cyberstrikeus
- 7.2k skills
- 0 followers
- 2 days ago last updated
- ▌ Cis Eks V160 4 2 4 · cyberstrikeusMinimize the admission of containers wishing to share the host network namespace (Automated)
- ▌ Cis Eks V160 4 2 5 · cyberstrikeusMinimize the admission of containers with allowPrivilegeEscalation (Automated)
- ▌
- ▌ Cis Eks V160 4 3 2 · cyberstrikeusEnsure that all Namespaces have Network Policies defined (Automated)
- ▌ Cis Eks V160 4 4 1 · cyberstrikeusPrefer using secrets as files over secrets as environment variables (Automated)
- ▌
- ▌ Cis Eks V160 4 5 1 · cyberstrikeusCreate administrative boundaries between resources using namespaces (Manual)
- ▌
- ▌ Cis Eks V160 5 1 1 · cyberstrikeusEnsure Image Vulnerability Scanning using Amazon ECR image scanning or a third party provider (Automated)
- ▌
- ▌
- ▌
- ▌
- ▌ Cis Eks V160 5 3 1 · cyberstrikeusEnsure Kubernetes Secrets are encrypted using Customer Master Keys (CMKs) managed in AWS KMS (Manual)
- ▌
- ▌ Cis Eks V160 5 4 2 · cyberstrikeusEnsure clusters are created with Private Endpoint Enabled and Public Access Disabled (Automated)
- ▌
- ▌ Cis Eks V160 5 4 4 · cyberstrikeusEnsure Network Policy is Enabled and set as appropriate (Automated)
- ▌ Cis Eks V160 5 4 5 · cyberstrikeusEncrypt traffic to HTTPS load balancers with TLS certificates (Manual)
- ▌ Cis Eks V160 5 5 1 · cyberstrikeusManage Kubernetes RBAC users with AWS IAM Authenticator for Kubernetes or Upgrade to AWS CLI v1.16.156 or greater (Manual)
- ▌ Cis Eks V180 4 1 1 · cyberstrikeusEnsure that the cluster-admin role is only used where required (Manual)
- ▌
- ▌
- ▌
- ▌ Cis Eks V180 4 1 5 · cyberstrikeusEnsure that default service accounts are not actively used (Manual)
- ▌ Cis Eks V180 4 1 6 · cyberstrikeusEnsure that Service Account Tokens are only mounted where necessary (Manual)
- ▌
- ▌
- ▌ Cis Eks V180 4 2 2 · cyberstrikeusMinimize the admission of containers wishing to share the host process ID namespace (Manual)
- ▌ Cis Eks V180 4 2 3 · cyberstrikeusMinimize the admission of containers wishing to share the host IPC namespace (Manual)
- ▌ Cis Eks V180 4 2 4 · cyberstrikeusMinimize the admission of containers wishing to share the host network namespace (Manual)
- ▌ Cis Eks V180 4 2 5 · cyberstrikeusMinimize the admission of containers with allowPrivilegeEscalation (Manual)
- ▌ Cis Eks V180 4 3 2 · cyberstrikeusEnsure that all Namespaces have Network Policies defined (Manual)
- ▌ Cis Eks V180 5 4 4 · cyberstrikeusEnsure AmazonEKSNetworkingPolicy is Enabled and set as appropriate (Automated)
- ▌ Cis K8S V1110 2 1 · cyberstrikeusEnsure that the --cert-file and --key-file arguments are set as appropriate (Automated)
- ▌ Cis K8S V1110 2 2 · cyberstrikeusEnsure that the --cert-file and --key-file arguments are set as appropriate (Automated)
- ▌ Cis K8S V1110 2 3 · cyberstrikeusEnsure that the --client-cert-auth argument is set to true (Automated)
- ▌ Cis K8S V1110 2 4 · cyberstrikeusEnsure that the --auto-tls argument is not set to true (Automated)
- ▌ Cis K8S V1110 2 5 · cyberstrikeusEnsure that the --peer-cert-file and --peer-key-file arguments are set as appropriate (Automated)
- ▌ Cis K8S V1110 2 6 · cyberstrikeusEnsure that the --peer-client-cert-auth argument is set to true (Automated)
- ▌ Cis K8S V1110 2 7 · cyberstrikeusEnsure that the --peer-auto-tls argument is not set to true (Automated)
- ▌ Cis K8S V1110 2 8 · cyberstrikeusEnsure that a unique Certificate Authority is used for etcd (Manual)
- ▌ Cis K8S V1111 2 1 · cyberstrikeusEnsure that the --cert-file and --key-file arguments are set as appropriate (Automated)
- ▌ Cis K8S V1111 2 2 · cyberstrikeusEnsure that the --cert-file and --key-file arguments are set as appropriate (Automated)
- ▌ Cis K8S V1111 2 5 · cyberstrikeusEnsure that the --peer-cert-file and --peer-key-file arguments are set as appropriate (Automated)
- ▌ Cis K8S V1111 2 6 · cyberstrikeusEnsure that the --peer-client-cert-auth argument is set to true (Automated)
- ▌ Cis K8S V1111 2 7 · cyberstrikeusEnsure that the --peer-auto-tls argument is not set to true (Automated)
- ▌ Cis K8S V1111 2 8 · cyberstrikeusEnsure that a unique Certificate Authority is used for etcd (Manual)
- ▌ Cis K8S V1120 2 1 · cyberstrikeusEnsure that the --cert-file and --key-file arguments are set as appropriate (Automated)
- ▌ Cis K8S V1120 2 2 · cyberstrikeusEnsure that the --client-cert-auth argument is set to true (Automated)
- ▌ Cis K8S V1120 2 3 · cyberstrikeusEnsure that the --auto-tls argument is not set to true (Automated)
- ▌ Cis K8S V1120 2 4 · cyberstrikeusEnsure that the --peer-cert-file and --peer-key-file arguments are set as appropriate (Automated)
- ▌ Cis K8S V1120 2 5 · cyberstrikeusEnsure that the --peer-client-cert-auth argument is set to true (Automated)
- ▌ Cis K8S V1120 2 6 · cyberstrikeusEnsure that the --peer-auto-tls argument is not set to true (Automated)
- ▌ Cis K8S V1120 2 7 · cyberstrikeusEnsure that a unique Certificate Authority is used for etcd (Manual)
- ▌ Cis K8S V200 1 1 1 · cyberstrikeusEnsure that the API server pod specification file permissions are set to 600 or more restrictive (Automated)
- ▌ Cis K8S V200 1 1 2 · cyberstrikeusEnsure that the API server pod specification file ownership is set to root:root (Automated)
- ▌ Cis K8S V200 1 1 3 · cyberstrikeusEnsure that the controller manager pod specification file permissions are set to 600 or more restrictive (Automated)
- ▌ Cis K8S V200 1 1 4 · cyberstrikeusEnsure that the controller manager pod specification file ownership is set to root:root (Automated)
- ▌ Cis K8S V200 1 1 5 · cyberstrikeusEnsure that the scheduler pod specification file permissions are set to 600 or more restrictive (Automated)
- ▌ Cis K8S V200 1 1 6 · cyberstrikeusEnsure that the scheduler pod specification file ownership is set to root:root (Automated)
- ▌ Cis K8S V200 1 1 7 · cyberstrikeusEnsure that the etcd pod specification file permissions are set to 600 or more restrictive (Automated)
- ▌ Cis K8S V200 1 1 8 · cyberstrikeusEnsure that the etcd pod specification file ownership is set to root:root (Automated)
- ▌ Cis K8S V200 1 1 9 · cyberstrikeusEnsure that the Container Network Interface file permissions are set to 600 or more restrictive (Manual)
- ▌ Cis K8S V200 1 2 1 · cyberstrikeusEnsure that the --anonymous-auth argument is set to false (Manual)
- ▌ Cis K8S V200 1 2 2 · cyberstrikeusEnsure that the --token-auth-file parameter is not set (Automated)
- ▌
- ▌ Cis K8S V200 1 2 4 · cyberstrikeusEnsure that the --kubelet-client-certificate and --kubelet-client-key arguments are set as appropriate (Automated)
- ▌ Cis K8S V200 1 2 5 · cyberstrikeusEnsure that the --kubelet-certificate-authority argument is set as appropriate (Automated)
- ▌ Cis K8S V200 1 2 6 · cyberstrikeusEnsure that the --authorization-mode argument is not set to AlwaysAllow (Automated)
- ▌ Cis K8S V200 1 2 7 · cyberstrikeusEnsure that the --authorization-mode argument includes Node (Automated)
- ▌ Cis K8S V200 1 2 8 · cyberstrikeusEnsure that the --authorization-mode argument includes RBAC (Automated)
- ▌ Cis K8S V200 1 2 9 · cyberstrikeusEnsure that the admission control plugin EventRateLimit is set (Manual)
- ▌ Cis K8S V200 1 3 1 · cyberstrikeusEnsure that the --terminated-pod-gc-threshold argument is set as appropriate (Manual)
- ▌
- ▌ Cis K8S V200 1 3 3 · cyberstrikeusEnsure that the --use-service-account-credentials argument is set to true (Automated)
- ▌ Cis K8S V200 1 3 4 · cyberstrikeusEnsure that the --service-account-private-key-file argument is set as appropriate (Automated)
- ▌ Cis K8S V200 1 3 5 · cyberstrikeusEnsure that the --root-ca-file argument is set as appropriate (Automated)
- ▌ Cis K8S V200 1 3 6 · cyberstrikeusEnsure that the RotateKubeletServerCertificate argument is set to true (Automated)
- ▌ Cis K8S V200 1 3 7 · cyberstrikeusEnsure that the --bind-address argument is set to 127.0.0.1 (Automated)
- ▌
- ▌ Cis K8S V200 1 4 2 · cyberstrikeusEnsure that the --bind-address argument is set to 127.0.0.1 (Automated)
- ▌ Cis K8S V200 3 1 1 · cyberstrikeusClient certificate authentication should not be used for users (Manual)
- ▌ Cis K8S V200 3 1 2 · cyberstrikeusService account token authentication should not be used for users (Manual)
- ▌ Cis K8S V200 3 1 3 · cyberstrikeusBootstrap token authentication should not be used for users (Manual)
- ▌
- ▌ Cis K8S V200 3 2 2 · cyberstrikeusEnsure that the audit policy covers key security concerns (Manual)
- ▌ Cis K8S V200 4 1 1 · cyberstrikeusEnsure that the kubelet service file permissions are set to 600 or more restrictive (Automated)
- ▌ Cis K8S V200 4 1 2 · cyberstrikeusEnsure that the kubelet service file ownership is set to root:root (Automated)
- ▌ Cis K8S V200 4 1 3 · cyberstrikeusIf proxy kubeconfig file exists ensure permissions are set to 600 or more restrictive (Manual)
- ▌ Cis K8S V200 4 1 4 · cyberstrikeusIf proxy kubeconfig file exists ensure ownership is set to root:root (Manual)
- ▌ Cis K8S V200 4 1 5 · cyberstrikeusEnsure that the --kubeconfig kubelet.conf file permissions are set to 600 or more restrictive (Automated)
- ▌ Cis K8S V200 4 1 6 · cyberstrikeusEnsure that the --kubeconfig kubelet.conf file ownership is set to root:root (Automated)
- ▌ Cis K8S V200 4 1 7 · cyberstrikeusEnsure that the certificate authorities file permissions are set to 644 or more restrictive (Manual)
- ▌ Cis K8S V200 4 1 8 · cyberstrikeusEnsure that the client certificate authorities file ownership is set to root:root (Manual)
- ▌ Cis K8S V200 4 1 9 · cyberstrikeusIf the kubelet config.yaml configuration file is being used validate permissions set to 600 or more restrictive (Automated)
- ▌ Cis K8S V200 4 2 1 · cyberstrikeusEnsure that the --anonymous-auth argument is set to false (Automated)
- ▌ Cis K8S V200 4 2 2 · cyberstrikeusEnsure that the --authorization-mode argument is not set to AlwaysAllow (Automated)
- ▌ Cis K8S V200 4 2 3 · cyberstrikeusEnsure that the --client-ca-file argument is set as appropriate (Automated)
- ▌