Categorize the system and information it processes, stores, and transmits;
Idioma do texto original: inglês
Menu
Skills neste repositório
O SkillsMP coletou 7.442 skills de CyberStrikeus/CyberStrike. Abra uma skill para revisar a origem e os detalhes.
CyberStrikeus/CyberStrikeMostrando 40 de 7.442 skills coletadas.
Categorize the system and information it processes, stores, and transmits;
Idioma do texto original: inglês
Assess supply chain risks associated with [organization-defined] ;
Idioma do texto original: inglês
Use all-source intelligence to assist in the analysis of risk.
Idioma do texto original: inglês
Determine the current cyber threat environment on an ongoing basis using [organization-defined].
Idioma do texto original: inglês
Employ the following advanced automation and analytics capabilities to predict and identify risks to [organization-defined]: [organization-defined].
Idioma do texto original: inglês
Conduct a risk assessment, including: Identifying threats to and vulnerabilities in the system; Determining the likelihood and magnitude of harm from
Idioma do texto original: inglês
Risk Assessment Update
Idioma do texto original: inglês
Update Tool Capability
Idioma do texto original: inglês
Correlate the output from vulnerability scanning tools to determine the presence of multi-vulnerability and multi-hop attack vectors.
Idioma do texto original: inglês
Establish a public reporting channel for receiving reports of vulnerabilities in organizational systems and system components.
Idioma do texto original: inglês
Update the system vulnerabilities to be scanned [organization-defined].
Idioma do texto original: inglês
Define the breadth and depth of vulnerability scanning coverage.
Idioma do texto original: inglês
Determine information about the system that is discoverable and take [organization-defined].
Idioma do texto original: inglês
Implement privileged access authorization to [organization-defined] for [organization-defined].
Idioma do texto original: inglês
Compare the results of multiple vulnerability scans using [organization-defined].
Idioma do texto original: inglês
Review historic audit logs to determine if a vulnerability identified in a [organization-defined] has been previously exploited within an [organizatio
Idioma do texto original: inglês
Penetration Testing and Analyses
Idioma do texto original: inglês
Monitor and scan for vulnerabilities in the system and hosted applications [organization-defined] and when new vulnerabilities potentially affectin...
Idioma do texto original: inglês
Employ a technical surveillance countermeasures survey at [organization-defined] [organization-defined].
Idioma do texto original: inglês
Respond to findings from security and privacy assessments, monitoring, and audits in accordance with organizational risk tolerance.
Idioma do texto original: inglês
Conduct privacy impact assessments for systems, programs, or other activities before: Developing or procuring information technology that processes pe
Idioma do texto original: inglês
Identify critical system components and functions by performing a criticality analysis for [organization-defined] at [organization-defined].
Idioma do texto original: inglês
Develop, document, and disseminate to [organization-defined]: [organization-defined] system and services acquisition policy that: Procedures to facili
Idioma do texto original: inglês
Require the developer of the system, system component, or system service to enable integrity verification of software and firmware components.
Idioma do texto original: inglês
Provide an alternate configuration management process using organizational personnel in the absence of a dedicated developer configuration management
Idioma do texto original: inglês
Require the developer of the system, system component, or system service to enable integrity verification of hardware components.
Idioma do texto original: inglês
Require the developer of the system, system component, or system service to employ tools for comparing newly generated versions of security-relevant h
Idioma do texto original: inglês
Require the developer of the system, system component, or system service to maintain the integrity of the mapping between the master build data descri
Idioma do texto original: inglês
Require the developer of the system, system component, or system service to execute procedures for ensuring that security-relevant hardware, software,
Idioma do texto original: inglês
Require [organization-defined] to be included in the [organization-defined].
Idioma do texto original: inglês
Require the developer of the system, system component, or system service to: Perform configuration management during system, component, or service [or
Idioma do texto original: inglês
Require the developer of the system, system component, or system service to employ static code analysis tools to identify common flaws and document th
Idioma do texto original: inglês
Require the developer of the system, system component, or system service to perform threat modeling and vulnerability analyses during development and
Idioma do texto original: inglês
Require the developer of the system, system component, or system service to perform a manual code review of [organization-defined] using the following
Idioma do texto original: inglês
Require the developer of the system, system component, or system service to perform penetration testing: At the following level of rigor: [organizatio
Idioma do texto original: inglês
Require the developer of the system, system component, or system service to perform attack surface reviews.
Idioma do texto original: inglês
Require the developer of the system, system component, or system service to verify that the scope of testing and evaluation provides complete coverage
Idioma do texto original: inglês
Require the developer of the system, system component, or system service to employ dynamic code analysis tools to identify common flaws and document t
Idioma do texto original: inglês
Require the developer of the system, system component, or system service to employ interactive application security testing tools to identify flaws an
Idioma do texto original: inglês
Require the developer of the system, system component, or system service, at all post-design stages of the system development life cycle, to: Develop
Idioma do texto original: inglês