Planning and due diligence are performed to reduce risks before entering into formal supplier or other third-party relationships
원문 언어: 영어
메뉴
이 저장소의 skills
SkillsMP는 CyberStrikeus/CyberStrike에서 7,442개의 skill을 수집했습니다. skill을 열어 소스와 세부 정보를 확인하세요.
CyberStrikeus/CyberStrike수집된 skill 7,442개 중 40개를 표시합니다.
Planning and due diligence are performed to reduce risks before entering into formal supplier or other third-party relationships
원문 언어: 영어
The risks posed by a supplier, their products and services, and other third parties are understood, recorded, prioritized, assessed, responded to, and
원문 언어: 영어
Relevant suppliers and other third parties are included in incident planning, response, and recovery activities
원문 언어: 영어
Supply chain security practices are integrated into cybersecurity and enterprise risk management programs, and their performance is monitored througho
원문 언어: 영어
Cybersecurity supply chain risk management plans include provisions for activities that occur after the conclusion of a partnership or service agreeme
원문 언어: 영어
The circumstances - mission, stakeholder expectations, dependencies, and legal, regulatory, and contractual requirements - surrounding the organizatio
원문 언어: 영어
Results of organization-wide cybersecurity risk management activities and performance are used to inform, improve, and adjust the risk management stra
원문 언어: 영어
Organizational cybersecurity policy is established, communicated, and enforced
원문 언어: 영어
The organization's priorities, constraints, risk tolerance and appetite statements, and assumptions are established, communicated, and used to support
원문 언어: 영어
Assets (e.g., data, hardware, software, systems, facilities, services, people) that enable the organization to achieve business purposes are identifie
원문 언어: 영어
Business Environment
원문 언어: 영어
Governance
원문 언어: 영어
Inventories of hardware managed by the organization are maintained
원문 언어: 영어
Inventories of software, services, and systems managed by the organization are maintained
원문 언어: 영어
Representations of the organization's authorized network communication and internal and external network data flows are maintained
원문 언어: 영어
Inventories of services provided by suppliers are maintained
원문 언어: 영어
Assets are prioritized based on classification, criticality, resources, and impact on the mission
원문 언어: 영어
Cybersecurity roles and responsibilities for the entire workforce and third-party stakeholders (e.g., suppliers, customers, partners) are established
원문 언어: 영어
Inventories of data and corresponding metadata for designated data types are maintained
원문 언어: 영어
Systems, hardware, software, services, and data are managed throughout their life cycles
원문 언어: 영어
The organization’s role in the supply chain is identified and communicated
원문 언어: 영어
The organization’s place in critical infrastructure and its industry sector is identified and communicated
원문 언어: 영어
Priorities for organizational mission, objectives, and activities are established and communicated
원문 언어: 영어
Dependencies and critical functions for delivery of critical services are established
원문 언어: 영어
Resilience requirements to support delivery of critical services are established for all operating states (e.g.
원문 언어: 영어
Organizational cybersecurity policy is established and communicated
원문 언어: 영어
Cybersecurity roles and responsibilities are coordinated and aligned with internal roles and external partners
원문 언어: 영어
Legal and regulatory requirements regarding cybersecurity, including privacy and civil liberties obligations, are understood and managed
원문 언어: 영어
Governance and risk management processes address cybersecurity risks
원문 언어: 영어
Improvements are identified from evaluations
원문 언어: 영어
Improvements are identified from security tests and exercises, including those done in coordination with suppliers and relevant third parties
원문 언어: 영어
Improvements are identified from execution of operational processes, procedures, and activities
원문 언어: 영어
Incident response plans and other cybersecurity plans that affect operations are established, communicated, maintained, and improved
원문 언어: 영어
Vulnerabilities in assets are identified, validated, and recorded
원문 언어: 영어
Cyber threat intelligence is received from information sharing forums and sources
원문 언어: 영어
Internal and external threats to the organization are identified and recorded
원문 언어: 영어
Potential impacts and likelihoods of threats exploiting vulnerabilities are identified and recorded
원문 언어: 영어
Threats, vulnerabilities, likelihoods, and impacts are used to understand inherent risk and inform risk response prioritization
원문 언어: 영어
Risk responses are chosen, prioritized, planned, tracked, and communicated
원문 언어: 영어
Changes and exceptions are managed, assessed for risk impact, recorded, and tracked
원문 언어: 영어