All authors
CyberStrikeus avatar

Claude Skills by CyberStrikeus

github.com/CyberStrikeus
1,315 skillsA× 1,256B× 57D× 20 installs318 views
ID.GV 01 Idgv 01A

Organizational cybersecurity policy is established and communicated

securitygoaws
0
291
ID.GV 02 Idgv 02A

Cybersecurity roles and responsibilities are coordinated and aligned with internal roles and external partners

securitygoaws
0
291
ID.GV 03 Idgv 03A

Legal and regulatory requirements regarding cybersecurity, including privacy and civil liberties obligations, are understood and managed

securitygoaws
0
291
ID.GV 04 Idgv 04A

Governance and risk management processes address cybersecurity risks

securitygoaws
0
291
ID.IM 01 Idim 01A

Improvements are identified from evaluations

securitygoaws
0
291
ID.IM 02 Idim 02A

Improvements are identified from security tests and exercises, including those done in coordination with suppliers and relevant third parties

securitygoaws
0
291
ID.IM 03 Idim 03A

Improvements are identified from execution of operational processes, procedures, and activities

securitygoaws
0
291
ID.IM 04 Idim 04A

Incident response plans and other cybersecurity plans that affect operations are established, communicated, maintained, and improved

securitygoaws
0
291
ID.RA 01 Idra 01A

Vulnerabilities in assets are identified, validated, and recorded

securitygoaws
0
291
ID.RA 02 Idra 02A

Cyber threat intelligence is received from information sharing forums and sources

securitygoaws
0
291
ID.RA 03 Idra 03A

Internal and external threats to the organization are identified and recorded

securitygoaws
0
291
ID.RA 04 Idra 04A

Potential impacts and likelihoods of threats exploiting vulnerabilities are identified and recorded

securitygoaws
0
291
ID.RA 05 Idra 05A

Threats, vulnerabilities, likelihoods, and impacts are used to understand inherent risk and inform risk response prioritization

securitygoaws
0
291
ID.RA 06 Idra 06A

Risk responses are chosen, prioritized, planned, tracked, and communicated

securitygoaws
0
291
ID.RA 07 Idra 07A

Changes and exceptions are managed, assessed for risk impact, recorded, and tracked

securitygoaws
0
291
ID.RA 08 Idra 08A

Processes for receiving, analyzing, and responding to vulnerability disclosures are established

securitygoaws
0
291
ID.RA 09 Idra 09A

The authenticity and integrity of hardware and software are assessed prior to acquisition and use

securitygoaws
0
291
ID.RA 10 Idra 10A

Critical suppliers are assessed prior to acquisition

securitygoaws
0
291
ID.RM 01 Idrm 01A

Risk management processes are established, managed, and agreed to by organizational stakeholders

securitygoaws
0
291
ID.RM 02 Idrm 02A

Organizational risk tolerance is determined and clearly expressed

securitygoexpress
0
291
ID.RM 03 Idrm 03A

The organization’s determination of risk tolerance is informed by its role in critical infrastructure and sector specific risk analysis

securitygoaws
0
291
ID.SC 01 Idsc 01A

Cyber supply chain risk management processes are identified, established, assessed, managed, and agreed to by organizational stakeholders

securitygoaws
0
291
ID.SC 02 Idsc 02A

Suppliers and third party partners of information systems, components, and services are identified, prioritized, and assessed using a cyber supply cha

securitygoaws
0
291
ID.SC 03 Idsc 03A

Contracts with suppliers and third-party partners are used to implement appropriate measures designed to meet the objectives of an organization’s cybe

securitygoaws
0
291
ID.SC 04 Idsc 04A

Suppliers and third-party partners are routinely assessed using audits, test results, or other forms of evaluations to confirm they are meeting their

securitygoaws
0
291
ID.SC 05 Idsc 05A

Response and recovery planning and testing are conducted with suppliers and third-party providers

securitygoaws
0
291
Improvement (ID.IM) ImprovementA

Improvements to organizational cybersecurity risk management processes, procedures and activities are identified across all CSF Functions

securitygoaws
0
291
Risk Assessment (ID.RA) Risk AssessmentA

The cybersecurity risk to the organization, assets, and individuals is understood by the organization

securitygoaws
0
291
Risk Management Strategy (ID.RM) Risk Management StrategyA

Risk Management Strategy

securitygoaws
0
291
Supply Chain Risk Management (ID.SC) Supply Chain Risk ManagementA

Supply Chain Risk Management

securitygoaws
0
291
Awareness And Training (PR.AT) Awareness And TrainingA

The organization's personnel are provided with cybersecurity awareness and training so that they can perform their cybersecurity-related tasks

securitygoaws
0
291
Data Security (PR.DS) Data SecurityA

Data are managed consistent with the organization's risk strategy to protect the confidentiality, integrity, and availability of information

securitygoaws
0
291
Identity Management, Authentication And Access Control (PR.AC) Identity Management Authentication And Access ControlA

Identity Management, Authentication and Access Control

securitygoaws
0
291
Information Protection Processes And Procedures (PR.IP) Information Protection Processes And ProceduresA

Information Protection Processes and Procedures

securitygoaws
0
291
Maintenance (PR.MA) MaintenanceA

Maintenance

securitygoaws
0
291
PR.AA 01 Praa 01A

Identities and credentials for authorized users, services, and hardware are managed by the organization

securitygoaws
0
291
PR.AA 02 Praa 02A

Identities are proofed and bound to credentials based on the context of interactions

securitygoaws
0
291
PR.AA 03 Praa 03A

Users, services, and hardware are authenticated

securitygoaws
0
291
PR.AA 04 Praa 04A

Identity assertions are protected, conveyed, and verified

securitygoaws
0
291
PR.AA 05 Praa 05A

Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least

securitygoaws
0
291
PR.AA 06 Praa 06A

Physical access to assets is managed, monitored, and enforced commensurate with risk

securitygoaws
0
291
PR.AC 01 Prac 01A

Identities and credentials are issued, managed, verified, revoked, and audited for authorized devices, users and processes

securitygoaws
0
291
PR.AC 02 Prac 02A

Physical access to assets is managed and protected

securitygoaws
0
291
PR.AC 03 Prac 03A

Remote access is managed

securitygoaws
0
291
PR.AC 04 Prac 04A

Access permissions and authorizations are managed, incorporating the principles of least privilege and separation of duties

securitygoaws
0
291
PR.AC 05 Prac 05A

Network integrity is protected (e.g., network segregation, network segmentation)

securitygoaws
0
291
PR.AC 06 Prac 06A

Identities are proofed and bound to credentials and asserted in interactions

securitygoaws
0
291
PR.AC 07 Prac 07A

Users, devices, and other assets are authenticated (e.g., single-factor, multi-factor) commensurate with the risk of the transaction (e.g., individual

securitygoaws
0
291
PR.AT 01 Prat 01A

Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in

securitygoaws
0
291
PR.AT 02 Prat 02A

Individuals in specialized roles are provided with awareness and training so that they possess the knowledge and skills to perform relevant tasks with

securitygoaws
0
291