cyberstrikeus
- 7.2k skills
- 0 followers
- 2 days ago last updated
- ▌ Cis Ocp V160 5 7 2 · cyberstrikeusEnsure that the seccomp profile is set to docker/default in your pod definitions (Manual)
- ▌
- ▌
- ▌
- ▌ System Monitoring 03 14 06 System Monitoring · cyberstrikeusMonitor the system to detect: Attacks and indicators of potential attacks and Unauthorized connections. Identify unauthorized use of the system. Monit
- ▌ Ia 12 3 Identity Evidence Validation And Verification · cyberstrikeusRequire that the presented identity evidence be validated and verified through [organization-defined].
- ▌ Ia 5 3 In Person Or Trusted External Party Registration · cyberstrikeusIn-person or Trusted External Party Registration
- ▌ Ia 5 6 Protection Of Authenticators · cyberstrikeusProtect authenticators commensurate with the security category of the information to which use of the authenticator permits access.
- ▌ Ia 8 1 Acceptance Of Piv Credentials From Other Agencies · cyberstrikeusAccept and electronically verify Personal Identity Verification-compliant credentials from other federal agencies.
- ▌ Pe 9 Power Equipment And Cabling · cyberstrikeusProtect power equipment and power cabling for the system from damage and destruction.
- ▌ Sa 11 Developer Testing And Evaluation · cyberstrikeusRequire the developer of the system, system component, or system service, at all post-design stages of the system development life cycle, to: Develop
- ▌ Sa 12 7 Assessments Prior To Selection Acceptance Update · cyberstrikeusAssessments Prior to Selection / Acceptance / Update
- ▌ Sa 17 7 Structure For Least Privilege · cyberstrikeusRequire the developer of the system, system component, or system service to structure security-relevant hardware, software, and firmware to facilitate
- ▌ Sa 8 4 Partially Ordered Dependencies · cyberstrikeusImplement the security design principle of partially ordered dependencies in [organization-defined].
- ▌ Sa 9 8 Processing And Storage Location Us Jurisdiction · cyberstrikeusRestrict the geographic location of information processing and data storage to facilities located within in the legal jurisdictional boundary of the U
- ▌ Sc 12 6 Physical Control Of Keys · cyberstrikeusMaintain physical control of cryptographic keys when stored information is encrypted by external service providers.
- ▌ Sc 16 2 Anti Spoofing Mechanisms · cyberstrikeusImplement anti-spoofing mechanisms to prevent adversaries from falsifying the security attributes indicating the successful application of the securit
- ▌ Sc 28 1 Cryptographic Protection · cyberstrikeusImplement cryptographic mechanisms to prevent unauthorized disclosure and modification of the following information at rest on [organization-defined]:
- ▌ Sc 4 Information In Shared System Resources · cyberstrikeusPrevent unauthorized and unintended information transfer via shared system resources.
- ▌ Sc 40 3 Imitative Or Manipulative Communications Deception · cyberstrikeusImplement cryptographic mechanisms to identify and reject wireless transmissions that are deliberate attempts to achieve imitative or manipulative com
- ▌ Sc 45 System Time Synchronization · cyberstrikeusSynchronize system clocks within and between systems and system components.
- ▌ Sc 5 Denial Of Service Protection · cyberstrikeus[organization-defined] the effects of the following types of denial-of-service events: [organization-defined] ;
- ▌ Sc 7 27 Unclassified Non National Security System Connection · cyberstrikeusProhibit the direct connection of [organization-defined] to an external network without the use of [organization-defined].
- ▌ Sc 7 7 Split Tunneling For Remote Devices · cyberstrikeusPrevent split tunneling for remote devices connecting to organizational systems unless the split tunnel is securely provisioned using [organization-de
- ▌
- ▌ Si 12 1 Limit Personally Identifiable Information Elements · cyberstrikeusLimit personally identifiable information being processed in the information life cycle to the following elements of personally identifiable informati
- ▌ Si 14 1 Refresh From Trusted Sources · cyberstrikeusObtain software and data employed during system component and service refreshes from the following trusted sources: [organization-defined].
- ▌ Si 4 2 Automated Tools And Mechanisms For Real Time Analysis · cyberstrikeusEmploy automated tools and mechanisms to support near real-time analysis of events.
- ▌ Si 4 14 Wireless Intrusion Detection · cyberstrikeusEmploy a wireless intrusion detection system to identify rogue wireless devices and to detect attack attempts and potential compromises or breaches to
- ▌
- ▌
- ▌ Cis Bind V100 10 2 · cyberstrikeusEnsure BIND Processes Run in the named_t Confined Context Type (Automated)
- ▌ Cis Bind V100 10 3 · cyberstrikeusEnsure the named_t Process Type is Not in Permissive Mode (Automated)
- ▌ Cis Bind V100 10 4 · cyberstrikeusEnsure Only the Necessary SELinux Booleans are Enabled (Automated)
- ▌
- ▌
- ▌
- ▌ Cis K8S V200 1 1 10 · cyberstrikeusEnsure that the Container Network Interface file ownership is set to root:root (Manual)
- ▌ Cis K8S V200 1 1 11 · cyberstrikeusEnsure that the etcd data directory permissions are set to 700 or more restrictive (Automated)
- ▌ Cis K8S V200 1 1 12 · cyberstrikeusEnsure that the etcd data directory ownership is set to etcd:etcd (Automated)
- ▌ Cis K8S V200 1 1 13 · cyberstrikeusEnsure that the default administrative credential file permissions are set to 600 (Automated)
- ▌ Cis K8S V200 1 1 14 · cyberstrikeusEnsure that the default administrative credential file ownership is set to root:root (Automated)
- ▌ Cis K8S V200 1 1 15 · cyberstrikeusEnsure that the scheduler.conf file permissions are set to 600 or more restrictive (Automated)
- ▌ Cis K8S V200 1 1 16 · cyberstrikeusEnsure that the scheduler.conf file ownership is set to root:root (Automated)
- ▌ Cis K8S V200 1 1 17 · cyberstrikeusEnsure that the controller-manager.conf file permissions are set to 600 or more restrictive (Automated)
- ▌ Cis K8S V200 1 1 18 · cyberstrikeusEnsure that the controller-manager.conf file ownership is set to root:root (Automated)
- ▌ Cis K8S V200 1 1 19 · cyberstrikeusEnsure that the Kubernetes PKI directory and file ownership is set to root:root (Automated)
- ▌ Cis K8S V200 1 1 20 · cyberstrikeusEnsure that the Kubernetes PKI certificate file permissions are set to 644 or more restrictive (Manual)
- ▌ Cis K8S V200 1 1 21 · cyberstrikeusEnsure that the Kubernetes PKI key file permissions are set to 600 (Manual)
- ▌ Cis K8S V200 1 2 10 · cyberstrikeusEnsure that the admission control plugin AlwaysAdmit is not set (Automated)
- ▌ Cis K8S V200 1 2 11 · cyberstrikeusEnsure that the admission control plugin AlwaysPullImages is set (Manual)
- ▌ Cis K8S V200 1 2 12 · cyberstrikeusEnsure that the admission control plugin ServiceAccount is set (Automated)
- ▌ Cis K8S V200 1 2 13 · cyberstrikeusEnsure that the admission control plugin NamespaceLifecycle is set (Automated)
- ▌ Cis K8S V200 1 2 14 · cyberstrikeusEnsure that the admission control plugin NodeRestriction is set (Automated)
- ▌ Cis K8S V200 1 2 15 · cyberstrikeusEnsure that the --profiling argument is set to false (Automated)
- ▌
- ▌ Cis K8S V200 1 2 17 · cyberstrikeusEnsure that the --audit-log-maxage argument is set to 30 or as appropriate (Automated)
- ▌ Cis K8S V200 1 2 18 · cyberstrikeusEnsure that the --audit-log-maxbackup argument is set to 10 or as appropriate (Automated)
- ▌ Cis K8S V200 1 2 19 · cyberstrikeusEnsure that the --audit-log-maxsize argument is set to 100 or as appropriate (Automated)
- ▌ Cis K8S V200 1 2 20 · cyberstrikeusEnsure that the --request-timeout argument is set as appropriate (Manual)
- ▌ Cis K8S V200 1 2 21 · cyberstrikeusEnsure that the --service-account-lookup argument is set to true (Automated)
- ▌ Cis K8S V200 1 2 22 · cyberstrikeusEnsure that the --service-account-key-file argument is set as appropriate (Automated)
- ▌ Cis K8S V200 1 2 23 · cyberstrikeusEnsure that the --etcd-certfile and --etcd-keyfile arguments are set as appropriate (Automated)
- ▌ Cis K8S V200 1 2 24 · cyberstrikeusEnsure that the --tls-cert-file and --tls-private-key-file arguments are set as appropriate (Automated)
- ▌ Cis K8S V200 1 2 25 · cyberstrikeusEnsure that the --client-ca-file argument is set as appropriate (Automated)
- ▌ Cis K8S V200 1 2 26 · cyberstrikeusEnsure that the --etcd-cafile argument is set as appropriate (Automated)
- ▌ Cis K8S V200 1 2 27 · cyberstrikeusEnsure that the --encryption-provider-config argument is set as appropriate (Manual)
- ▌ Cis K8S V200 1 2 28 · cyberstrikeusEnsure that encryption providers are appropriately configured (Manual)
- ▌ Cis K8S V200 1 2 29 · cyberstrikeusEnsure that the API Server only makes use of Strong Cryptographic Ciphers (Manual)
- ▌ Cis K8S V200 1 2 30 · cyberstrikeusEnsure that the --service-account-extend-token-expiration parameter is set to false (Automated)
- ▌ Cis K8S V200 4 1 10 · cyberstrikeusIf the kubelet config.yaml configuration file is being used validate file ownership is set to root:root (Automated)
- ▌ Cis K8S V200 4 2 10 · cyberstrikeusEnsure that the --rotate-certificates argument is not set to false (Automated)
- ▌ Cis K8S V200 4 2 11 · cyberstrikeusVerify that the RotateKubeletServerCertificate argument is set to true (Manual)
- ▌ Cis K8S V200 4 2 12 · cyberstrikeusEnsure that the Kubelet only makes use of Strong Cryptographic Ciphers (Manual)
- ▌
- ▌ Cis K8S V200 4 2 14 · cyberstrikeusEnsure that the --seccomp-default parameter is set to true (Manual)
- ▌
- ▌ Cis K8S V200 5 1 11 · cyberstrikeusMinimize access to the approval sub-resource of certificatesigningrequests objects (Manual)
- ▌
- ▌
- ▌ Cis K8S V200 5 2 10 · cyberstrikeusMinimize the admission of Windows HostProcess Containers (Manual)
- ▌
- ▌ Cis K8S V200 5 2 12 · cyberstrikeusMinimize the admission of containers which use HostPorts (Manual)
- ▌
- ▌ Cis Aks V170 3 1 1 · cyberstrikeusEnsure that the kubeconfig file permissions are set to 644 or more restrictive (Automated)
- ▌ Cis Aks V170 3 1 2 · cyberstrikeusEnsure that the kubelet kubeconfig file ownership is set to root:root (Automated)
- ▌ Cis Aks V170 3 1 3 · cyberstrikeusEnsure that the azure.json file has permissions set to 644 or more restrictive (Automated)
- ▌ Cis Aks V170 3 1 4 · cyberstrikeusEnsure that the azure.json file ownership is set to root:root (Automated)
- ▌ Cis Aks V170 3 2 1 · cyberstrikeusEnsure that the --anonymous-auth argument is set to false (Automated)
- ▌ Cis Aks V170 3 2 2 · cyberstrikeusEnsure that the --authorization-mode argument is not set to AlwaysAllow (Automated)
- ▌ Cis Aks V170 3 2 3 · cyberstrikeusEnsure that the --client-ca-file argument is set as appropriate (Automated)
- ▌
- ▌ Cis Aks V170 3 2 5 · cyberstrikeusEnsure that the --streaming-connection-idle-timeout argument is not set to 0 (Automated)
- ▌ Cis Aks V170 3 2 6 · cyberstrikeusEnsure that the --make-iptables-util-chains argument is set to true (Automated)
- ▌ Cis Aks V170 3 2 7 · cyberstrikeusEnsure that the --eventRecordQPS argument is set to 0 or a level which ensures appropriate event capture (Automated)
- ▌ Cis Aks V170 3 2 8 · cyberstrikeusEnsure that the --rotate-certificates argument is not set to false (Automated)
- ▌ Cis Aks V170 3 2 9 · cyberstrikeusEnsure that the RotateKubeletServerCertificate argument is set to true (Automated)
- ▌ Cis Aks V170 4 1 1 · cyberstrikeusEnsure that the cluster-admin role is only used where required (Automated)
- ▌
- ▌