For password-based authentication: Maintain a list of commonly-used, expected, or compromised passwords and update the list [organization-defined] and
Idioma do texto original: inglês
Menu
Skills neste repositório
O SkillsMP coletou 7.442 skills de CyberStrikeus/CyberStrike. Abra uma skill para revisar a origem e os detalhes.
CyberStrikeus/CyberStrikeMostrando 40 de 7.442 skills coletadas.
For password-based authentication: Maintain a list of commonly-used, expected, or compromised passwords and update the list [organization-defined] and
Idioma do texto original: inglês
Bind identities and authenticators dynamically using the following rules: [organization-defined].
Idioma do texto original: inglês
Hardware Token-based Authentication
Idioma do texto original: inglês
For biometric-based authentication, employ mechanisms that satisfy the following biometric quality requirements [organization-defined].
Idioma do texto original: inglês
Prohibit the use of cached authenticators after [organization-defined].
Idioma do texto original: inglês
For PKI-based authentication, employ an organization-wide methodology for managing the content of PKI trust stores installed across all platforms, inc
Idioma do texto original: inglês
Use only General Services Administration-approved products and services for identity, credential, and access management.
Idioma do texto original: inglês
Employ [organization-defined] to generate and manage passwords;
Idioma do texto original: inglês
For public key-based authentication: Enforce authorized access to the corresponding private key; and Map the authenticated identity to the account of
Idioma do texto original: inglês
In-person or Trusted External Party Registration
Idioma do texto original: inglês
Automated Support for Password Strength Determination
Idioma do texto original: inglês
Require developers and installers of system components to provide unique authenticators or change default authenticators prior to delivery and install
Idioma do texto original: inglês
Protect authenticators commensurate with the security category of the information to which use of the authenticator permits access.
Idioma do texto original: inglês
Ensure that unencrypted static authenticators are not embedded in applications or other forms of static storage.
Idioma do texto original: inglês
Implement [organization-defined] to manage the risk of compromise due to individuals having accounts on multiple systems.
Idioma do texto original: inglês
Use the following external organizations to federate credentials: [organization-defined].
Idioma do texto original: inglês
Manage system authenticators by: Verifying, as part of the initial authenticator distribution, the identity of the individual, group, role, service, o
Idioma do texto original: inglês
Obscure feedback of authentication information during the authentication process to protect the information from possible exploitation and use by unau
Idioma do texto original: inglês
Implement mechanisms for authentication to a cryptographic module that meet the requirements of applicable laws, executive orders, directives, policie
Idioma do texto original: inglês
Accept and electronically verify Personal Identity Verification-compliant credentials from other federal agencies.
Idioma do texto original: inglês
Accept only external authenticators that are NIST-compliant;
Idioma do texto original: inglês
Use of FICAM-approved Products
Idioma do texto original: inglês
Conform to the following profiles for identity management [organization-defined].
Idioma do texto original: inglês
Accept and verify federated or PKI credentials that meet [organization-defined].
Idioma do texto original: inglês
Implement the following measures to disassociate user attributes or identifier assertion relationships among individuals, credential service providers
Idioma do texto original: inglês
Uniquely identify and authenticate non-organizational users or processes acting on behalf of non-organizational users.
Idioma do texto original: inglês
Information Exchange
Idioma do texto original: inglês
Transmission of Decisions
Idioma do texto original: inglês
Uniquely identify and authenticate [organization-defined] before establishing communications with devices, users, or other services or applications.
Idioma do texto original: inglês
Develop, document, and disseminate to [organization-defined]: [organization-defined] incident response policy that: Procedures to facilitate the imple
Idioma do texto original: inglês
Integrated Information Security Analysis Team
Idioma do texto original: inglês
Incorporate simulated events into incident response training to facilitate the required response by personnel in crisis situations.
Idioma do texto original: inglês
Provide an incident response training environment using [organization-defined].
Idioma do texto original: inglês
Provide incident response training on how to identify and respond to a breach, including the organization’s process for reporting a breach.
Idioma do texto original: inglês
Provide incident response training to system users consistent with assigned roles and responsibilities: Within [organization-defined] of assuming an i
Idioma do texto original: inglês
Test the incident response capability using [organization-defined].
Idioma do texto original: inglês
Coordinate incident response testing with organizational elements responsible for related plans.
Idioma do texto original: inglês
Use qualitative and quantitative data from testing to: Determine the effectiveness of incident response processes; Continuously improve incident respo
Idioma do texto original: inglês
Test the effectiveness of the incident response capability for the system [organization-defined] using the following tests: [organization-defined].
Idioma do texto original: inglês
Support the incident handling process using [organization-defined].
Idioma do texto original: inglês