All authors

Claude Skills by CyberStrikeus
github.com/CyberStrikeus7,689 skills0 installs16,544 views
- SR 4(4) Supply Chain Integrity PedigreeEmploy [organization-defined] and conduct [organization-defined] to ensure the integrity of the system and system components by validating the internaVotes: 0GitHub stars: 2,182
- SR 4 ProvenanceDocument, monitor, and maintain valid provenance of the following systems, system components, and associated data: [organization-defined].Votes: 0GitHub stars: 2,182
- SR 5(1) Adequate SupplyEmploy the following controls to ensure an adequate supply of [organization-defined]: [organization-defined].Votes: 0GitHub stars: 2,182
- SR 6(1) Testing And AnalysisEmploy [organization-defined] of the following supply chain elements, processes, and actors associated with the system, system component, or system seVotes: 0GitHub stars: 2,182
- SR 6 Supplier Assessments And ReviewsAssess and review the supply chain-related risks associated with suppliers or contractors and the system, system component, or system service they proVotes: 0GitHub stars: 2,182
- SR 7 Supply Chain Operations SecurityEmploy the following Operations Security (OPSEC) controls to protect supply chain-related information for the system, system component, or system servVotes: 0GitHub stars: 2,182
- SR 8 Notification AgreementsEstablish agreements and procedures with entities involved in the supply chain for the system, system component, or system service for the [organizatiVotes: 0GitHub stars: 2,182
- SR 9 Tamper Resistance And DetectionImplement a tamper protection program for the system, system component, or system service.Votes: 0GitHub stars: 2,182
- Sr 10 Inspection Of Systems OrInspect the following systems or system components [organization-defined] to detect tampering: [organization-defined].Votes: 0GitHub stars: 2,182
- Sr 11 2 Configuration Control ForMaintain configuration control over the following system components awaiting service or repair and serviced or repaired components awaiting return toVotes: 0GitHub stars: 2,182
- Sr 4 3 Validate As Genuine And NotEmploy the following controls to validate that the system or system component received is genuine and has not been altered: [organization-defined].Votes: 0GitHub stars: 2,182
- Sr 5 2 Assessments Prior To SelectionAssess the system, system component, or system service prior to selection, acceptance, modification, or update.Votes: 0GitHub stars: 2,182
- Sr 5 Acquisition Strategies Tools AndEmploy the following acquisition strategies, contract tools, and procurement methods to protect against, identify, and mitigate supply chain risks: [oVotes: 0GitHub stars: 2,182
- Sr 9 1 Multiple Stages Of SystemEmploy anti-tamper technologies, tools, and techniques throughout the system development life cycle.Votes: 0GitHub stars: 2,182
- CA 1 Policy And ProceduresDevelop, document, and disseminate to [organization-defined]: [organization-defined] assessment, authorization, and monitoring policy that: ProceduresVotes: 0GitHub stars: 2,182
- CA 2(1) Independent AssessorsEmploy independent assessors or assessment teams to conduct control assessments.Votes: 0GitHub stars: 2,182
- CA 2(2) Specialized AssessmentsInclude as part of control assessments, [organization-defined], [organization-defined], [organization-defined].Votes: 0GitHub stars: 2,182
- CA 2 Control AssessmentsSelect the appropriate assessor or assessment team for the type of assessment to be conducted;Votes: 0GitHub stars: 2,182
- CA 3(4) Connections To Public NetworksConnections to Public NetworksVotes: 0GitHub stars: 2,182
- CA 3(6) Transfer AuthorizationsVerify that individuals or systems transferring data between interconnecting systems have the requisite authorizations (i.e., write permissions or priVotes: 0GitHub stars: 2,182
- CA 3(7) Transitive Information ExchangesIdentify transitive (downstream) information exchanges with other systems through the systems identified in [CA-3a](#ca-3_smt.a) ;Votes: 0GitHub stars: 2,182
- CA 3 Information ExchangeApprove and manage the exchange of information between the system and other systems using [organization-defined];Votes: 0GitHub stars: 2,182
- CA 4 Security CertificationSecurity CertificationVotes: 0GitHub stars: 2,182
- CA 5 Plan Of Action And MilestonesDevelop a plan of action and milestones for the system to document the planned remediation actions of the organization to correct weaknesses or def...Votes: 0GitHub stars: 2,182
- CA 6 AuthorizationAssign a senior official as the authorizing official for the system;Votes: 0GitHub stars: 2,182
- CA 7(1) Independent AssessmentEmploy independent assessors or assessment teams to monitor the controls in the system on an ongoing basis.Votes: 0GitHub stars: 2,182
- CA 7(2) Types Of AssessmentsTypes of AssessmentsVotes: 0GitHub stars: 2,182
- CA 7(3) Trend AnalysesEmploy trend analyses to determine if control implementations, the frequency of continuous monitoring activities, and the types of activities used inVotes: 0GitHub stars: 2,182
- CA 7(4) Risk MonitoringEnsure risk monitoring is an integral part of the continuous monitoring strategy that includes the following: Effectiveness monitoring; Compliance monVotes: 0GitHub stars: 2,182
- CA 7(5) Consistency AnalysisEmploy the following actions to validate that policies are established and implemented controls are operating in a consistent manner: [organization-deVotes: 0GitHub stars: 2,182
- CA 7 Continuous MonitoringDevelop a system-level continuous monitoring strategy and implement continuous monitoring in accordance with the organization-level continuous monitorVotes: 0GitHub stars: 2,182
- CA 8(2) Red Team ExercisesEmploy the following red-team exercises to simulate attempts by adversaries to compromise organizational systems in accordance with applicable rules oVotes: 0GitHub stars: 2,182
- CA 8(3) Facility Penetration TestingEmploy a penetration testing process that includes [organization-defined] [organization-defined] attempts to bypass or circumvent controls associatedVotes: 0GitHub stars: 2,182
- CA 8 Penetration TestingConduct penetration testing [organization-defined] on [organization-defined].Votes: 0GitHub stars: 2,182
- CA 9(1) Compliance ChecksPerform security and privacy compliance checks on constituent system components prior to the establishment of the internal connection.Votes: 0GitHub stars: 2,182
- CA 9 Internal System ConnectionsAuthorize internal connections of [organization-defined] to the system;Votes: 0GitHub stars: 2,182
- Ca 2 3 Leveraging Results From ExternalLeverage the results of control assessments performed by [organization-defined] on [organization-defined] when the assessment meets [organization-defiVotes: 0GitHub stars: 2,182
- Ca 3 1 Unclassified National SecurityUnclassified National Security System ConnectionsVotes: 0GitHub stars: 2,182
- Ca 3 2 Classified National SecurityClassified National Security System ConnectionsVotes: 0GitHub stars: 2,182
- Ca 3 3 Unclassified Non NationalUnclassified Non-national Security System ConnectionsVotes: 0GitHub stars: 2,182
- Ca 3 5 Restrictions On External SystemRestrictions on External System ConnectionsVotes: 0GitHub stars: 2,182
- Ca 5 1 Automation Support For AccuracyEnsure the accuracy, currency, and availability of the plan of action and milestones for the system using [organization-defined].Votes: 0GitHub stars: 2,182
- Ca 6 1 Joint Authorization IntraEmploy a joint authorization process for the system that includes multiple authorizing officials from the same organization conducting the authorizatiVotes: 0GitHub stars: 2,182
- Ca 6 2 Joint Authorization InterEmploy a joint authorization process for the system that includes multiple authorizing officials with at least one authorizing official from an organiVotes: 0GitHub stars: 2,182
- Ca 7 6 Automation Support For MonitoringEnsure the accuracy, currency, and availability of monitoring results for the system using [organization-defined].Votes: 0GitHub stars: 2,182
- Ca 8 1 Independent Penetration TestingEmploy an independent penetration testing agent or team to perform penetration testing on the system or system components.Votes: 0GitHub stars: 2,182
- PT 1 Policy And ProceduresDevelop, document, and disseminate to [organization-defined]: [organization-defined] personally identifiable information processing and transparency pVotes: 0GitHub stars: 2,182
- PT 2(1) Data TaggingAttach data tags containing [organization-defined] to [organization-defined].Votes: 0GitHub stars: 2,182
- PT 2(2) AutomationManage enforcement of the authorized processing of personally identifiable information using [organization-defined].Votes: 0GitHub stars: 2,182
- PT 3(1) Data TaggingAttach data tags containing the following purposes to [organization-defined]: [organization-defined].Votes: 0GitHub stars: 2,182