← all publishers

cyberstrikeus

@cyberstrikeus source repo

7171 published skills · page 30 of 72

  1. Cis Ocp V160 5 7 2 · cyberstrikeus
    Ensure that the seccomp profile is set to docker/default in your pod definitions (Manual)
    0 installs
  2. Cis Ocp V160 5 7 3 · cyberstrikeus
    Apply Security Context to Your Pods and Containers (Manual)
    0 installs
  3. Cis Ocp V160 5 7 4 · cyberstrikeus
    The default namespace should not be used (Manual)
    0 installs
  4. Authentication Feedback 03 05 11 Authentication Feedback · cyberstrikeus
    Authentication Feedback
    0 installs
  5. System Monitoring 03 14 06 System Monitoring · cyberstrikeus
    Monitor the system to detect: Attacks and indicators of potential attacks and Unauthorized connections. Identify unauthorized use of the system. Monit
    0 installs
  6. Ia 12 3 Identity Evidence Validation And Verification · cyberstrikeus
    Require that the presented identity evidence be validated and verified through [organization-defined].
    0 installs
  7. Ia 5 3 In Person Or Trusted External Party Registration · cyberstrikeus
    In-person or Trusted External Party Registration
    0 installs
  8. Ia 5 6 Protection Of Authenticators · cyberstrikeus
    Protect authenticators commensurate with the security category of the information to which use of the authenticator permits access.
    0 installs
  9. Ia 8 1 Acceptance Of Piv Credentials From Other Agencies · cyberstrikeus
    Accept and electronically verify Personal Identity Verification-compliant credentials from other federal agencies.
    0 installs
  10. Pe 9 Power Equipment And Cabling · cyberstrikeus
    Protect power equipment and power cabling for the system from damage and destruction.
    0 installs
  11. Sa 11 Developer Testing And Evaluation · cyberstrikeus
    Require the developer of the system, system component, or system service, at all post-design stages of the system development life cycle, to: Develop
    0 installs
  12. Sa 12 7 Assessments Prior To Selection Acceptance Update · cyberstrikeus
    Assessments Prior to Selection / Acceptance / Update
    0 installs
  13. Sa 17 7 Structure For Least Privilege · cyberstrikeus
    Require the developer of the system, system component, or system service to structure security-relevant hardware, software, and firmware to facilitate
    0 installs
  14. Sa 8 4 Partially Ordered Dependencies · cyberstrikeus
    Implement the security design principle of partially ordered dependencies in [organization-defined].
    0 installs
  15. Sa 9 8 Processing And Storage Location Us Jurisdiction · cyberstrikeus
    Restrict the geographic location of information processing and data storage to facilities located within in the legal jurisdictional boundary of the U
    0 installs
  16. Sc 12 6 Physical Control Of Keys · cyberstrikeus
    Maintain physical control of cryptographic keys when stored information is encrypted by external service providers.
    0 installs
  17. Sc 16 2 Anti Spoofing Mechanisms · cyberstrikeus
    Implement anti-spoofing mechanisms to prevent adversaries from falsifying the security attributes indicating the successful application of the securit
    0 installs
  18. Sc 28 1 Cryptographic Protection · cyberstrikeus
    Implement cryptographic mechanisms to prevent unauthorized disclosure and modification of the following information at rest on [organization-defined]:
    0 installs
  19. Sc 4 Information In Shared System Resources · cyberstrikeus
    Prevent unauthorized and unintended information transfer via shared system resources.
    0 installs
  20. Sc 40 3 Imitative Or Manipulative Communications Deception · cyberstrikeus
    Implement cryptographic mechanisms to identify and reject wireless transmissions that are deliberate attempts to achieve imitative or manipulative com
    0 installs
  21. Sc 45 System Time Synchronization · cyberstrikeus
    Synchronize system clocks within and between systems and system components.
    0 installs
  22. Sc 5 Denial Of Service Protection · cyberstrikeus
    [organization-defined] the effects of the following types of denial-of-service events: [organization-defined] ;
    0 installs
  23. Sc 7 27 Unclassified Non National Security System Connection · cyberstrikeus
    Prohibit the direct connection of [organization-defined] to an external network without the use of [organization-defined].
    0 installs
  24. Sc 7 7 Split Tunneling For Remote Devices · cyberstrikeus
    Prevent split tunneling for remote devices connecting to organizational systems unless the split tunnel is securely provisioned using [organization-de
    0 installs
  25. Sc 9 Transmission Confidentiality · cyberstrikeus
    Transmission Confidentiality
    0 installs
  26. Si 12 1 Limit Personally Identifiable Information Elements · cyberstrikeus
    Limit personally identifiable information being processed in the information life cycle to the following elements of personally identifiable informati
    0 installs
  27. Si 14 1 Refresh From Trusted Sources · cyberstrikeus
    Obtain software and data employed during system component and service refreshes from the following trusted sources: [organization-defined].
    0 installs
  28. Si 4 2 Automated Tools And Mechanisms For Real Time Analysis · cyberstrikeus
    Employ automated tools and mechanisms to support near real-time analysis of events.
    0 installs
  29. Si 4 14 Wireless Intrusion Detection · cyberstrikeus
    Employ a wireless intrusion detection system to identify rogue wireless devices and to detect attack attempts and potential compromises or breaches to
    0 installs
  30. Si 4 6 Restrict Non Privileged Users · cyberstrikeus
    Restrict Non-privileged Users
    0 installs
  31. Cis Bind V100 10 1 · cyberstrikeus
    Ensure SELinux Is Enabled in Enforcing Mode (Automated)
    0 installs
  32. Cis Bind V100 10 2 · cyberstrikeus
    Ensure BIND Processes Run in the named_t Confined Context Type (Automated)
    0 installs
  33. Cis Bind V100 10 3 · cyberstrikeus
    Ensure the named_t Process Type is Not in Permissive Mode (Automated)
    0 installs
  34. Cis Bind V100 10 4 · cyberstrikeus
    Ensure Only the Necessary SELinux Booleans are Enabled (Automated)
    0 installs
  35. Cis Eks V180 4 1 10 · cyberstrikeus
    Minimize access to the proxy sub-resource of nodes (Manual)
    0 installs
  36. Cis Eks V180 4 1 11 · cyberstrikeus
    Minimize access to webhook configuration objects (Manual)
    0 installs
  37. Cis Eks V180 4 1 12 · cyberstrikeus
    Minimize access to the service account token creation (Manual)
    0 installs
  38. Cis K8S V200 1 1 10 · cyberstrikeus
    Ensure that the Container Network Interface file ownership is set to root:root (Manual)
    0 installs
  39. Cis K8S V200 1 1 11 · cyberstrikeus
    Ensure that the etcd data directory permissions are set to 700 or more restrictive (Automated)
    0 installs
  40. Cis K8S V200 1 1 12 · cyberstrikeus
    Ensure that the etcd data directory ownership is set to etcd:etcd (Automated)
    0 installs
  41. Cis K8S V200 1 1 13 · cyberstrikeus
    Ensure that the default administrative credential file permissions are set to 600 (Automated)
    0 installs
  42. Cis K8S V200 1 1 14 · cyberstrikeus
    Ensure that the default administrative credential file ownership is set to root:root (Automated)
    0 installs
  43. Cis K8S V200 1 1 15 · cyberstrikeus
    Ensure that the scheduler.conf file permissions are set to 600 or more restrictive (Automated)
    0 installs
  44. Cis K8S V200 1 1 16 · cyberstrikeus
    Ensure that the scheduler.conf file ownership is set to root:root (Automated)
    0 installs
  45. Cis K8S V200 1 1 17 · cyberstrikeus
    Ensure that the controller-manager.conf file permissions are set to 600 or more restrictive (Automated)
    0 installs
  46. Cis K8S V200 1 1 18 · cyberstrikeus
    Ensure that the controller-manager.conf file ownership is set to root:root (Automated)
    0 installs
  47. Cis K8S V200 1 1 19 · cyberstrikeus
    Ensure that the Kubernetes PKI directory and file ownership is set to root:root (Automated)
    0 installs
  48. Cis K8S V200 1 1 20 · cyberstrikeus
    Ensure that the Kubernetes PKI certificate file permissions are set to 644 or more restrictive (Manual)
    0 installs
  49. Cis K8S V200 1 1 21 · cyberstrikeus
    Ensure that the Kubernetes PKI key file permissions are set to 600 (Manual)
    0 installs
  50. Cis K8S V200 1 2 10 · cyberstrikeus
    Ensure that the admission control plugin AlwaysAdmit is not set (Automated)
    0 installs
  51. Cis K8S V200 1 2 11 · cyberstrikeus
    Ensure that the admission control plugin AlwaysPullImages is set (Manual)
    0 installs
  52. Cis K8S V200 1 2 12 · cyberstrikeus
    Ensure that the admission control plugin ServiceAccount is set (Automated)
    0 installs
  53. Cis K8S V200 1 2 13 · cyberstrikeus
    Ensure that the admission control plugin NamespaceLifecycle is set (Automated)
    0 installs
  54. Cis K8S V200 1 2 14 · cyberstrikeus
    Ensure that the admission control plugin NodeRestriction is set (Automated)
    0 installs
  55. Cis K8S V200 1 2 15 · cyberstrikeus
    Ensure that the --profiling argument is set to false (Automated)
    0 installs
  56. Cis K8S V200 1 2 16 · cyberstrikeus
    Ensure that the --audit-log-path argument is set (Automated)
    0 installs
  57. Cis K8S V200 1 2 17 · cyberstrikeus
    Ensure that the --audit-log-maxage argument is set to 30 or as appropriate (Automated)
    0 installs
  58. Cis K8S V200 1 2 18 · cyberstrikeus
    Ensure that the --audit-log-maxbackup argument is set to 10 or as appropriate (Automated)
    0 installs
  59. Cis K8S V200 1 2 19 · cyberstrikeus
    Ensure that the --audit-log-maxsize argument is set to 100 or as appropriate (Automated)
    0 installs
  60. Cis K8S V200 1 2 20 · cyberstrikeus
    Ensure that the --request-timeout argument is set as appropriate (Manual)
    0 installs
  61. Cis K8S V200 1 2 21 · cyberstrikeus
    Ensure that the --service-account-lookup argument is set to true (Automated)
    0 installs
  62. Cis K8S V200 1 2 22 · cyberstrikeus
    Ensure that the --service-account-key-file argument is set as appropriate (Automated)
    0 installs
  63. Cis K8S V200 1 2 23 · cyberstrikeus
    Ensure that the --etcd-certfile and --etcd-keyfile arguments are set as appropriate (Automated)
    0 installs
  64. Cis K8S V200 1 2 24 · cyberstrikeus
    Ensure that the --tls-cert-file and --tls-private-key-file arguments are set as appropriate (Automated)
    0 installs
  65. Cis K8S V200 1 2 25 · cyberstrikeus
    Ensure that the --client-ca-file argument is set as appropriate (Automated)
    0 installs
  66. Cis K8S V200 1 2 26 · cyberstrikeus
    Ensure that the --etcd-cafile argument is set as appropriate (Automated)
    0 installs
  67. Cis K8S V200 1 2 27 · cyberstrikeus
    Ensure that the --encryption-provider-config argument is set as appropriate (Manual)
    0 installs
  68. Cis K8S V200 1 2 28 · cyberstrikeus
    Ensure that encryption providers are appropriately configured (Manual)
    0 installs
  69. Cis K8S V200 1 2 29 · cyberstrikeus
    Ensure that the API Server only makes use of Strong Cryptographic Ciphers (Manual)
    0 installs
  70. Cis K8S V200 1 2 30 · cyberstrikeus
    Ensure that the --service-account-extend-token-expiration parameter is set to false (Automated)
    0 installs
  71. Cis K8S V200 4 1 10 · cyberstrikeus
    If the kubelet config.yaml configuration file is being used validate file ownership is set to root:root (Automated)
    0 installs
  72. Cis K8S V200 4 2 10 · cyberstrikeus
    Ensure that the --rotate-certificates argument is not set to false (Automated)
    0 installs
  73. Cis K8S V200 4 2 11 · cyberstrikeus
    Verify that the RotateKubeletServerCertificate argument is set to true (Manual)
    0 installs
  74. Cis K8S V200 4 2 12 · cyberstrikeus
    Ensure that the Kubelet only makes use of Strong Cryptographic Ciphers (Manual)
    0 installs
  75. Cis K8S V200 4 2 13 · cyberstrikeus
    Ensure that a limit is set on pod PIDs (Manual)
    0 installs
  76. Cis K8S V200 4 2 14 · cyberstrikeus
    Ensure that the --seccomp-default parameter is set to true (Manual)
    0 installs
  77. Cis K8S V200 5 1 10 · cyberstrikeus
    Minimize access to the proxy sub-resource of nodes (Manual)
    0 installs
  78. Cis K8S V200 5 1 11 · cyberstrikeus
    Minimize access to the approval sub-resource of certificatesigningrequests objects (Manual)
    0 installs
  79. Cis K8S V200 5 1 12 · cyberstrikeus
    Minimize access to webhook configuration objects (Manual)
    0 installs
  80. Cis K8S V200 5 1 13 · cyberstrikeus
    Minimize access to the service account token creation (Manual)
    0 installs
  81. Cis K8S V200 5 2 10 · cyberstrikeus
    Minimize the admission of Windows HostProcess Containers (Manual)
    0 installs
  82. Cis K8S V200 5 2 11 · cyberstrikeus
    Minimize the admission of HostPath volumes (Manual)
    0 installs
  83. Cis K8S V200 5 2 12 · cyberstrikeus
    Minimize the admission of containers which use HostPorts (Manual)
    0 installs
  84. Cis Aks V170 2 1 1 · cyberstrikeus
    Enable audit Logs (Manual)
    0 installs
  85. Cis Aks V170 3 1 1 · cyberstrikeus
    Ensure that the kubeconfig file permissions are set to 644 or more restrictive (Automated)
    0 installs
  86. Cis Aks V170 3 1 2 · cyberstrikeus
    Ensure that the kubelet kubeconfig file ownership is set to root:root (Automated)
    0 installs
  87. Cis Aks V170 3 1 3 · cyberstrikeus
    Ensure that the azure.json file has permissions set to 644 or more restrictive (Automated)
    0 installs
  88. Cis Aks V170 3 1 4 · cyberstrikeus
    Ensure that the azure.json file ownership is set to root:root (Automated)
    0 installs
  89. Cis Aks V170 3 2 1 · cyberstrikeus
    Ensure that the --anonymous-auth argument is set to false (Automated)
    0 installs
  90. Cis Aks V170 3 2 2 · cyberstrikeus
    Ensure that the --authorization-mode argument is not set to AlwaysAllow (Automated)
    0 installs
  91. Cis Aks V170 3 2 3 · cyberstrikeus
    Ensure that the --client-ca-file argument is set as appropriate (Automated)
    0 installs
  92. Cis Aks V170 3 2 4 · cyberstrikeus
    Ensure that the --read-only-port is secured (Automated)
    0 installs
  93. Cis Aks V170 3 2 5 · cyberstrikeus
    Ensure that the --streaming-connection-idle-timeout argument is not set to 0 (Automated)
    0 installs
  94. Cis Aks V170 3 2 6 · cyberstrikeus
    Ensure that the --make-iptables-util-chains argument is set to true (Automated)
    0 installs
  95. Cis Aks V170 3 2 7 · cyberstrikeus
    Ensure that the --eventRecordQPS argument is set to 0 or a level which ensures appropriate event capture (Automated)
    0 installs
  96. Cis Aks V170 3 2 8 · cyberstrikeus
    Ensure that the --rotate-certificates argument is not set to false (Automated)
    0 installs
  97. Cis Aks V170 3 2 9 · cyberstrikeus
    Ensure that the RotateKubeletServerCertificate argument is set to true (Automated)
    0 installs
  98. Cis Aks V170 4 1 1 · cyberstrikeus
    Ensure that the cluster-admin role is only used where required (Automated)
    0 installs
  99. Cis Aks V170 4 1 2 · cyberstrikeus
    Minimize access to secrets (Automated)
    0 installs
  100. Cis Aks V170 4 1 3 · cyberstrikeus
    Minimize wildcard use in Roles and ClusterRoles (Automated)
    0 installs