← all publishers

cyberstrikeus

@cyberstrikeus source repo

7171 published skills · page 13 of 72

  1. Cis Ocp V160 1 2 17 · cyberstrikeus
    Ensure that the --insecure-port argument is set to 0 (Manual)
    0 installs
  2. Cis Ocp V160 1 2 18 · cyberstrikeus
    Ensure that the --secure-port argument is not set to 0 (Manual)
    0 installs
  3. Cis Ocp V160 1 2 19 · cyberstrikeus
    Ensure that the healthz endpoint is protected by RBAC (Manual)
    0 installs
  4. Cis Ocp V160 1 2 20 · cyberstrikeus
    Ensure that the --audit-log-path argument is set (Manual)
    0 installs
  5. Cis Ocp V160 1 2 21 · cyberstrikeus
    Ensure that the audit logs are forwarded off the cluster for retention (Manual)
    0 installs
  6. Cis Ocp V160 1 2 22 · cyberstrikeus
    Ensure that the maximumRetainedFiles argument is set to 10 or as appropriate (Manual)
    0 installs
  7. Cis Ocp V160 1 2 23 · cyberstrikeus
    Ensure that the maximumFileSizeMegabytes argument is set to 100 (Manual)
    0 installs
  8. Cis Ocp V160 1 2 24 · cyberstrikeus
    Ensure that the --request-timeout argument is set (Manual)
    0 installs
  9. Cis Ocp V160 1 2 25 · cyberstrikeus
    Ensure that the --service-account-lookup argument is set to true (Manual)
    0 installs
  10. Cis Ocp V160 1 2 26 · cyberstrikeus
    Ensure that the --service-account-key-file argument is set as appropriate (Manual)
    0 installs
  11. Cis Ocp V160 1 2 27 · cyberstrikeus
    Ensure that the --etcd-certfile and --etcd-keyfile arguments are set as appropriate (Manual)
    0 installs
  12. Cis Ocp V160 1 2 28 · cyberstrikeus
    Ensure that the --tls-cert-file and --tls-private-key-file arguments are set as appropriate (Manual)
    0 installs
  13. Cis Ocp V160 1 2 29 · cyberstrikeus
    Ensure that the --client-ca-file argument is set as appropriate (Manual)
    0 installs
  14. Cis Ocp V160 1 2 30 · cyberstrikeus
    Ensure that the --etcd-cafile argument is set as appropriate (Manual)
    0 installs
  15. Cis Ocp V160 1 2 31 · cyberstrikeus
    Ensure that encryption providers are appropriately configured (Manual)
    0 installs
  16. Cis Ocp V160 1 2 32 · cyberstrikeus
    Ensure that the API Server only makes use of Strong Cryptographic Ciphers (Manual)
    0 installs
  17. Cis Ocp V160 1 2 33 · cyberstrikeus
    Ensure unsupported configuration overrides are not used (Manual)
    0 installs
  18. Cis Ocp V160 4 1 10 · cyberstrikeus
    Ensure that the kubelet configuration file ownership is set to root:root (Automated)
    0 installs
  19. Cis Ocp V160 4 2 10 · cyberstrikeus
    Ensure that the --rotate-certificates argument is not set to false (Manual)
    0 installs
  20. Cis Ocp V160 4 2 11 · cyberstrikeus
    Verify that the RotateKubeletServerCertificate argument is set to true (Manual)
    0 installs
  21. Cis Ocp V160 4 2 12 · cyberstrikeus
    Ensure that the Kubelet only makes use of Strong Cryptographic Ciphers (Manual)
    0 installs
  22. Cis Ocp V160 5 2 10 · cyberstrikeus
    Minimize access to privileged Security Context Constraints (Manual)
    0 installs
  23. Authenticator Management 03 05 12 Authenticator Management · cyberstrikeus
    Verify the identity of the individual, group, role, service, or device receiving the authenticator as part of the initial authenticator distribution.
    0 installs
  24. Malicious Code Protection 03 14 02 Malicious Code Protection · cyberstrikeus
    Implement malicious code protection mechanisms at system entry and exit points to detect and eradicate malicious code.
    0 installs
  25. Ia 2 1 Multi Factor Authentication To Privileged Accounts · cyberstrikeus
    Implement multi-factor authentication for access to privileged accounts.
    0 installs
  26. Ia 2 2 Multi Factor Authentication To Non Privileged Account · cyberstrikeus
    Implement multi-factor authentication for access to non-privileged accounts.
    0 installs
  27. Ia 2 4 Local Access To Non Privileged Accounts · cyberstrikeus
    Local Access to Non-privileged Accounts
    0 installs
  28. Ia 2 5 Individual Authentication With Group Authentication · cyberstrikeus
    When shared accounts or authenticators are employed, require users to be individually authenticated before granting access to the shared accounts or r
    0 installs
  29. Ia 4 6 Cross Organization Management · cyberstrikeus
    Coordinate with the following external organizations for cross-organization management of identifiers: [organization-defined].
    0 installs
  30. Ia 5 14 Managing Content Of Pki Trust Stores · cyberstrikeus
    For PKI-based authentication, employ an organization-wide methodology for managing the content of PKI trust stores installed across all platforms, inc
    0 installs
  31. Ia 5 16 In Person Or Trusted External Party Authenticator Is · cyberstrikeus
    Require that the issuance of [organization-defined] be conducted [organization-defined] before [organization-defined] with authorization by [organizat
    0 installs
  32. Ia 5 17 Presentation Attack Detection For Biometric Authenti · cyberstrikeus
    Employ presentation attack detection mechanisms for biometric-based authentication.
    0 installs
  33. Ia 5 4 Automated Support For Password Strength Determination · cyberstrikeus
    Automated Support for Password Strength Determination
    0 installs
  34. Ia 5 5 Change Authenticators Prior To Delivery · cyberstrikeus
    Require developers and installers of system components to provide unique authenticators or change default authenticators prior to delivery and install
    0 installs
  35. Ia 5 7 No Embedded Unencrypted Static Authenticators · cyberstrikeus
    Ensure that unencrypted static authenticators are not embedded in applications or other forms of static storage.
    0 installs
  36. Ia 5 1 Password Based Authentication · cyberstrikeus
    For password-based authentication: Maintain a list of commonly-used, expected, or compromised passwords and update the list [organization-defined] and
    0 installs
  37. Pe 3 8 Access Control Vestibules · cyberstrikeus
    Employ access control vestibules at [organization-defined].
    0 installs
  38. Pt 7 2 First Amendment Information · cyberstrikeus
    Prohibit the processing of information describing how any individual exercises rights guaranteed by the First Amendment unless expressly authorized by
    0 installs
  39. Pt 8 Computer Matching Requirements · cyberstrikeus
    When a system or organization processes information for the purpose of conducting a matching program: Obtain approval from the Data Integrity Board to
    0 installs
  40. Sa 10 1 Software And Firmware Integrity Verification · cyberstrikeus
    Require the developer of the system, system component, or system service to enable integrity verification of software and firmware components.
    0 installs
  41. Sa 12 8 Use Of All Source Intelligence · cyberstrikeus
    Use of All-source Intelligence
    0 installs
  42. Sa 15 Development Process Standards And Tools · cyberstrikeus
    Require the developer of the system, system component, or system service to follow a documented development process that: Explicitly addresses securit
    0 installs
  43. Sa 3 2 Use Of Live Or Operational Data · cyberstrikeus
    Approve, document, and control the use of live data in preproduction environments for the system, system component, or system service;
    0 installs
  44. Sa 8 11 Inverse Modification Threshold · cyberstrikeus
    Implement the security design principle of inverse modification threshold in [organization-defined].
    0 installs
  45. Sa 8 17 Secure Distributed Composition · cyberstrikeus
    Implement the security design principle of secure distributed composition in [organization-defined].
    0 installs
  46. Sc 13 3 Individuals Without Formal Access Approvals · cyberstrikeus
    Individuals Without Formal Access Approvals
    0 installs
  47. Sc 13 2 Nsa Approved Cryptography · cyberstrikeus
    NSA-approved Cryptography
    0 installs
  48. Sc 16 Transmission Of Security And Privacy Attributes · cyberstrikeus
    Associate [organization-defined] with information exchanged between systems and between system components.
    0 installs
  49. Sc 19 Voice Over Internet Protocol · cyberstrikeus
    Technology-specific;
    0 installs
  50. Sc 2 Separation Of System And User Functionality · cyberstrikeus
    Separate user functionality, including user interface services, from system management functionality.
    0 installs
  51. Sc 20 2 Data Origin And Integrity · cyberstrikeus
    Provide data origin and integrity protection artifacts for internal name/address resolution queries.
    0 installs
  52. Sc 21 1 Data Origin And Integrity · cyberstrikeus
    Data Origin and Integrity
    0 installs
  53. Sc 23 2 User Initiated Logouts And Message Displays · cyberstrikeus
    User-initiated Logouts and Message Displays
    0 installs
  54. Sc 29 1 Virtualization Techniques · cyberstrikeus
    Employ virtualization techniques to support the deployment of a diversity of operating systems and applications that are changed [organization-defined
    0 installs
  55. Sc 30 Concealment And Misdirection · cyberstrikeus
    Employ the following concealment and misdirection techniques for [organization-defined] at [organization-defined] to confuse and mislead adversaries:
    0 installs
  56. Sc 30 1 Virtualization Techniques · cyberstrikeus
    Virtualization Techniques
    0 installs
  57. Sc 34 3 Hardware Based Protection · cyberstrikeus
    Hardware-based Protection
    0 installs
  58. Sc 7 23 Disable Sender Feedback On Protocol Validation Failu · cyberstrikeus
    Disable feedback to senders on protocol format validation failure.
    0 installs
  59. Sc 7 4 External Telecommunications Services · cyberstrikeus
    Implement a managed interface for each external telecommunication service;
    0 installs
  60. Si 13 4 Standby Component Installation And Notification · cyberstrikeus
    If system component failures are detected: Ensure that the standby components are successfully and transparently installed within [organization-define
    0 installs
  61. Si 2 5 Automatic Software And Firmware Updates · cyberstrikeus
    Install [organization-defined] automatically to [organization-defined].
    0 installs
  62. Si 2 6 Removal Of Previous Versions Of Software And Firmware · cyberstrikeus
    Remove previous versions of [organization-defined] after updated versions have been installed.
    0 installs
  63. Si 4 1 System Wide Intrusion Detection System · cyberstrikeus
    Connect and configure individual intrusion detection tools into a system-wide intrusion detection system.
    0 installs
  64. Si 4 11 Analyze Communications Traffic Anomalies · cyberstrikeus
    Analyze outbound communications traffic at the external interfaces to the system and selected [organization-defined] to discover anomalies.
    0 installs
  65. Si 4 9 Testing Of Monitoring Tools And Mechanisms · cyberstrikeus
    Test intrusion-monitoring tools and mechanisms [organization-defined].
    0 installs
  66. Si 4 22 Unauthorized Network Services · cyberstrikeus
    Detect network services that have not been authorized or approved by [organization-defined] ;
    0 installs
  67. Si 6 1 Notification Of Failed Security Tests · cyberstrikeus
    Notification of Failed Security Tests
    0 installs
  68. Si 7 5 Automated Response To Integrity Violations · cyberstrikeus
    Automatically [organization-defined] when integrity violations are discovered.
    0 installs
  69. Si 7 Software Firmware And Information Integrity · cyberstrikeus
    Employ integrity verification tools to detect unauthorized changes to the following software, firmware, and information: [organization-defined] ;
    0 installs
  70. Si 8 3 Continuous Learning Capability · cyberstrikeus
    Implement spam protection mechanisms with a learning capability to more effectively identify legitimate communications traffic.
    0 installs
  71. Cis AWS Foundations 2 2 · cyberstrikeus
    Maintain current AWS account contact details
    0 installs
  72. Cis AWS Foundations 2 3 · cyberstrikeus
    Ensure security contact information is registered
    0 installs
  73. Cis AWS Foundations 2 4 · cyberstrikeus
    Ensure no 'root' user account access key exists
    0 installs
  74. Cis AWS Foundations 2 5 · cyberstrikeus
    Ensure MFA is enabled for the 'root' user account
    0 installs
  75. Cis AWS Foundations 2 6 · cyberstrikeus
    Ensure hardware MFA is enabled for the 'root' user account
    0 installs
  76. Cis AWS Foundations 2 7 · cyberstrikeus
    Eliminate use of the 'root' user for administrative and daily tasks
    0 installs
  77. Cis AWS Foundations 2 8 · cyberstrikeus
    Ensure IAM password policy requires minimum length of 14 or greater
    0 installs
  78. Cis AWS Foundations 2 9 · cyberstrikeus
    Ensure IAM password policy prevents password reuse
    0 installs
  79. Cis AWS Foundations 4 1 · cyberstrikeus
    Ensure CloudTrail is enabled in all regions
    0 installs
  80. Cis AWS Foundations 4 2 · cyberstrikeus
    Ensure CloudTrail log file validation is enabled
    0 installs
  81. Cis AWS Foundations 4 3 · cyberstrikeus
    Ensure AWS Config is enabled in all regions
    0 installs
  82. Cis AWS Foundations 4 4 · cyberstrikeus
    Ensure that server access logging is enabled on the CloudTrail S3 bucket
    0 installs
  83. Cis AWS Foundations 4 5 · cyberstrikeus
    Ensure CloudTrail logs are encrypted at rest using KMS CMKs
    0 installs
  84. Cis AWS Foundations 4 6 · cyberstrikeus
    Ensure rotation for customer-created symmetric CMKs is enabled
    0 installs
  85. Cis AWS Foundations 4 7 · cyberstrikeus
    Ensure VPC flow logging is enabled in all VPCs
    0 installs
  86. Cis AWS Foundations 4 8 · cyberstrikeus
    Ensure that object-level logging for write events is enabled for S3 buckets
    0 installs
  87. Cis AWS Foundations 4 9 · cyberstrikeus
    Ensure that object-level logging for read events is enabled for S3 buckets
    0 installs
  88. Cis AWS Foundations 5 1 · cyberstrikeus
    Ensure unauthorized API calls are monitored
    0 installs
  89. Cis AWS Foundations 5 2 · cyberstrikeus
    Ensure management console sign-in without MFA is monitored
    0 installs
  90. Cis AWS Foundations 5 3 · cyberstrikeus
    Ensure usage of the 'root' account is monitored
    0 installs
  91. Cis AWS Foundations 5 4 · cyberstrikeus
    Ensure IAM policy changes are monitored
    0 installs
  92. Cis AWS Foundations 5 5 · cyberstrikeus
    Ensure CloudTrail configuration changes are monitored
    0 installs
  93. Cis AWS Foundations 5 6 · cyberstrikeus
    Ensure AWS Management Console authentication failures are monitored
    0 installs
  94. Cis AWS Foundations 5 7 · cyberstrikeus
    Ensure disabling or scheduled deletion of customer created CMKs is monitored
    0 installs
  95. Cis AWS Foundations 5 8 · cyberstrikeus
    Ensure S3 bucket policy changes are monitored
    0 installs
  96. Cis AWS Foundations 5 9 · cyberstrikeus
    Ensure AWS Config configuration changes are monitored
    0 installs
  97. Cis AWS Foundations 6 2 · cyberstrikeus
    Ensure no Network ACLs allow ingress from 0.0.0.0/0 to remote server administration ports
    0 installs
  98. Cis AWS Foundations 6 3 · cyberstrikeus
    Ensure no security groups allow ingress from 0.0.0.0/0 to remote server administration ports
    0 installs
  99. Cis AWS Foundations 6 4 · cyberstrikeus
    Ensure no security groups allow ingress from ::/0 to remote server administration ports
    0 installs
  100. Cis AWS Foundations 6 5 · cyberstrikeus
    Ensure the default security group of every VPC restricts all traffic
    0 installs