← all publishers

cyberstrikeus

@cyberstrikeus source repo

7171 published skills · page 32 of 72

  1. Cis Ocp V180 5 4 2 · cyberstrikeus
    Consider external secret storage (Manual)
    0 installs
  2. Cis Ocp V180 5 5 1 · cyberstrikeus
    Configure Image Provenance using image controller configuration parameters (Manual)
    0 installs
  3. Cis Ocp V180 5 7 1 · cyberstrikeus
    Create administrative boundaries between resources using namespaces (Manual)
    0 installs
  4. Cis Ocp V180 5 7 2 · cyberstrikeus
    Ensure seccomp profile set to docker/default in pod definitions (Manual)
    0 installs
  5. Cis Ocp V180 5 7 3 · cyberstrikeus
    Apply Security Context to Your Pods and Containers (Manual)
    0 installs
  6. Cis Ocp V180 5 7 4 · cyberstrikeus
    The default namespace should not be used (Manual)
    0 installs
  7. Cis Ocp Vm V100 1 10 · cyberstrikeus
    Restrict namespace administrator access to migration tools (Manual)
    0 installs
  8. Cis Ocp Vm V100 1 11 · cyberstrikeus
    Restrict exec access to the pods (Manual)
    0 installs
  9. Cis Ocp Vm V100 1 12 · cyberstrikeus
    Restrict VNC access to cluster workloads (Manual)
    0 installs
  10. Cis Ocp Vm V100 1 13 · cyberstrikeus
    Restrict access to create and modify the Virtual Machine Cluster Instance and Preference Types (Manual)
    0 installs
  11. Cis Ocp Vm V100 1 14 · cyberstrikeus
    Restrict update access to the CDI CR (Manual)
    0 installs
  12. Plan Of Action And Milestones 03 12 02 Plan Of Action And Mi · cyberstrikeus
    Develop a plan of action and milestones for the system: To document the planned remediation actions to correct weaknesses or deficiencies noted during
    0 installs
  13. Pe 19 1 National Emissions Policies And Procedures · cyberstrikeus
    Protect system components, associated data communications, and networks in accordance with national Emissions Security policies and procedures based o
    0 installs
  14. Sc 11 1 Irrefutable Communications Path · cyberstrikeus
    Provide a trusted communications path that is irrefutably distinguishable from other communications paths;
    0 installs
  15. Sc 12 5 Pki Certificates Hardware Tokens · cyberstrikeus
    PKI Certificates / Hardware Tokens
    0 installs
  16. Sc 18 2 Acquisition Development And Use · cyberstrikeus
    Verify that the acquisition, development, and use of mobile code to be deployed in the system meets [organization-defined].
    0 installs
  17. Sc 23 5 Allowed Certificate Authorities · cyberstrikeus
    Only allow the use of [organization-defined] for verification of the establishment of protected sessions.
    0 installs
  18. Sc 3 2 Access And Flow Control Functions · cyberstrikeus
    Isolate security functions enforcing access and information flow control from nonsecurity functions and from other security functions.
    0 installs
  19. Sc 3 4 Module Coupling And Cohesiveness · cyberstrikeus
    Implement security functions as largely independent modules that maximize internal cohesiveness within modules and minimize coupling between modules.
    0 installs
  20. Sc 30 5 Concealment Of System Components · cyberstrikeus
    Employ the following techniques to hide or conceal [organization-defined]: [organization-defined].
    0 installs
  21. Sc 33 Transmission Preparation Integrity · cyberstrikeus
    Transmission Preparation Integrity
    0 installs
  22. Sc 34 Non Modifiable Executable Programs · cyberstrikeus
    For [organization-defined] , load and execute: The operating environment from hardware-enforced, read-only media; and The following applications from
    0 installs
  23. Sc 36 Distributed Processing And Storage · cyberstrikeus
    Distribute the following processing and storage components across multiple [organization-defined]: [organization-defined].
    0 installs
  24. Sc 37 1 Ensure Delivery And Transmission · cyberstrikeus
    Employ [organization-defined] to ensure that only [organization-defined] receive the following information, system components, or devices: [organizati
    0 installs
  25. Sc 4 2 Multilevel Or Periods Processing · cyberstrikeus
    Prevent unauthorized information transfer via shared resources in accordance with [organization-defined] when system processing explicitly switches be
    0 installs
  26. Sc 40 4 Signal Parameter Identification · cyberstrikeus
    Implement cryptographic mechanisms to prevent the identification of [organization-defined] by using the transmitter signal parameters.
    0 installs
  27. Sc 5 2 Capacity Bandwidth And Redundancy · cyberstrikeus
    Manage capacity, bandwidth, or other redundancy to limit the effects of information flooding denial-of-service attacks.
    0 installs
  28. Sc 7 1 Physically Separated Subnetworks · cyberstrikeus
    Physically Separated Subnetworks
    0 installs
  29. Cis Aks V180 4 1 1 · cyberstrikeus
    Ensure that the cluster-admin role is only used where required (Manual)
    0 installs
  30. Cis Aks V180 4 1 2 · cyberstrikeus
    Minimize access to secrets (Manual)
    0 installs
  31. Cis Aks V180 4 1 3 · cyberstrikeus
    Minimize wildcard use in Roles and ClusterRoles (Manual)
    0 installs
  32. Cis Aks V180 4 1 4 · cyberstrikeus
    Minimize access to create pods (Manual)
    0 installs
  33. Cis Aks V180 4 1 5 · cyberstrikeus
    Ensure that default service accounts are not actively used (Manual)
    0 installs
  34. Cis Aks V180 4 1 6 · cyberstrikeus
    Ensure Service Account Tokens are only mounted where necessary (Manual)
    0 installs
  35. Cis Aks V180 4 1 7 · cyberstrikeus
    Limit use of Bind, Impersonate and Escalate permissions (Manual)
    0 installs
  36. Cis Aks V180 4 1 8 · cyberstrikeus
    Minimize access to create persistent volumes (Manual)
    0 installs
  37. Cis Aks V180 4 1 9 · cyberstrikeus
    Minimize access to the proxy sub-resource of nodes (Manual)
    0 installs
  38. Cis Aks V180 4 2 1 · cyberstrikeus
    Minimize the admission of privileged containers (Manual)
    0 installs
  39. Cis Aks V180 4 2 2 · cyberstrikeus
    Minimize the admission of containers wishing to share the host process ID namespace (Manual)
    0 installs
  40. Cis Aks V180 4 2 3 · cyberstrikeus
    Minimize the admission of containers wishing to share the host IPC namespace (Manual)
    0 installs
  41. Cis Aks V180 4 2 4 · cyberstrikeus
    Minimize the admission of containers wishing to share the host network namespace (Manual)
    0 installs
  42. Cis Aks V180 4 2 5 · cyberstrikeus
    Minimize the admission of containers with allowPrivilegeEscalation (Manual)
    0 installs
  43. Cis Ocp V170 1 1 10 · cyberstrikeus
    Ensure that the Container Network Interface file ownership is set to root:root (Manual)
    0 installs
  44. Cis Ocp V170 1 1 11 · cyberstrikeus
    Ensure that the etcd data directory permissions are set to 700 or more restrictive (Manual)
    0 installs
  45. Cis Ocp V170 1 1 12 · cyberstrikeus
    Ensure that the etcd data directory ownership is set to etcd:etcd (Manual)
    0 installs
  46. Cis Ocp V170 1 1 13 · cyberstrikeus
    Ensure that the kubeconfig file permissions are set to 600 or more restrictive (Manual)
    0 installs
  47. Cis Ocp V170 1 1 14 · cyberstrikeus
    Ensure that the kubeconfig file ownership is set to root:root (Manual)
    0 installs
  48. Cis Ocp V170 1 1 15 · cyberstrikeus
    Ensure that the Scheduler kubeconfig file permissions are set to 600 or more restrictive (Manual)
    0 installs
  49. Cis Ocp V170 1 1 16 · cyberstrikeus
    Ensure that the Scheduler kubeconfig file ownership is set to root:root (Manual)
    0 installs
  50. Cis Ocp V170 1 1 17 · cyberstrikeus
    Ensure that the Controller Manager kubeconfig file permissions are set to 600 or more restrictive (Manual)
    0 installs
  51. Cis Ocp V170 1 1 18 · cyberstrikeus
    Ensure that the Controller Manager kubeconfig file ownership is set to root:root (Manual)
    0 installs
  52. Cis Ocp V170 1 1 19 · cyberstrikeus
    Ensure that the OpenShift PKI directory and file ownership is set to root:root (Manual)
    0 installs
  53. Cis Ocp V170 1 1 20 · cyberstrikeus
    Ensure that the OpenShift PKI certificate file permissions are set to 600 or more restrictive (Manual)
    0 installs
  54. Cis Ocp V170 1 1 21 · cyberstrikeus
    Ensure that the OpenShift PKI key file permissions are set to 600 or more restrictive (Manual)
    0 installs
  55. Cis Ocp V170 1 2 10 · cyberstrikeus
    Ensure that the admission control plugin AlwaysAdmit is not set (Manual)
    0 installs
  56. Cis Ocp V170 1 2 11 · cyberstrikeus
    Ensure that the admission control plugin AlwaysPullImages is not set (Manual)
    0 installs
  57. Cis Ocp V170 1 2 12 · cyberstrikeus
    Ensure that the admission control plugin ServiceAccount is set (Manual)
    0 installs
  58. Cis Ocp V170 1 2 13 · cyberstrikeus
    Ensure that the admission control plugin NamespaceLifecycle is set (Manual)
    0 installs
  59. Cis Ocp V170 1 2 14 · cyberstrikeus
    Ensure that the admission control plugin SecurityContextConstraint is set (Manual)
    0 installs
  60. Cis Ocp V170 1 2 15 · cyberstrikeus
    Ensure that the admission control plugin NodeRestriction is set (Manual)
    0 installs
  61. Cis Ocp V170 1 2 16 · cyberstrikeus
    Ensure that the --insecure-bind-address argument is not set (Manual)
    0 installs
  62. Cis Ocp V170 1 2 17 · cyberstrikeus
    Ensure that the --insecure-port argument is set to 0 (Manual)
    0 installs
  63. Cis Ocp V170 1 2 18 · cyberstrikeus
    Ensure that the --secure-port argument is not set to 0 (Manual)
    0 installs
  64. Cis Ocp V170 1 2 19 · cyberstrikeus
    Ensure that the healthz endpoint is protected by RBAC (Manual)
    0 installs
  65. Cis Ocp V170 1 2 20 · cyberstrikeus
    Ensure that the --audit-log-path argument is set (Manual)
    0 installs
  66. Cis Ocp V170 1 2 21 · cyberstrikeus
    Ensure that the audit logs are forwarded off the cluster for retention (Manual)
    0 installs
  67. Cis Ocp V170 1 2 22 · cyberstrikeus
    Ensure that the maximumRetainedFiles argument is set to 10 or as appropriate (Manual)
    0 installs
  68. Cis Ocp V170 1 2 23 · cyberstrikeus
    Ensure that the maximumFileSizeMegabytes argument is set to 100 (Manual)
    0 installs
  69. Cis Ocp V170 1 2 24 · cyberstrikeus
    Ensure that the --request-timeout argument is set as appropriate (Manual)
    0 installs
  70. Cis Ocp V170 1 2 25 · cyberstrikeus
    Ensure that the --service-account-lookup argument is set to true (Manual)
    0 installs
  71. Cis Ocp V170 1 2 26 · cyberstrikeus
    Ensure that the --service-account-key-file argument is set as appropriate (Manual)
    0 installs
  72. Cis Ocp V170 1 2 27 · cyberstrikeus
    Ensure that the --etcd-certfile and --etcd-keyfile arguments are set as appropriate (Manual)
    0 installs
  73. Cis Ocp V170 1 2 28 · cyberstrikeus
    Ensure that the --tls-cert-file and --tls-private-key-file arguments are set as appropriate (Manual)
    0 installs
  74. Cis Ocp V170 1 2 29 · cyberstrikeus
    Ensure that the --client-ca-file argument is set as appropriate (Manual)
    0 installs
  75. Cis Ocp V170 1 2 30 · cyberstrikeus
    Ensure that the --etcd-cafile argument is set as appropriate (Manual)
    0 installs
  76. Cis Ocp V170 1 2 31 · cyberstrikeus
    Ensure that encryption providers are appropriately configured (Manual)
    0 installs
  77. Cis Ocp V170 1 2 32 · cyberstrikeus
    Ensure that the API Server only makes use of Strong Cryptographic Ciphers (Manual)
    0 installs
  78. Cis Ocp V170 1 2 33 · cyberstrikeus
    Ensure that unsupported configuration overrides are not used (Manual)
    0 installs
  79. Cis Ocp V170 4 1 10 · cyberstrikeus
    Ensure that the kubelet configuration file ownership is set to root:root (Automated)
    0 installs
  80. Cis Ocp V170 4 2 10 · cyberstrikeus
    Ensure that the --rotate-certificates argument is not set to false (Manual)
    0 installs
  81. Cis Ocp V170 4 2 11 · cyberstrikeus
    Verify that the RotateKubeletServerCertificate argument is set to true (Manual)
    0 installs
  82. Cis Ocp V170 4 2 12 · cyberstrikeus
    Ensure that the Kubelet only makes use of Strong Cryptographic Ciphers (Manual)
    0 installs
  83. Cis Ocp V170 5 2 10 · cyberstrikeus
    Minimize access to privileged Security Context Constraints (Manual)
    0 installs
  84. Cis Ocp V190 1 1 10 · cyberstrikeus
    Ensure that the Container Network Interface file ownership is set to root:root (Manual)
    0 installs
  85. Cis Ocp V190 1 1 11 · cyberstrikeus
    Ensure that the etcd data directory permissions are set to 700 or more restrictive (Manual)
    0 installs
  86. Cis Ocp V190 1 1 12 · cyberstrikeus
    Ensure that the etcd data directory ownership is set to root:root (Manual)
    0 installs
  87. Cis Ocp V190 1 1 13 · cyberstrikeus
    Ensure that the kubeconfig file permissions are set to 600 or more restrictive (Manual)
    0 installs
  88. Cis Ocp V190 1 1 14 · cyberstrikeus
    Ensure that the kubeconfig file ownership is set to root:root (Manual)
    0 installs
  89. Cis Ocp V190 1 1 15 · cyberstrikeus
    Ensure that the Scheduler kubeconfig file permissions are set to 600 or more restrictive (Manual)
    0 installs
  90. Cis Ocp V190 1 1 16 · cyberstrikeus
    Ensure that the Scheduler kubeconfig file ownership is set to root:root (Manual)
    0 installs
  91. Cis Ocp V190 1 1 17 · cyberstrikeus
    Ensure that the Controller Manager kubeconfig file permissions are set to 600 or more restrictive (Manual)
    2 installs
  92. Cis Ocp V190 1 1 18 · cyberstrikeus
    Ensure that the Controller Manager kubeconfig file ownership is set to root:root (Manual)
    0 installs
  93. Cis Ocp V190 1 1 19 · cyberstrikeus
    Ensure that the OpenShift PKI directory and file ownership is set to root:root (Manual)
    0 installs
  94. Cis Ocp V190 1 1 20 · cyberstrikeus
    Ensure that the OpenShift PKI certificate file permissions are set to 600 or more restrictive (Manual)
    0 installs
  95. Cis Ocp V190 1 1 21 · cyberstrikeus
    Ensure that the OpenShift PKI key file permissions are set to 600 (Manual)
    0 installs
  96. Cis Ocp V190 1 2 10 · cyberstrikeus
    Ensure that the admission control plugin ServiceAccount is set (Manual)
    0 installs
  97. Cis Ocp V190 1 2 11 · cyberstrikeus
    Ensure that the admission control plugin NamespaceLifecycle is set (Manual)
    0 installs
  98. Cis Ocp V190 1 2 12 · cyberstrikeus
    Ensure that the admission control plugin SecurityContextConstraint is set (Manual)
    0 installs
  99. Cis Ocp V190 1 2 13 · cyberstrikeus
    Ensure that the admission control plugin NodeRestriction is set (Manual)
    0 installs
  100. Cis Ocp V190 1 2 14 · cyberstrikeus
    Ensure that the --insecure-bind-address argument is not set (Manual)
    2 installs