# Cis Ocp Vm V100 1 11

> Restrict exec access to the pods (Manual)

- Skill: `cyberstrikeus/cis-ocp-vm-v100-1-11` (Agent Skill)
- Install (CLI): `npx skillmds@latest add cyberstrikeus/cis-ocp-vm-v100-1-11`
- Raw SKILL.md: https://api.skillmd.com/api/skills/cyberstrikeus/cis-ocp-vm-v100-1-11/raw
- Safety review: PASS (external: skill-scanner PASS, skillspector PASS)
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: DevOps & Infra
- Author: cyberstrikeus (https://skillmd.com/u/cyberstrikeus)
- Updated: 2026-09-17
- Page: https://skillmd.com/skills/cyberstrikeus/cis-ocp-vm-v100-1-11

---


# CIS 1.11 — Restrict exec access to the pods

## Profile Applicability

- Level 1

## Description

The ability to `exec` commands in a pod allows for arbitrary execution by users. This includes administrative functions which normally require elevation of privileges by an approved administrator, and could lead to unauthorized use of both security and non-security related administrative functions.

## Rationale

The exec command is not necessary for the proper functioning of OpenShift Virtualization.

## Impact

Limiting access to exec can restrict access to utilities used to accomplish tasks users are authorized to perform. These restrictions may require more granular role or attribute based access controls to be defined.

## Audit Procedure

To verify who can exec commands in pods, use the following command:

```bash
$ oc adm policy who-can exec pod
```

## Remediation

Assign `exec` access to `pods` in the cluster only to approved administrators.

## Default Value

The ability to run `exec` commands is reserved for cluster administrators by default.

## References

- CIS Redhat OpenShift Virtual Machine Extension Benchmark v1.0.0, Section 1.11

## CIS Controls

| Controls Version | Control                                                  | IG 1 | IG 2 | IG 3 |
| ---------------- | -------------------------------------------------------- | ---- | ---- | ---- |
| v8               | 4 Secure Configuration of Enterprise Assets and Software | N    | N    | N    |
| v7               | 5.1 Establish Secure Configurations                      | Y    | Y    | Y    |

## MITRE ATT&CK Mappings

| Tactic           | Technique                              |
| ---------------- | -------------------------------------- |
| Execution        | T1609 Container Administration Command |
| Lateral Movement | T1021 Remote Services                  |

## Profile

- Level 1 - OpenShift Virtualization

