All authors

Claude Skills by CyberStrikeus
github.com/CyberStrikeus7,689 skills0 installs16,544 views
- System Monitoring 03 14 06 SystemMonitor the system to detect: Attacks and indicators of potential attacks and Unauthorized connections. Identify unauthorized use of the system. MonitVotes: 0GitHub stars: 2,182
- Policy And Procedures 03 15 01 PolicyDevelop, document, and disseminate to organizational personnel or roles the policies and procedures needed to satisfy the security requirements for...Votes: 0GitHub stars: 2,182
- Rules Of Behavior 03 15 03 Rules OfEstablish rules that describe the responsibilities and expected behavior for system usage and protecting CUI.Votes: 0GitHub stars: 2,182
- System Security Plan 03 15 02 SystemDevelop a system security plan that: Defines the constituent system components; Identifies the information types processed, stored, and transmitted byVotes: 0GitHub stars: 2,182
- External System Services 03 16 03Require the providers of external system services used for the processing, storage, or transmission of CUI to comply with the following security re...Votes: 0GitHub stars: 2,182
- Security Engineering Principles 03 16Security Engineering PrinciplesVotes: 0GitHub stars: 2,182
- Unsupported System Components 03 16 02Replace system components when support for the components is no longer available from the developer, vendor, or manufacturer.Votes: 0GitHub stars: 2,182
- Acquisition Strategies Tools AndAcquisition Strategies, Tools, and MethodsVotes: 0GitHub stars: 2,182
- Supply Chain Requirements And ProcessesEstablish a process for identifying and addressing weaknesses or deficiencies in the supply chain elements and processes.Votes: 0GitHub stars: 2,182
- Supply Chain Risk Management Plan 03 17Develop a plan for managing supply chain risks associated with the research and development, design, manufacturing, acquisition, delivery, integrat...Votes: 0GitHub stars: 2,182
- PO.1.1 Po11Identify and document all security requirements for the organization’s software development infrastructures and processes, and maintain the requiremenVotes: 0GitHub stars: 2,182
- PO.1.2 Po12Identify and document all security requirements for organization-developed software to meet, and maintain the requirements over time.Votes: 0GitHub stars: 2,182
- PO.1.3 Po13Communicate requirements to all third parties who will provide commercial software components to the organization for reuse by the organization’s o...Votes: 0GitHub stars: 2,182
- PO.2.1 Po21Create new roles and alter responsibilities for existing roles as needed to encompass all parts of the SDLC.Votes: 0GitHub stars: 2,182
- PO.2.2 Po22Provide role-based training for all personnel with responsibilities that contribute to secure development.Votes: 0GitHub stars: 2,182
- PO.2.3 Po23Obtain upper management or authorizing official commitment to secure development, and convey that commitment to all with development-related roles andVotes: 0GitHub stars: 2,182
- PO.3.1 Po31Specify which tools or tool types must or should be included in each toolchain to mitigate identified risks, as well as how the toolchain components aVotes: 0GitHub stars: 2,182
- PO.3.2 Po32Follow recommended security practices to deploy, operate, and maintain tools and toolchains.Votes: 0GitHub stars: 2,182
- PO.3.3 Po33Configure tools to generate artifacts of their support of secure software development practices as defined by the organization.Votes: 0GitHub stars: 2,182
- PO.4.1 Po41Define criteria for software security checks and track throughout the SDLC.Votes: 0GitHub stars: 2,182
- PO.4.2 Po42Implement processes, mechanisms, etc.Votes: 0GitHub stars: 2,182
- PO.5.1 Po51Separate and protect each environment involved in software development.Votes: 0GitHub stars: 2,182
- PO.5.2 Po52Secure and harden development endpoints (i.e., endpoints for software designers, developers, testers, builders, etc.) to perform development-related tVotes: 0GitHub stars: 2,182
- Define And Use Criteria For SoftwareHelp ensure that the software resulting from the SDLC meets the organization’s expectations by defining and using criteria for checking the software’sVotes: 0GitHub stars: 2,182
- Define Security Requirements ForEnsure that security requirements for software development are known at all times so that they can be taken into account throughout the SDLC and du...Votes: 0GitHub stars: 2,182
- Implement And Maintain SecureEnsure that all components of the environments for software development are strongly protected from internal and external threats to prevent compro...Votes: 0GitHub stars: 2,182
- Implement Roles And Responsibilities PoEnsure that everyone inside and outside of the organization involved in the SDLC is prepared to perform their SDLC-related roles and responsibilitiesVotes: 0GitHub stars: 2,182
- Implement Supporting Toolchains Po 3Use automation to reduce human effort and improve the accuracy, reproducibility, usability, and comprehensiveness of security practices throughout ...Votes: 0GitHub stars: 2,182
- PS.1.1 Ps11Store all forms of code – including source code, executable code, and configuration-as-code – based on the principle of least privilege so that onl...Votes: 0GitHub stars: 2,182
- PS.2.1 Ps21Make software integrity verification information available to software acquirers.Votes: 0GitHub stars: 2,182
- PS.3.1 Ps31Securely archive the necessary files and supporting data (e.g., integrity verification information, provenance data) to be retained for each softwareVotes: 0GitHub stars: 2,182
- PS.3.2 Ps32Collect, safeguard, maintain, and share provenance data for all components of each software release (e.g., in a software bill of materials .SBOM).Votes: 0GitHub stars: 2,182
- Archive And Protect Each SoftwarePreserve software releases in order to help identify, analyze, and eliminate vulnerabilities discovered in the software after release.Votes: 0GitHub stars: 2,182
- Protect All Forms Of Code FromHelp prevent unauthorized changes to code, both inadvertent and intentional, which could circumvent or negate the intended security characteristics...Votes: 0GitHub stars: 2,182
- Provide A Mechanism For VerifyingHelp software acquirers ensure that the software they acquire is legitimate and has not been tampered with.Votes: 0GitHub stars: 2,182
- PW.1.1 Pw11Use forms of risk modeling – such as threat modeling, attack modeling, or attack surface mapping – to help assess the security risk for the software.Votes: 0GitHub stars: 2,182
- PW.1.2 Pw12Track and maintain the software’s security requirements, risks, and design decisions.Votes: 0GitHub stars: 2,182
- PW.1.3 Pw13Where appropriate, build in support for using standardized security features and services (e.g., enabling software to integrate with existing log m...Votes: 0GitHub stars: 2,182
- PW.2.1 Pw21Have 1) a qualified person (or people) who were not involved with the design and/or 2) automated processes instantiated in the toolchain review the soVotes: 0GitHub stars: 2,182
- PW.4.1 Pw41Acquire and maintain well-secured software components (e.g., software libraries, modules, middleware, frameworks) from commercial, open-source, and otVotes: 0GitHub stars: 2,182
- PW.4.2 Pw42Create and maintain well-secured software components in-house following SDLC processes to meet common internal software development needs that cannotVotes: 0GitHub stars: 2,182
- PW.4.4 Pw44Verify that acquired commercial, open-source, and all other third-party software components comply with the requirements, as defined by the organizatiVotes: 0GitHub stars: 2,182
- PW.5.1 Pw51Follow all secure coding practices that are appropriate to the development languages and environment to meet the organization’s requirements.Votes: 0GitHub stars: 2,182
- PW.6.1 Pw61Use compiler, interpreter, and build tools that offer features to improve executable security.Votes: 0GitHub stars: 2,182
- PW.6.2 Pw62Determine which compiler, interpreter, and build tool features should be used and how each should be configured, then implement and use the approved cVotes: 0GitHub stars: 2,182
- PW.7.1 Pw71Determine whether code review (a person looks directly at the code to find issues) and/or code analysis (tools are used to find issues in code, eitherVotes: 0GitHub stars: 2,182
- PW.7.2 Pw72Perform the code review and/or code analysis based on the organization’s secure coding standards, and record and triage all discovered issues and recoVotes: 0GitHub stars: 2,182
- PW.8.1 Pw81Determine whether executable code testing should be performed to find vulnerabilities not identified by previous reviews, analysis, or testing and, ifVotes: 0GitHub stars: 2,182
- PW.8.2 Pw82Scope the testing, design the tests, perform the testing, and document the results, including recording and triaging all discovered issues and recommeVotes: 0GitHub stars: 2,182
- PW.9.1 Pw91Define a secure baseline by determining how to configure each setting that has an effect on security or a security-related setting so that the defaultVotes: 0GitHub stars: 2,182