Categorize the system and information it processes, stores, and transmits;
原文语言:英语
菜单
这个仓库中的 skills
SkillsMP 已收集 CyberStrikeus/CyberStrike 中的 7,442 个 Skill。打开任一 Skill 可查看来源和详情。
CyberStrikeus/CyberStrike已展示 40 / 7,442 个已收集 Skill。
Categorize the system and information it processes, stores, and transmits;
原文语言:英语
Assess supply chain risks associated with [organization-defined] ;
原文语言:英语
Use all-source intelligence to assist in the analysis of risk.
原文语言:英语
Determine the current cyber threat environment on an ongoing basis using [organization-defined].
原文语言:英语
Employ the following advanced automation and analytics capabilities to predict and identify risks to [organization-defined]: [organization-defined].
原文语言:英语
Conduct a risk assessment, including: Identifying threats to and vulnerabilities in the system; Determining the likelihood and magnitude of harm from
原文语言:英语
Risk Assessment Update
原文语言:英语
Update Tool Capability
原文语言:英语
Correlate the output from vulnerability scanning tools to determine the presence of multi-vulnerability and multi-hop attack vectors.
原文语言:英语
Establish a public reporting channel for receiving reports of vulnerabilities in organizational systems and system components.
原文语言:英语
Update the system vulnerabilities to be scanned [organization-defined].
原文语言:英语
Define the breadth and depth of vulnerability scanning coverage.
原文语言:英语
Determine information about the system that is discoverable and take [organization-defined].
原文语言:英语
Implement privileged access authorization to [organization-defined] for [organization-defined].
原文语言:英语
Compare the results of multiple vulnerability scans using [organization-defined].
原文语言:英语
Review historic audit logs to determine if a vulnerability identified in a [organization-defined] has been previously exploited within an [organizatio
原文语言:英语
Penetration Testing and Analyses
原文语言:英语
Monitor and scan for vulnerabilities in the system and hosted applications [organization-defined] and when new vulnerabilities potentially affectin...
原文语言:英语
Employ a technical surveillance countermeasures survey at [organization-defined] [organization-defined].
原文语言:英语
Respond to findings from security and privacy assessments, monitoring, and audits in accordance with organizational risk tolerance.
原文语言:英语
Conduct privacy impact assessments for systems, programs, or other activities before: Developing or procuring information technology that processes pe
原文语言:英语
Identify critical system components and functions by performing a criticality analysis for [organization-defined] at [organization-defined].
原文语言:英语
Develop, document, and disseminate to [organization-defined]: [organization-defined] system and services acquisition policy that: Procedures to facili
原文语言:英语
Require the developer of the system, system component, or system service to enable integrity verification of software and firmware components.
原文语言:英语
Provide an alternate configuration management process using organizational personnel in the absence of a dedicated developer configuration management
原文语言:英语
Require the developer of the system, system component, or system service to enable integrity verification of hardware components.
原文语言:英语
Require the developer of the system, system component, or system service to employ tools for comparing newly generated versions of security-relevant h
原文语言:英语
Require the developer of the system, system component, or system service to maintain the integrity of the mapping between the master build data descri
原文语言:英语
Require the developer of the system, system component, or system service to execute procedures for ensuring that security-relevant hardware, software,
原文语言:英语
Require [organization-defined] to be included in the [organization-defined].
原文语言:英语
Require the developer of the system, system component, or system service to: Perform configuration management during system, component, or service [or
原文语言:英语
Require the developer of the system, system component, or system service to employ static code analysis tools to identify common flaws and document th
原文语言:英语
Require the developer of the system, system component, or system service to perform threat modeling and vulnerability analyses during development and
原文语言:英语
Require the developer of the system, system component, or system service to perform a manual code review of [organization-defined] using the following
原文语言:英语
Require the developer of the system, system component, or system service to perform penetration testing: At the following level of rigor: [organizatio
原文语言:英语
Require the developer of the system, system component, or system service to perform attack surface reviews.
原文语言:英语
Require the developer of the system, system component, or system service to verify that the scope of testing and evaluation provides complete coverage
原文语言:英语
Require the developer of the system, system component, or system service to employ dynamic code analysis tools to identify common flaws and document t
原文语言:英语
Require the developer of the system, system component, or system service to employ interactive application security testing tools to identify flaws an
原文语言:英语
Require the developer of the system, system component, or system service, at all post-design stages of the system development life cycle, to: Develop
原文语言:英语