
Claude Skills by CyberStrikeus
github.com/CyberStrikeusOrganizational cybersecurity policy is established and communicated
Cybersecurity roles and responsibilities are coordinated and aligned with internal roles and external partners
Legal and regulatory requirements regarding cybersecurity, including privacy and civil liberties obligations, are understood and managed
Governance and risk management processes address cybersecurity risks
Improvements are identified from evaluations
Improvements are identified from security tests and exercises, including those done in coordination with suppliers and relevant third parties
Improvements are identified from execution of operational processes, procedures, and activities
Incident response plans and other cybersecurity plans that affect operations are established, communicated, maintained, and improved
Vulnerabilities in assets are identified, validated, and recorded
Cyber threat intelligence is received from information sharing forums and sources
Internal and external threats to the organization are identified and recorded
Potential impacts and likelihoods of threats exploiting vulnerabilities are identified and recorded
Threats, vulnerabilities, likelihoods, and impacts are used to understand inherent risk and inform risk response prioritization
Risk responses are chosen, prioritized, planned, tracked, and communicated
Changes and exceptions are managed, assessed for risk impact, recorded, and tracked
Processes for receiving, analyzing, and responding to vulnerability disclosures are established
The authenticity and integrity of hardware and software are assessed prior to acquisition and use
Critical suppliers are assessed prior to acquisition
Risk management processes are established, managed, and agreed to by organizational stakeholders
Organizational risk tolerance is determined and clearly expressed
The organization’s determination of risk tolerance is informed by its role in critical infrastructure and sector specific risk analysis
Cyber supply chain risk management processes are identified, established, assessed, managed, and agreed to by organizational stakeholders
Suppliers and third party partners of information systems, components, and services are identified, prioritized, and assessed using a cyber supply cha
Contracts with suppliers and third-party partners are used to implement appropriate measures designed to meet the objectives of an organization’s cybe
Suppliers and third-party partners are routinely assessed using audits, test results, or other forms of evaluations to confirm they are meeting their
Response and recovery planning and testing are conducted with suppliers and third-party providers
Improvements to organizational cybersecurity risk management processes, procedures and activities are identified across all CSF Functions
The cybersecurity risk to the organization, assets, and individuals is understood by the organization
Risk Management Strategy
Supply Chain Risk Management
The organization's personnel are provided with cybersecurity awareness and training so that they can perform their cybersecurity-related tasks
Data are managed consistent with the organization's risk strategy to protect the confidentiality, integrity, and availability of information
Identity Management, Authentication and Access Control
Information Protection Processes and Procedures
Maintenance
Identities and credentials for authorized users, services, and hardware are managed by the organization
Identities are proofed and bound to credentials based on the context of interactions
Users, services, and hardware are authenticated
Identity assertions are protected, conveyed, and verified
Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least
Physical access to assets is managed, monitored, and enforced commensurate with risk
Identities and credentials are issued, managed, verified, revoked, and audited for authorized devices, users and processes
Physical access to assets is managed and protected
Remote access is managed
Access permissions and authorizations are managed, incorporating the principles of least privilege and separation of duties
Network integrity is protected (e.g., network segregation, network segmentation)
Identities are proofed and bound to credentials and asserted in interactions
Users, devices, and other assets are authenticated (e.g., single-factor, multi-factor) commensurate with the risk of the transaction (e.g., individual
Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in
Individuals in specialized roles are provided with awareness and training so that they possess the knowledge and skills to perform relevant tasks with