cyberstrikeus
- 7.2k skills
- 0 followers
- 1 day ago last updated
- ▌
- ▌
- ▌
- ▌
- ▌ Cis Ocp V160 1 2 21 · cyberstrikeusEnsure that the audit logs are forwarded off the cluster for retention (Manual)
- ▌ Cis Ocp V160 1 2 22 · cyberstrikeusEnsure that the maximumRetainedFiles argument is set to 10 or as appropriate (Manual)
- ▌ Cis Ocp V160 1 2 23 · cyberstrikeusEnsure that the maximumFileSizeMegabytes argument is set to 100 (Manual)
- ▌
- ▌ Cis Ocp V160 1 2 25 · cyberstrikeusEnsure that the --service-account-lookup argument is set to true (Manual)
- ▌ Cis Ocp V160 1 2 26 · cyberstrikeusEnsure that the --service-account-key-file argument is set as appropriate (Manual)
- ▌ Cis Ocp V160 1 2 27 · cyberstrikeusEnsure that the --etcd-certfile and --etcd-keyfile arguments are set as appropriate (Manual)
- ▌ Cis Ocp V160 1 2 28 · cyberstrikeusEnsure that the --tls-cert-file and --tls-private-key-file arguments are set as appropriate (Manual)
- ▌ Cis Ocp V160 1 2 29 · cyberstrikeusEnsure that the --client-ca-file argument is set as appropriate (Manual)
- ▌ Cis Ocp V160 1 2 30 · cyberstrikeusEnsure that the --etcd-cafile argument is set as appropriate (Manual)
- ▌ Cis Ocp V160 1 2 31 · cyberstrikeusEnsure that encryption providers are appropriately configured (Manual)
- ▌ Cis Ocp V160 1 2 32 · cyberstrikeusEnsure that the API Server only makes use of Strong Cryptographic Ciphers (Manual)
- ▌ Cis Ocp V160 1 2 33 · cyberstrikeusEnsure unsupported configuration overrides are not used (Manual)
- ▌ Cis Ocp V160 4 1 10 · cyberstrikeusEnsure that the kubelet configuration file ownership is set to root:root (Automated)
- ▌ Cis Ocp V160 4 2 10 · cyberstrikeusEnsure that the --rotate-certificates argument is not set to false (Manual)
- ▌ Cis Ocp V160 4 2 11 · cyberstrikeusVerify that the RotateKubeletServerCertificate argument is set to true (Manual)
- ▌ Cis Ocp V160 4 2 12 · cyberstrikeusEnsure that the Kubelet only makes use of Strong Cryptographic Ciphers (Manual)
- ▌ Cis Ocp V160 5 2 10 · cyberstrikeusMinimize access to privileged Security Context Constraints (Manual)
- ▌ Authenticator Management 03 05 12 Authenticator Management · cyberstrikeusVerify the identity of the individual, group, role, service, or device receiving the authenticator as part of the initial authenticator distribution.
- ▌ Malicious Code Protection 03 14 02 Malicious Code Protection · cyberstrikeusImplement malicious code protection mechanisms at system entry and exit points to detect and eradicate malicious code.
- ▌ Ia 2 1 Multi Factor Authentication To Privileged Accounts · cyberstrikeusImplement multi-factor authentication for access to privileged accounts.
- ▌ Ia 2 2 Multi Factor Authentication To Non Privileged Account · cyberstrikeusImplement multi-factor authentication for access to non-privileged accounts.
- ▌ Ia 2 4 Local Access To Non Privileged Accounts · cyberstrikeusLocal Access to Non-privileged Accounts
- ▌ Ia 2 5 Individual Authentication With Group Authentication · cyberstrikeusWhen shared accounts or authenticators are employed, require users to be individually authenticated before granting access to the shared accounts or r
- ▌ Ia 4 6 Cross Organization Management · cyberstrikeusCoordinate with the following external organizations for cross-organization management of identifiers: [organization-defined].
- ▌ Ia 5 14 Managing Content Of Pki Trust Stores · cyberstrikeusFor PKI-based authentication, employ an organization-wide methodology for managing the content of PKI trust stores installed across all platforms, inc
- ▌ Ia 5 16 In Person Or Trusted External Party Authenticator Is · cyberstrikeusRequire that the issuance of [organization-defined] be conducted [organization-defined] before [organization-defined] with authorization by [organizat
- ▌ Ia 5 17 Presentation Attack Detection For Biometric Authenti · cyberstrikeusEmploy presentation attack detection mechanisms for biometric-based authentication.
- ▌ Ia 5 4 Automated Support For Password Strength Determination · cyberstrikeusAutomated Support for Password Strength Determination
- ▌ Ia 5 5 Change Authenticators Prior To Delivery · cyberstrikeusRequire developers and installers of system components to provide unique authenticators or change default authenticators prior to delivery and install
- ▌ Ia 5 7 No Embedded Unencrypted Static Authenticators · cyberstrikeusEnsure that unencrypted static authenticators are not embedded in applications or other forms of static storage.
- ▌ Ia 5 1 Password Based Authentication · cyberstrikeusFor password-based authentication: Maintain a list of commonly-used, expected, or compromised passwords and update the list [organization-defined] and
- ▌ Pe 3 8 Access Control Vestibules · cyberstrikeusEmploy access control vestibules at [organization-defined].
- ▌ Pt 7 2 First Amendment Information · cyberstrikeusProhibit the processing of information describing how any individual exercises rights guaranteed by the First Amendment unless expressly authorized by
- ▌ Pt 8 Computer Matching Requirements · cyberstrikeusWhen a system or organization processes information for the purpose of conducting a matching program: Obtain approval from the Data Integrity Board to
- ▌ Sa 10 1 Software And Firmware Integrity Verification · cyberstrikeusRequire the developer of the system, system component, or system service to enable integrity verification of software and firmware components.
- ▌
- ▌ Sa 15 Development Process Standards And Tools · cyberstrikeusRequire the developer of the system, system component, or system service to follow a documented development process that: Explicitly addresses securit
- ▌ Sa 3 2 Use Of Live Or Operational Data · cyberstrikeusApprove, document, and control the use of live data in preproduction environments for the system, system component, or system service;
- ▌ Sa 8 11 Inverse Modification Threshold · cyberstrikeusImplement the security design principle of inverse modification threshold in [organization-defined].
- ▌ Sa 8 17 Secure Distributed Composition · cyberstrikeusImplement the security design principle of secure distributed composition in [organization-defined].
- ▌ Sc 13 3 Individuals Without Formal Access Approvals · cyberstrikeusIndividuals Without Formal Access Approvals
- ▌
- ▌ Sc 16 Transmission Of Security And Privacy Attributes · cyberstrikeusAssociate [organization-defined] with information exchanged between systems and between system components.
- ▌
- ▌ Sc 2 Separation Of System And User Functionality · cyberstrikeusSeparate user functionality, including user interface services, from system management functionality.
- ▌ Sc 20 2 Data Origin And Integrity · cyberstrikeusProvide data origin and integrity protection artifacts for internal name/address resolution queries.
- ▌
- ▌ Sc 23 2 User Initiated Logouts And Message Displays · cyberstrikeusUser-initiated Logouts and Message Displays
- ▌ Sc 29 1 Virtualization Techniques · cyberstrikeusEmploy virtualization techniques to support the deployment of a diversity of operating systems and applications that are changed [organization-defined
- ▌ Sc 30 Concealment And Misdirection · cyberstrikeusEmploy the following concealment and misdirection techniques for [organization-defined] at [organization-defined] to confuse and mislead adversaries:
- ▌
- ▌
- ▌ Sc 7 23 Disable Sender Feedback On Protocol Validation Failu · cyberstrikeusDisable feedback to senders on protocol format validation failure.
- ▌ Sc 7 4 External Telecommunications Services · cyberstrikeusImplement a managed interface for each external telecommunication service;
- ▌ Si 13 4 Standby Component Installation And Notification · cyberstrikeusIf system component failures are detected: Ensure that the standby components are successfully and transparently installed within [organization-define
- ▌ Si 2 5 Automatic Software And Firmware Updates · cyberstrikeusInstall [organization-defined] automatically to [organization-defined].
- ▌ Si 2 6 Removal Of Previous Versions Of Software And Firmware · cyberstrikeusRemove previous versions of [organization-defined] after updated versions have been installed.
- ▌ Si 4 1 System Wide Intrusion Detection System · cyberstrikeusConnect and configure individual intrusion detection tools into a system-wide intrusion detection system.
- ▌ Si 4 11 Analyze Communications Traffic Anomalies · cyberstrikeusAnalyze outbound communications traffic at the external interfaces to the system and selected [organization-defined] to discover anomalies.
- ▌ Si 4 9 Testing Of Monitoring Tools And Mechanisms · cyberstrikeusTest intrusion-monitoring tools and mechanisms [organization-defined].
- ▌ Si 4 22 Unauthorized Network Services · cyberstrikeusDetect network services that have not been authorized or approved by [organization-defined] ;
- ▌
- ▌ Si 7 5 Automated Response To Integrity Violations · cyberstrikeusAutomatically [organization-defined] when integrity violations are discovered.
- ▌ Si 7 Software Firmware And Information Integrity · cyberstrikeusEmploy integrity verification tools to detect unauthorized changes to the following software, firmware, and information: [organization-defined] ;
- ▌ Si 8 3 Continuous Learning Capability · cyberstrikeusImplement spam protection mechanisms with a learning capability to more effectively identify legitimate communications traffic.
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌ Cis AWS Foundations 2 7 · cyberstrikeusEliminate use of the 'root' user for administrative and daily tasks
- ▌ Cis AWS Foundations 2 8 · cyberstrikeusEnsure IAM password policy requires minimum length of 14 or greater
- ▌
- ▌
- ▌
- ▌
- ▌ Cis AWS Foundations 4 4 · cyberstrikeusEnsure that server access logging is enabled on the CloudTrail S3 bucket
- ▌
- ▌ Cis AWS Foundations 4 6 · cyberstrikeusEnsure rotation for customer-created symmetric CMKs is enabled
- ▌
- ▌ Cis AWS Foundations 4 8 · cyberstrikeusEnsure that object-level logging for write events is enabled for S3 buckets
- ▌ Cis AWS Foundations 4 9 · cyberstrikeusEnsure that object-level logging for read events is enabled for S3 buckets
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌ Cis AWS Foundations 5 6 · cyberstrikeusEnsure AWS Management Console authentication failures are monitored
- ▌ Cis AWS Foundations 5 7 · cyberstrikeusEnsure disabling or scheduled deletion of customer created CMKs is monitored
- ▌
- ▌
- ▌ Cis AWS Foundations 6 2 · cyberstrikeusEnsure no Network ACLs allow ingress from 0.0.0.0/0 to remote server administration ports
- ▌ Cis AWS Foundations 6 3 · cyberstrikeusEnsure no security groups allow ingress from 0.0.0.0/0 to remote server administration ports
- ▌ Cis AWS Foundations 6 4 · cyberstrikeusEnsure no security groups allow ingress from ::/0 to remote server administration ports
- ▌ Cis AWS Foundations 6 5 · cyberstrikeusEnsure the default security group of every VPC restricts all traffic