03.13.05
原文语言:英语
菜单
这个仓库中的 skills
SkillsMP 已收集 CyberStrikeus/CyberStrike 中的 7,442 个 Skill。打开任一 Skill 可查看来源和详情。
CyberStrikeus/CyberStrike已展示 40 / 7,442 个已收集 Skill。
03.13.05
原文语言:英语
03.13.07
原文语言:英语
03.13.14
原文语言:英语
03.13.16
原文语言:英语
Identify, report, and correct system flaws.
原文语言:英语
Implement malicious code protection mechanisms at system entry and exit points to detect and eradicate malicious code.
原文语言:英语
03.14.04
原文语言:英语
03.14.05
原文语言:英语
03.14.07
原文语言:英语
Monitor the system to detect: Attacks and indicators of potential attacks and Unauthorized connections. Identify unauthorized use of the system. Monit
原文语言:英语
Develop, document, and disseminate to organizational personnel or roles the policies and procedures needed to satisfy the security requirements for...
原文语言:英语
Establish rules that describe the responsibilities and expected behavior for system usage and protecting CUI.
原文语言:英语
Develop a system security plan that: Defines the constituent system components; Identifies the information types processed, stored, and transmitted by
原文语言:英语
Require the providers of external system services used for the processing, storage, or transmission of CUI to comply with the following security re...
原文语言:英语
Identify and document all security requirements for the organization’s software development infrastructures and processes, and maintain the requiremen
原文语言:英语
Identify and document all security requirements for organization-developed software to meet, and maintain the requirements over time.
原文语言:英语
Communicate requirements to all third parties who will provide commercial software components to the organization for reuse by the organization’s o...
原文语言:英语
Create new roles and alter responsibilities for existing roles as needed to encompass all parts of the SDLC.
原文语言:英语
Provide role-based training for all personnel with responsibilities that contribute to secure development.
原文语言:英语
Obtain upper management or authorizing official commitment to secure development, and convey that commitment to all with development-related roles and
原文语言:英语
Specify which tools or tool types must or should be included in each toolchain to mitigate identified risks, as well as how the toolchain components a
原文语言:英语
Follow recommended security practices to deploy, operate, and maintain tools and toolchains.
原文语言:英语
Configure tools to generate artifacts of their support of secure software development practices as defined by the organization.
原文语言:英语
Define criteria for software security checks and track throughout the SDLC.
原文语言:英语
Implement processes, mechanisms, etc.
原文语言:英语
Separate and protect each environment involved in software development.
原文语言:英语
Secure and harden development endpoints (i.e., endpoints for software designers, developers, testers, builders, etc.) to perform development-related t
原文语言:英语
Store all forms of code – including source code, executable code, and configuration-as-code – based on the principle of least privilege so that onl...
原文语言:英语
Make software integrity verification information available to software acquirers.
原文语言:英语
Securely archive the necessary files and supporting data (e.g., integrity verification information, provenance data) to be retained for each software
原文语言:英语
Collect, safeguard, maintain, and share provenance data for all components of each software release (e.g., in a software bill of materials .SBOM).
原文语言:英语
Use forms of risk modeling – such as threat modeling, attack modeling, or attack surface mapping – to help assess the security risk for the software.
原文语言:英语
Track and maintain the software’s security requirements, risks, and design decisions.
原文语言:英语
Where appropriate, build in support for using standardized security features and services (e.g., enabling software to integrate with existing log m...
原文语言:英语
Have 1) a qualified person (or people) who were not involved with the design and/or 2) automated processes instantiated in the toolchain review the so
原文语言:英语
Acquire and maintain well-secured software components (e.g., software libraries, modules, middleware, frameworks) from commercial, open-source, and ot
原文语言:英语
Create and maintain well-secured software components in-house following SDLC processes to meet common internal software development needs that cannot
原文语言:英语
Verify that acquired commercial, open-source, and all other third-party software components comply with the requirements, as defined by the organizati
原文语言:英语
Follow all secure coding practices that are appropriate to the development languages and environment to meet the organization’s requirements.
原文语言:英语
Use compiler, interpreter, and build tools that offer features to improve executable security.
原文语言:英语