Skip to main content

这个仓库中的 skills

CyberStrikeus/CyberStrike - 第 121 页

SkillsMP 已收集 CyberStrikeus/CyberStrike 中的 7,442 个 Skill。打开任一 Skill 可查看来源和详情。

CyberStrikeus/CyberStrike

已展示 40 / 7,442 个已收集 Skill。

职业分类
信息安全分析师
描述

Enforce dual authorization for [organization-defined] of [organization-defined].

原文语言:英语

更新
职业分类
信息安全分析师
描述

Authorize read-only access to audit information to [organization-defined].

原文语言:英语

更新
职业分类
信息安全分析师
描述

Protect audit information and audit logging tools from unauthorized access, modification, and deletion;

原文语言:英语

更新
职业分类
信息安全分析师
描述

Develop, document, and disseminate to [organization-defined]: [organization-defined] assessment, authorization, and monitoring policy that: Procedures

原文语言:英语

更新
职业分类
信息安全分析师
描述

Employ independent assessors or assessment teams to conduct control assessments.

原文语言:英语

更新
职业分类
信息安全分析师
描述

Include as part of control assessments, [organization-defined], [organization-defined], [organization-defined].

原文语言:英语

更新
职业分类
信息安全分析师
描述

Leverage the results of control assessments performed by [organization-defined] on [organization-defined] when the assessment meets [organization-defi

原文语言:英语

更新
职业分类
信息安全分析师
描述

Select the appropriate assessor or assessment team for the type of assessment to be conducted;

原文语言:英语

更新
职业分类
信息安全分析师
描述

Verify that individuals or systems transferring data between interconnecting systems have the requisite authorizations (i.e., write permissions or pri

原文语言:英语

更新
职业分类
信息安全分析师
描述

Identify transitive (downstream) information exchanges with other systems through the systems identified in [CA-3a](#ca-3_smt.a) ;

原文语言:英语

更新
职业分类
信息安全分析师
描述

Approve and manage the exchange of information between the system and other systems using [organization-defined];

原文语言:英语

更新
职业分类
信息安全分析师
描述

Ensure the accuracy, currency, and availability of the plan of action and milestones for the system using [organization-defined].

原文语言:英语

更新
职业分类
信息安全分析师
描述

Develop a plan of action and milestones for the system to document the planned remediation actions of the organization to correct weaknesses or def...

原文语言:英语

更新
职业分类
信息安全分析师
描述

Employ a joint authorization process for the system that includes multiple authorizing officials from the same organization conducting the authorizati

原文语言:英语

更新
职业分类
信息安全分析师
描述

Employ a joint authorization process for the system that includes multiple authorizing officials with at least one authorizing official from an organi

原文语言:英语

更新
职业分类
信息安全分析师
描述

Assign a senior official as the authorizing official for the system;

原文语言:英语

更新
职业分类
信息安全分析师
描述

Employ independent assessors or assessment teams to monitor the controls in the system on an ongoing basis.

原文语言:英语

更新
职业分类
信息安全分析师
描述

Employ trend analyses to determine if control implementations, the frequency of continuous monitoring activities, and the types of activities used in

原文语言:英语

更新
职业分类
信息安全分析师
描述

Ensure risk monitoring is an integral part of the continuous monitoring strategy that includes the following: Effectiveness monitoring; Compliance mon

原文语言:英语

更新
职业分类
信息安全分析师
描述

Employ the following actions to validate that policies are established and implemented controls are operating in a consistent manner: [organization-de

原文语言:英语

更新
职业分类
信息安全分析师
描述

Ensure the accuracy, currency, and availability of monitoring results for the system using [organization-defined].

原文语言:英语

更新
职业分类
信息安全分析师
描述

Develop a system-level continuous monitoring strategy and implement continuous monitoring in accordance with the organization-level continuous monitor

原文语言:英语

更新
职业分类
信息安全分析师
描述

Employ the following red-team exercises to simulate attempts by adversaries to compromise organizational systems in accordance with applicable rules o

原文语言:英语

更新
职业分类
信息安全分析师
描述

Employ a penetration testing process that includes [organization-defined] [organization-defined] attempts to bypass or circumvent controls associated

原文语言:英语

更新
职业分类
信息安全分析师
描述

Conduct penetration testing [organization-defined] on [organization-defined].

原文语言:英语

更新
职业分类
信息安全分析师
描述

Perform security and privacy compliance checks on constituent system components prior to the establishment of the internal connection.

原文语言:英语

更新
职业分类
信息安全分析师
描述

Authorize internal connections of [organization-defined] to the system;

原文语言:英语

更新
职业分类
信息安全分析师
描述

Develop, document, and disseminate to [organization-defined]: [organization-defined] configuration management policy that: Procedures to facilitate th

原文语言:英语

更新
职业分类
信息安全分析师
描述

Establish the following restrictions on the use of open-source software: [organization-defined].

原文语言:英语

更新
职业分类
信息安全分析师
描述

Use software and associated documentation in accordance with contract agreements and copyright laws;

原文语言:英语

更新
已展示 40 / 7,442 个已收集 Skill。