components in-house following SDLC processes to meet common internal software development needs that cannot
Langue du texte source : anglais
Verify that acquired commercial, open-source, and all other third-party software components comply with the requirements, as defined by the organizati
Langue du texte source : anglais
Follow all secure coding practices that are appropriate to the development languages and environment to meet the organization’s requirements.
Langue du texte source : anglais
Use compiler, interpreter, and build tools that offer features to improve executable security.
Langue du texte source : anglais