Skip to main content

这个仓库中的 skills

CyberStrikeus/CyberStrike - 第 109 页

SkillsMP 已收集 CyberStrikeus/CyberStrike 中的 7,442 个 Skill。打开任一 Skill 可查看来源和详情。

CyberStrikeus/CyberStrike

已展示 40 / 7,442 个已收集 Skill。

职业分类
信息安全分析师
描述

Processes for receiving, analyzing, and responding to vulnerability disclosures are established

原文语言:英语

更新
职业分类
信息安全分析师
描述

The authenticity and integrity of hardware and software are assessed prior to acquisition and use

原文语言:英语

更新
职业分类
信息安全分析师
描述

Critical suppliers are assessed prior to acquisition

原文语言:英语

更新
职业分类
信息安全分析师
描述

Risk management processes are established, managed, and agreed to by organizational stakeholders

原文语言:英语

更新
职业分类
信息安全分析师
描述

Organizational risk tolerance is determined and clearly expressed

原文语言:英语

更新
职业分类
信息安全分析师
描述

The organization’s determination of risk tolerance is informed by its role in critical infrastructure and sector specific risk analysis

原文语言:英语

更新
职业分类
信息安全分析师
描述

Cyber supply chain risk management processes are identified, established, assessed, managed, and agreed to by organizational stakeholders

原文语言:英语

更新
职业分类
信息安全分析师
描述

Suppliers and third party partners of information systems, components, and services are identified, prioritized, and assessed using a cyber supply cha

原文语言:英语

更新
职业分类
信息安全分析师
描述

Contracts with suppliers and third-party partners are used to implement appropriate measures designed to meet the objectives of an organization’s cybe

原文语言:英语

更新
职业分类
信息安全分析师
描述

Suppliers and third-party partners are routinely assessed using audits, test results, or other forms of evaluations to confirm they are meeting their

原文语言:英语

更新
职业分类
信息安全分析师
描述

Response and recovery planning and testing are conducted with suppliers and third-party providers

原文语言:英语

更新
职业分类
信息安全分析师
描述

Improvements to organizational cybersecurity risk management processes, procedures and activities are identified across all CSF Functions

原文语言:英语

更新
职业分类
信息安全分析师
描述

The cybersecurity risk to the organization, assets, and individuals is understood by the organization

原文语言:英语

更新
职业分类
信息安全分析师
描述

The organization's personnel are provided with cybersecurity awareness and training so that they can perform their cybersecurity-related tasks

原文语言:英语

更新
职业分类
信息安全分析师
描述

Data are managed consistent with the organization's risk strategy to protect the confidentiality, integrity, and availability of information

原文语言:英语

更新
职业分类
信息安全分析师
描述

The hardware, software (e.g., firmware, operating systems, applications), and services of physical and virtual platforms are managed consistent with t

原文语言:英语

更新
职业分类
信息安全分析师
描述

Identities and credentials for authorized users, services, and hardware are managed by the organization

原文语言:英语

更新
职业分类
信息安全分析师
描述

Identities are proofed and bound to credentials based on the context of interactions

原文语言:英语

更新
职业分类
信息安全分析师
描述

Users, services, and hardware are authenticated

原文语言:英语

更新
职业分类
信息安全分析师
描述

Identity assertions are protected, conveyed, and verified

原文语言:英语

更新
职业分类
信息安全分析师
描述

Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least

原文语言:英语

更新
职业分类
信息安全分析师
描述

Physical access to assets is managed, monitored, and enforced commensurate with risk

原文语言:英语

更新
职业分类
信息安全分析师
描述

Identities and credentials are issued, managed, verified, revoked, and audited for authorized devices, users and processes

原文语言:英语

更新
职业分类
信息安全分析师
描述

Physical access to assets is managed and protected

原文语言:英语

更新
职业分类
信息安全分析师
描述

Remote access is managed

原文语言:英语

更新
职业分类
信息安全分析师
描述

Access permissions and authorizations are managed, incorporating the principles of least privilege and separation of duties

原文语言:英语

更新
职业分类
信息安全分析师
描述

Network integrity is protected (e.g., network segregation, network segmentation)

原文语言:英语

更新
职业分类
信息安全分析师
描述

Identities are proofed and bound to credentials and asserted in interactions

原文语言:英语

更新
职业分类
信息安全分析师
描述

Users, devices, and other assets are authenticated (e.g., single-factor, multi-factor) commensurate with the risk of the transaction (e.g., individual

原文语言:英语

更新
职业分类
信息安全分析师
描述

Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in

原文语言:英语

更新
职业分类
信息安全分析师
描述

Individuals in specialized roles are provided with awareness and training so that they possess the knowledge and skills to perform relevant tasks with

原文语言:英语

更新
职业分类
信息安全分析师
描述

Third-party stakeholders (e.g., suppliers, customers, partners) understand their roles and responsibilities

原文语言:英语

更新
职业分类
信息安全分析师
描述

Senior executives understand their roles and responsibilities

原文语言:英语

更新
职业分类
信息安全分析师
描述

Physical and cybersecurity personnel understand their roles and responsibilities

原文语言:英语

更新
职业分类
信息安全分析师
描述

The confidentiality, integrity, and availability of data-at-rest are protected

原文语言:英语

更新
职业分类
信息安全分析师
描述

The confidentiality, integrity, and availability of data-in-transit are protected

原文语言:英语

更新
职业分类
信息安全分析师
描述

Assets are formally managed throughout removal, transfers, and disposition

原文语言:英语

更新
已展示 40 / 7,442 个已收集 Skill。