Determine which compiler, interpreter, and build tool features should be used and how each should be configured, then implement and use the approved c
原文语言:英语
菜单
这个仓库中的 skills
SkillsMP 已收集 CyberStrikeus/CyberStrike 中的 7,442 个 Skill。打开任一 Skill 可查看来源和详情。
CyberStrikeus/CyberStrike已展示 40 / 7,442 个已收集 Skill。
Determine which compiler, interpreter, and build tool features should be used and how each should be configured, then implement and use the approved c
原文语言:英语
Determine whether code review (a person looks directly at the code to find issues) and/or code analysis (tools are used to find issues in code, either
原文语言:英语
Perform the code review and/or code analysis based on the organization’s secure coding standards, and record and triage all discovered issues and reco
原文语言:英语
Determine whether executable code testing should be performed to find vulnerabilities not identified by previous reviews, analysis, or testing and, if
原文语言:英语
Scope the testing, design the tests, perform the testing, and document the results, including recording and triaging all discovered issues and recomme
原文语言:英语
Define a secure baseline by determining how to configure each setting that has an effect on security or a security-related setting so that the default
原文语言:英语
Implement the default settings (or groups of default settings, if applicable), and document each setting for software administrators.
原文语言:英语
Gather information from software acquirers, users, and public sources on potential vulnerabilities in the software and third-party components that the
原文语言:英语
Review, analyze, and/or test the software’s code to identify or confirm the presence of previously undetected vulnerabilities.
原文语言:英语
Have a policy that addresses vulnerability disclosure and remediation, and implement the roles, responsibilities, and processes needed to support that
原文语言:英语
Analyze each vulnerability to gather sufficient information about risk to plan its remediation or other risk response.
原文语言:英语
Plan and implement risk responses for vulnerabilities.
原文语言:英语
Analyze identified vulnerabilities to determine their root causes.
原文语言:英语
Analyze the root causes over time to identify patterns, such as a particular secure coding practice not being followed consistently.
原文语言:英语
Review the software for similar vulnerabilities to eradicate a class of vulnerabilities, and proactively fix them rather than waiting for external rep
原文语言:英语
Review the SDLC process, and update it if appropriate to prevent (or reduce the likelihood of) the root cause recurring in updates to the software or
原文语言:英语
Develop, document, and disseminate to [organization-defined]: [organization-defined] access control policy that: Procedures to facilitate the implemen
原文语言:英语
Limit the number of concurrent sessions for each [organization-defined] to [organization-defined].
原文语言:英语
Conceal, via the device lock, information previously visible on the display with a publicly viewable image.
原文语言:英语
Prevent further access to the system by [organization-defined] ;
原文语言:英语
Provide a logout capability for user-initiated communications sessions whenever authentication is used to gain access to [organization-defined].
原文语言:英语
Display an explicit logout message to users indicating the termination of authenticated communications sessions.
原文语言:英语
Display an explicit message to users indicating that the session will end in [organization-defined].
原文语言:英语
Automatically terminate a user session after [organization-defined].
原文语言:英语
Supervision and Review — Access Control
原文语言:英语
Necessary Uses
原文语言:英语
Identify [organization-defined] that can be performed on the system without identification or authentication consistent with organizational mission...
原文语言:英语
Automated Marking
原文语言:英语
Dynamically associate security and privacy attributes with [organization-defined] in accordance with the following security and privacy policies as in
原文语言:英语
Provide authorized individuals the capability to define or change the type and value of security and privacy attributes available for association with
原文语言:英语
Provide authorized individuals (or processes acting on behalf of individuals) the capability to define or change the value of associated security and
原文语言:英语
Maintain the association and integrity of [organization-defined] to [organization-defined].
原文语言:英语
Provide the capability to associate [organization-defined] with [organization-defined] by authorized individuals (or processes acting on behalf of ind
原文语言:英语
Display security and privacy attributes in human-readable form on each object that the system transmits to output devices to identify [organization-de
原文语言:英语
Require personnel to associate and maintain the association of [organization-defined] with [organization-defined] in accordance with [organization-def
原文语言:英语
Provide a consistent interpretation of security and privacy attributes transmitted between distributed system components.
原文语言:英语
Implement [organization-defined] in associating security and privacy attributes to information.
原文语言:英语
Change security and privacy attributes associated with information only via regrading mechanisms validated using [organization-defined].
原文语言:英语
Provide the means to associate [organization-defined] with [organization-defined] for information in storage, in process, and/or in transmission;
原文语言:英语
Employ automated mechanisms to monitor and control remote access methods.
原文语言:英语