For password-based authentication: Maintain a list of commonly-used, expected, or compromised passwords and update the list [organization-defined] and
Langue du texte source : anglais
Menu
Skills dans ce dépôt
SkillsMP a collecté 7 442 skills depuis CyberStrikeus/CyberStrike. Ouvrez un skill pour examiner sa source et ses détails.
CyberStrikeus/CyberStrikeAffichage de 40 skills collectés sur 7 442.
For password-based authentication: Maintain a list of commonly-used, expected, or compromised passwords and update the list [organization-defined] and
Langue du texte source : anglais
Bind identities and authenticators dynamically using the following rules: [organization-defined].
Langue du texte source : anglais
Hardware Token-based Authentication
Langue du texte source : anglais
For biometric-based authentication, employ mechanisms that satisfy the following biometric quality requirements [organization-defined].
Langue du texte source : anglais
Prohibit the use of cached authenticators after [organization-defined].
Langue du texte source : anglais
For PKI-based authentication, employ an organization-wide methodology for managing the content of PKI trust stores installed across all platforms, inc
Langue du texte source : anglais
Use only General Services Administration-approved products and services for identity, credential, and access management.
Langue du texte source : anglais
Employ [organization-defined] to generate and manage passwords;
Langue du texte source : anglais
For public key-based authentication: Enforce authorized access to the corresponding private key; and Map the authenticated identity to the account of
Langue du texte source : anglais
In-person or Trusted External Party Registration
Langue du texte source : anglais
Automated Support for Password Strength Determination
Langue du texte source : anglais
Require developers and installers of system components to provide unique authenticators or change default authenticators prior to delivery and install
Langue du texte source : anglais
Protect authenticators commensurate with the security category of the information to which use of the authenticator permits access.
Langue du texte source : anglais
Ensure that unencrypted static authenticators are not embedded in applications or other forms of static storage.
Langue du texte source : anglais
Implement [organization-defined] to manage the risk of compromise due to individuals having accounts on multiple systems.
Langue du texte source : anglais
Use the following external organizations to federate credentials: [organization-defined].
Langue du texte source : anglais
Manage system authenticators by: Verifying, as part of the initial authenticator distribution, the identity of the individual, group, role, service, o
Langue du texte source : anglais
Obscure feedback of authentication information during the authentication process to protect the information from possible exploitation and use by unau
Langue du texte source : anglais
Implement mechanisms for authentication to a cryptographic module that meet the requirements of applicable laws, executive orders, directives, policie
Langue du texte source : anglais
Accept and electronically verify Personal Identity Verification-compliant credentials from other federal agencies.
Langue du texte source : anglais
Accept only external authenticators that are NIST-compliant;
Langue du texte source : anglais
Use of FICAM-approved Products
Langue du texte source : anglais
Conform to the following profiles for identity management [organization-defined].
Langue du texte source : anglais
Accept and verify federated or PKI credentials that meet [organization-defined].
Langue du texte source : anglais
Implement the following measures to disassociate user attributes or identifier assertion relationships among individuals, credential service providers
Langue du texte source : anglais
Uniquely identify and authenticate non-organizational users or processes acting on behalf of non-organizational users.
Langue du texte source : anglais
Information Exchange
Langue du texte source : anglais
Transmission of Decisions
Langue du texte source : anglais
Uniquely identify and authenticate [organization-defined] before establishing communications with devices, users, or other services or applications.
Langue du texte source : anglais
Develop, document, and disseminate to [organization-defined]: [organization-defined] incident response policy that: Procedures to facilitate the imple
Langue du texte source : anglais
Integrated Information Security Analysis Team
Langue du texte source : anglais
Incorporate simulated events into incident response training to facilitate the required response by personnel in crisis situations.
Langue du texte source : anglais
Provide an incident response training environment using [organization-defined].
Langue du texte source : anglais
Provide incident response training on how to identify and respond to a breach, including the organization’s process for reporting a breach.
Langue du texte source : anglais
Provide incident response training to system users consistent with assigned roles and responsibilities: Within [organization-defined] of assuming an i
Langue du texte source : anglais
Test the incident response capability using [organization-defined].
Langue du texte source : anglais
Coordinate incident response testing with organizational elements responsible for related plans.
Langue du texte source : anglais
Use qualitative and quantitative data from testing to: Determine the effectiveness of incident response processes; Continuously improve incident respo
Langue du texte source : anglais
Test the effectiveness of the incident response capability for the system [organization-defined] using the following tests: [organization-defined].
Langue du texte source : anglais
Support the incident handling process using [organization-defined].
Langue du texte source : anglais