Skip to main content

Skills dans ce dépôt

CyberStrikeus/CyberStrike - Page 121

SkillsMP a collecté 7 442 skills depuis CyberStrikeus/CyberStrike. Ouvrez un skill pour examiner sa source et ses détails.

CyberStrikeus/CyberStrike

Affichage de 40 skills collectés sur 7 442.

métier
Analystes en sécurité de l'information
description

Authorize access to management of audit logging functionality to only [organization-defined].

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Enforce dual authorization for [organization-defined] of [organization-defined].

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Authorize read-only access to audit information to [organization-defined].

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Store audit information on a component running a different operating system than the system or component being audited.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Protect audit information and audit logging tools from unauthorized access, modification, and deletion;

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Develop, document, and disseminate to [organization-defined]: [organization-defined] assessment, authorization, and monitoring policy that: Procedures

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Employ independent assessors or assessment teams to conduct control assessments.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Include as part of control assessments, [organization-defined], [organization-defined], [organization-defined].

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Leverage the results of control assessments performed by [organization-defined] on [organization-defined] when the assessment meets [organization-defi

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Select the appropriate assessor or assessment team for the type of assessment to be conducted;

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Verify that individuals or systems transferring data between interconnecting systems have the requisite authorizations (i.e., write permissions or pri

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Identify transitive (downstream) information exchanges with other systems through the systems identified in [CA-3a](#ca-3_smt.a) ;

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Approve and manage the exchange of information between the system and other systems using [organization-defined];

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Security Certification

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Ensure the accuracy, currency, and availability of the plan of action and milestones for the system using [organization-defined].

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Develop a plan of action and milestones for the system to document the planned remediation actions of the organization to correct weaknesses or def...

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Employ a joint authorization process for the system that includes multiple authorizing officials from the same organization conducting the authorizati

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Employ a joint authorization process for the system that includes multiple authorizing officials with at least one authorizing official from an organi

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Assign a senior official as the authorizing official for the system;

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Employ independent assessors or assessment teams to monitor the controls in the system on an ongoing basis.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Types of Assessments

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Employ trend analyses to determine if control implementations, the frequency of continuous monitoring activities, and the types of activities used in

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Ensure risk monitoring is an integral part of the continuous monitoring strategy that includes the following: Effectiveness monitoring; Compliance mon

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Employ the following actions to validate that policies are established and implemented controls are operating in a consistent manner: [organization-de

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Ensure the accuracy, currency, and availability of monitoring results for the system using [organization-defined].

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Develop a system-level continuous monitoring strategy and implement continuous monitoring in accordance with the organization-level continuous monitor

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Employ an independent penetration testing agent or team to perform penetration testing on the system or system components.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Employ the following red-team exercises to simulate attempts by adversaries to compromise organizational systems in accordance with applicable rules o

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Employ a penetration testing process that includes [organization-defined] [organization-defined] attempts to bypass or circumvent controls associated

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Conduct penetration testing [organization-defined] on [organization-defined].

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Perform security and privacy compliance checks on constituent system components prior to the establishment of the internal connection.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Authorize internal connections of [organization-defined] to the system;

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Develop, document, and disseminate to [organization-defined]: [organization-defined] configuration management policy that: Procedures to facilitate th

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Establish the following restrictions on the use of open-source software: [organization-defined].

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Use software and associated documentation in accordance with contract agreements and copyright laws;

Langue du texte source : anglais

mis à jour
Affichage de 40 skills collectés sur 7 442.