Planning and due diligence are performed to reduce risks before entering into formal supplier or other third-party relationships
原文の言語: 英語
メニュー
このリポジトリの skills
SkillsMP は CyberStrikeus/CyberStrike から 7,442 件の skill を収集しています。skill を開くとソースと詳細を確認できます。
CyberStrikeus/CyberStrike収集済み skill 7,442 件中 40 件を表示しています。
Planning and due diligence are performed to reduce risks before entering into formal supplier or other third-party relationships
原文の言語: 英語
The risks posed by a supplier, their products and services, and other third parties are understood, recorded, prioritized, assessed, responded to, and
原文の言語: 英語
Relevant suppliers and other third parties are included in incident planning, response, and recovery activities
原文の言語: 英語
Supply chain security practices are integrated into cybersecurity and enterprise risk management programs, and their performance is monitored througho
原文の言語: 英語
Cybersecurity supply chain risk management plans include provisions for activities that occur after the conclusion of a partnership or service agreeme
原文の言語: 英語
The circumstances - mission, stakeholder expectations, dependencies, and legal, regulatory, and contractual requirements - surrounding the organizatio
原文の言語: 英語
Results of organization-wide cybersecurity risk management activities and performance are used to inform, improve, and adjust the risk management stra
原文の言語: 英語
Organizational cybersecurity policy is established, communicated, and enforced
原文の言語: 英語
The organization's priorities, constraints, risk tolerance and appetite statements, and assumptions are established, communicated, and used to support
原文の言語: 英語
Assets (e.g., data, hardware, software, systems, facilities, services, people) that enable the organization to achieve business purposes are identifie
原文の言語: 英語
Business Environment
原文の言語: 英語
Governance
原文の言語: 英語
Inventories of hardware managed by the organization are maintained
原文の言語: 英語
Inventories of software, services, and systems managed by the organization are maintained
原文の言語: 英語
Representations of the organization's authorized network communication and internal and external network data flows are maintained
原文の言語: 英語
Inventories of services provided by suppliers are maintained
原文の言語: 英語
Assets are prioritized based on classification, criticality, resources, and impact on the mission
原文の言語: 英語
Cybersecurity roles and responsibilities for the entire workforce and third-party stakeholders (e.g., suppliers, customers, partners) are established
原文の言語: 英語
Inventories of data and corresponding metadata for designated data types are maintained
原文の言語: 英語
Systems, hardware, software, services, and data are managed throughout their life cycles
原文の言語: 英語
The organization’s role in the supply chain is identified and communicated
原文の言語: 英語
The organization’s place in critical infrastructure and its industry sector is identified and communicated
原文の言語: 英語
Priorities for organizational mission, objectives, and activities are established and communicated
原文の言語: 英語
Dependencies and critical functions for delivery of critical services are established
原文の言語: 英語
Resilience requirements to support delivery of critical services are established for all operating states (e.g.
原文の言語: 英語
Organizational cybersecurity policy is established and communicated
原文の言語: 英語
Cybersecurity roles and responsibilities are coordinated and aligned with internal roles and external partners
原文の言語: 英語
Legal and regulatory requirements regarding cybersecurity, including privacy and civil liberties obligations, are understood and managed
原文の言語: 英語
Governance and risk management processes address cybersecurity risks
原文の言語: 英語
Improvements are identified from evaluations
原文の言語: 英語
Improvements are identified from security tests and exercises, including those done in coordination with suppliers and relevant third parties
原文の言語: 英語
Improvements are identified from execution of operational processes, procedures, and activities
原文の言語: 英語
Incident response plans and other cybersecurity plans that affect operations are established, communicated, maintained, and improved
原文の言語: 英語
Vulnerabilities in assets are identified, validated, and recorded
原文の言語: 英語
Cyber threat intelligence is received from information sharing forums and sources
原文の言語: 英語
Internal and external threats to the organization are identified and recorded
原文の言語: 英語
Potential impacts and likelihoods of threats exploiting vulnerabilities are identified and recorded
原文の言語: 英語
Threats, vulnerabilities, likelihoods, and impacts are used to understand inherent risk and inform risk response prioritization
原文の言語: 英語
Risk responses are chosen, prioritized, planned, tracked, and communicated
原文の言語: 英語
Changes and exceptions are managed, assessed for risk impact, recorded, and tracked
原文の言語: 英語