Determine which compiler, interpreter, and build tool features should be used and how each should be configured, then implement and use the approved c
Idioma do texto original: inglês
Menu
Skills neste repositório
O SkillsMP coletou 7.442 skills de CyberStrikeus/CyberStrike. Abra uma skill para revisar a origem e os detalhes.
CyberStrikeus/CyberStrikeMostrando 40 de 7.442 skills coletadas.
Determine which compiler, interpreter, and build tool features should be used and how each should be configured, then implement and use the approved c
Idioma do texto original: inglês
Determine whether code review (a person looks directly at the code to find issues) and/or code analysis (tools are used to find issues in code, either
Idioma do texto original: inglês
Perform the code review and/or code analysis based on the organization’s secure coding standards, and record and triage all discovered issues and reco
Idioma do texto original: inglês
Determine whether executable code testing should be performed to find vulnerabilities not identified by previous reviews, analysis, or testing and, if
Idioma do texto original: inglês
Scope the testing, design the tests, perform the testing, and document the results, including recording and triaging all discovered issues and recomme
Idioma do texto original: inglês
Define a secure baseline by determining how to configure each setting that has an effect on security or a security-related setting so that the default
Idioma do texto original: inglês
Implement the default settings (or groups of default settings, if applicable), and document each setting for software administrators.
Idioma do texto original: inglês
Gather information from software acquirers, users, and public sources on potential vulnerabilities in the software and third-party components that the
Idioma do texto original: inglês
Review, analyze, and/or test the software’s code to identify or confirm the presence of previously undetected vulnerabilities.
Idioma do texto original: inglês
Have a policy that addresses vulnerability disclosure and remediation, and implement the roles, responsibilities, and processes needed to support that
Idioma do texto original: inglês
Analyze each vulnerability to gather sufficient information about risk to plan its remediation or other risk response.
Idioma do texto original: inglês
Plan and implement risk responses for vulnerabilities.
Idioma do texto original: inglês
Analyze identified vulnerabilities to determine their root causes.
Idioma do texto original: inglês
Analyze the root causes over time to identify patterns, such as a particular secure coding practice not being followed consistently.
Idioma do texto original: inglês
Review the software for similar vulnerabilities to eradicate a class of vulnerabilities, and proactively fix them rather than waiting for external rep
Idioma do texto original: inglês
Review the SDLC process, and update it if appropriate to prevent (or reduce the likelihood of) the root cause recurring in updates to the software or
Idioma do texto original: inglês
Develop, document, and disseminate to [organization-defined]: [organization-defined] access control policy that: Procedures to facilitate the implemen
Idioma do texto original: inglês
Limit the number of concurrent sessions for each [organization-defined] to [organization-defined].
Idioma do texto original: inglês
Conceal, via the device lock, information previously visible on the display with a publicly viewable image.
Idioma do texto original: inglês
Prevent further access to the system by [organization-defined] ;
Idioma do texto original: inglês
Provide a logout capability for user-initiated communications sessions whenever authentication is used to gain access to [organization-defined].
Idioma do texto original: inglês
Display an explicit logout message to users indicating the termination of authenticated communications sessions.
Idioma do texto original: inglês
Display an explicit message to users indicating that the session will end in [organization-defined].
Idioma do texto original: inglês
Automatically terminate a user session after [organization-defined].
Idioma do texto original: inglês
Supervision and Review — Access Control
Idioma do texto original: inglês
Necessary Uses
Idioma do texto original: inglês
Identify [organization-defined] that can be performed on the system without identification or authentication consistent with organizational mission...
Idioma do texto original: inglês
Automated Marking
Idioma do texto original: inglês
Dynamically associate security and privacy attributes with [organization-defined] in accordance with the following security and privacy policies as in
Idioma do texto original: inglês
Provide authorized individuals the capability to define or change the type and value of security and privacy attributes available for association with
Idioma do texto original: inglês
Provide authorized individuals (or processes acting on behalf of individuals) the capability to define or change the value of associated security and
Idioma do texto original: inglês
Maintain the association and integrity of [organization-defined] to [organization-defined].
Idioma do texto original: inglês
Provide the capability to associate [organization-defined] with [organization-defined] by authorized individuals (or processes acting on behalf of ind
Idioma do texto original: inglês
Display security and privacy attributes in human-readable form on each object that the system transmits to output devices to identify [organization-de
Idioma do texto original: inglês
Require personnel to associate and maintain the association of [organization-defined] with [organization-defined] in accordance with [organization-def
Idioma do texto original: inglês
Provide a consistent interpretation of security and privacy attributes transmitted between distributed system components.
Idioma do texto original: inglês
Implement [organization-defined] in associating security and privacy attributes to information.
Idioma do texto original: inglês
Change security and privacy attributes associated with information only via regrading mechanisms validated using [organization-defined].
Idioma do texto original: inglês
Provide the means to associate [organization-defined] with [organization-defined] for information in storage, in process, and/or in transmission;
Idioma do texto original: inglês
Employ automated mechanisms to monitor and control remote access methods.
Idioma do texto original: inglês