cyberstrikeus
- 7.2k skills
- 0 followers
- 2 days ago last updated
- ▌
- ▌ Cis Ocp V180 5 5 1 · cyberstrikeusConfigure Image Provenance using image controller configuration parameters (Manual)
- ▌ Cis Ocp V180 5 7 1 · cyberstrikeusCreate administrative boundaries between resources using namespaces (Manual)
- ▌ Cis Ocp V180 5 7 2 · cyberstrikeusEnsure seccomp profile set to docker/default in pod definitions (Manual)
- ▌
- ▌
- ▌ Cis Ocp Vm V100 1 10 · cyberstrikeusRestrict namespace administrator access to migration tools (Manual)
- ▌
- ▌
- ▌ Cis Ocp Vm V100 1 13 · cyberstrikeusRestrict access to create and modify the Virtual Machine Cluster Instance and Preference Types (Manual)
- ▌
- ▌ Plan Of Action And Milestones 03 12 02 Plan Of Action And Mi · cyberstrikeusDevelop a plan of action and milestones for the system: To document the planned remediation actions to correct weaknesses or deficiencies noted during
- ▌ Pe 19 1 National Emissions Policies And Procedures · cyberstrikeusProtect system components, associated data communications, and networks in accordance with national Emissions Security policies and procedures based o
- ▌ Sc 11 1 Irrefutable Communications Path · cyberstrikeusProvide a trusted communications path that is irrefutably distinguishable from other communications paths;
- ▌
- ▌ Sc 18 2 Acquisition Development And Use · cyberstrikeusVerify that the acquisition, development, and use of mobile code to be deployed in the system meets [organization-defined].
- ▌ Sc 23 5 Allowed Certificate Authorities · cyberstrikeusOnly allow the use of [organization-defined] for verification of the establishment of protected sessions.
- ▌ Sc 3 2 Access And Flow Control Functions · cyberstrikeusIsolate security functions enforcing access and information flow control from nonsecurity functions and from other security functions.
- ▌ Sc 3 4 Module Coupling And Cohesiveness · cyberstrikeusImplement security functions as largely independent modules that maximize internal cohesiveness within modules and minimize coupling between modules.
- ▌ Sc 30 5 Concealment Of System Components · cyberstrikeusEmploy the following techniques to hide or conceal [organization-defined]: [organization-defined].
- ▌
- ▌ Sc 34 Non Modifiable Executable Programs · cyberstrikeusFor [organization-defined] , load and execute: The operating environment from hardware-enforced, read-only media; and The following applications from
- ▌ Sc 36 Distributed Processing And Storage · cyberstrikeusDistribute the following processing and storage components across multiple [organization-defined]: [organization-defined].
- ▌ Sc 37 1 Ensure Delivery And Transmission · cyberstrikeusEmploy [organization-defined] to ensure that only [organization-defined] receive the following information, system components, or devices: [organizati
- ▌ Sc 4 2 Multilevel Or Periods Processing · cyberstrikeusPrevent unauthorized information transfer via shared resources in accordance with [organization-defined] when system processing explicitly switches be
- ▌ Sc 40 4 Signal Parameter Identification · cyberstrikeusImplement cryptographic mechanisms to prevent the identification of [organization-defined] by using the transmitter signal parameters.
- ▌ Sc 5 2 Capacity Bandwidth And Redundancy · cyberstrikeusManage capacity, bandwidth, or other redundancy to limit the effects of information flooding denial-of-service attacks.
- ▌
- ▌ Cis Aks V180 4 1 1 · cyberstrikeusEnsure that the cluster-admin role is only used where required (Manual)
- ▌
- ▌
- ▌
- ▌ Cis Aks V180 4 1 5 · cyberstrikeusEnsure that default service accounts are not actively used (Manual)
- ▌ Cis Aks V180 4 1 6 · cyberstrikeusEnsure Service Account Tokens are only mounted where necessary (Manual)
- ▌
- ▌
- ▌
- ▌
- ▌ Cis Aks V180 4 2 2 · cyberstrikeusMinimize the admission of containers wishing to share the host process ID namespace (Manual)
- ▌ Cis Aks V180 4 2 3 · cyberstrikeusMinimize the admission of containers wishing to share the host IPC namespace (Manual)
- ▌ Cis Aks V180 4 2 4 · cyberstrikeusMinimize the admission of containers wishing to share the host network namespace (Manual)
- ▌ Cis Aks V180 4 2 5 · cyberstrikeusMinimize the admission of containers with allowPrivilegeEscalation (Manual)
- ▌ Cis Ocp V170 1 1 10 · cyberstrikeusEnsure that the Container Network Interface file ownership is set to root:root (Manual)
- ▌ Cis Ocp V170 1 1 11 · cyberstrikeusEnsure that the etcd data directory permissions are set to 700 or more restrictive (Manual)
- ▌ Cis Ocp V170 1 1 12 · cyberstrikeusEnsure that the etcd data directory ownership is set to etcd:etcd (Manual)
- ▌ Cis Ocp V170 1 1 13 · cyberstrikeusEnsure that the kubeconfig file permissions are set to 600 or more restrictive (Manual)
- ▌ Cis Ocp V170 1 1 14 · cyberstrikeusEnsure that the kubeconfig file ownership is set to root:root (Manual)
- ▌ Cis Ocp V170 1 1 15 · cyberstrikeusEnsure that the Scheduler kubeconfig file permissions are set to 600 or more restrictive (Manual)
- ▌ Cis Ocp V170 1 1 16 · cyberstrikeusEnsure that the Scheduler kubeconfig file ownership is set to root:root (Manual)
- ▌ Cis Ocp V170 1 1 17 · cyberstrikeusEnsure that the Controller Manager kubeconfig file permissions are set to 600 or more restrictive (Manual)
- ▌ Cis Ocp V170 1 1 18 · cyberstrikeusEnsure that the Controller Manager kubeconfig file ownership is set to root:root (Manual)
- ▌ Cis Ocp V170 1 1 19 · cyberstrikeusEnsure that the OpenShift PKI directory and file ownership is set to root:root (Manual)
- ▌ Cis Ocp V170 1 1 20 · cyberstrikeusEnsure that the OpenShift PKI certificate file permissions are set to 600 or more restrictive (Manual)
- ▌ Cis Ocp V170 1 1 21 · cyberstrikeusEnsure that the OpenShift PKI key file permissions are set to 600 or more restrictive (Manual)
- ▌ Cis Ocp V170 1 2 10 · cyberstrikeusEnsure that the admission control plugin AlwaysAdmit is not set (Manual)
- ▌ Cis Ocp V170 1 2 11 · cyberstrikeusEnsure that the admission control plugin AlwaysPullImages is not set (Manual)
- ▌ Cis Ocp V170 1 2 12 · cyberstrikeusEnsure that the admission control plugin ServiceAccount is set (Manual)
- ▌ Cis Ocp V170 1 2 13 · cyberstrikeusEnsure that the admission control plugin NamespaceLifecycle is set (Manual)
- ▌ Cis Ocp V170 1 2 14 · cyberstrikeusEnsure that the admission control plugin SecurityContextConstraint is set (Manual)
- ▌ Cis Ocp V170 1 2 15 · cyberstrikeusEnsure that the admission control plugin NodeRestriction is set (Manual)
- ▌ Cis Ocp V170 1 2 16 · cyberstrikeusEnsure that the --insecure-bind-address argument is not set (Manual)
- ▌
- ▌
- ▌
- ▌
- ▌ Cis Ocp V170 1 2 21 · cyberstrikeusEnsure that the audit logs are forwarded off the cluster for retention (Manual)
- ▌ Cis Ocp V170 1 2 22 · cyberstrikeusEnsure that the maximumRetainedFiles argument is set to 10 or as appropriate (Manual)
- ▌ Cis Ocp V170 1 2 23 · cyberstrikeusEnsure that the maximumFileSizeMegabytes argument is set to 100 (Manual)
- ▌ Cis Ocp V170 1 2 24 · cyberstrikeusEnsure that the --request-timeout argument is set as appropriate (Manual)
- ▌ Cis Ocp V170 1 2 25 · cyberstrikeusEnsure that the --service-account-lookup argument is set to true (Manual)
- ▌ Cis Ocp V170 1 2 26 · cyberstrikeusEnsure that the --service-account-key-file argument is set as appropriate (Manual)
- ▌ Cis Ocp V170 1 2 27 · cyberstrikeusEnsure that the --etcd-certfile and --etcd-keyfile arguments are set as appropriate (Manual)
- ▌ Cis Ocp V170 1 2 28 · cyberstrikeusEnsure that the --tls-cert-file and --tls-private-key-file arguments are set as appropriate (Manual)
- ▌ Cis Ocp V170 1 2 29 · cyberstrikeusEnsure that the --client-ca-file argument is set as appropriate (Manual)
- ▌ Cis Ocp V170 1 2 30 · cyberstrikeusEnsure that the --etcd-cafile argument is set as appropriate (Manual)
- ▌ Cis Ocp V170 1 2 31 · cyberstrikeusEnsure that encryption providers are appropriately configured (Manual)
- ▌ Cis Ocp V170 1 2 32 · cyberstrikeusEnsure that the API Server only makes use of Strong Cryptographic Ciphers (Manual)
- ▌ Cis Ocp V170 1 2 33 · cyberstrikeusEnsure that unsupported configuration overrides are not used (Manual)
- ▌ Cis Ocp V170 4 1 10 · cyberstrikeusEnsure that the kubelet configuration file ownership is set to root:root (Automated)
- ▌ Cis Ocp V170 4 2 10 · cyberstrikeusEnsure that the --rotate-certificates argument is not set to false (Manual)
- ▌ Cis Ocp V170 4 2 11 · cyberstrikeusVerify that the RotateKubeletServerCertificate argument is set to true (Manual)
- ▌ Cis Ocp V170 4 2 12 · cyberstrikeusEnsure that the Kubelet only makes use of Strong Cryptographic Ciphers (Manual)
- ▌ Cis Ocp V170 5 2 10 · cyberstrikeusMinimize access to privileged Security Context Constraints (Manual)
- ▌ Cis Ocp V190 1 1 10 · cyberstrikeusEnsure that the Container Network Interface file ownership is set to root:root (Manual)
- ▌ Cis Ocp V190 1 1 11 · cyberstrikeusEnsure that the etcd data directory permissions are set to 700 or more restrictive (Manual)
- ▌ Cis Ocp V190 1 1 12 · cyberstrikeusEnsure that the etcd data directory ownership is set to root:root (Manual)
- ▌ Cis Ocp V190 1 1 13 · cyberstrikeusEnsure that the kubeconfig file permissions are set to 600 or more restrictive (Manual)
- ▌ Cis Ocp V190 1 1 14 · cyberstrikeusEnsure that the kubeconfig file ownership is set to root:root (Manual)
- ▌ Cis Ocp V190 1 1 15 · cyberstrikeusEnsure that the Scheduler kubeconfig file permissions are set to 600 or more restrictive (Manual)
- ▌ Cis Ocp V190 1 1 16 · cyberstrikeusEnsure that the Scheduler kubeconfig file ownership is set to root:root (Manual)
- ▌ Cis Ocp V190 1 1 17 · cyberstrikeusEnsure that the Controller Manager kubeconfig file permissions are set to 600 or more restrictive (Manual)
- ▌ Cis Ocp V190 1 1 18 · cyberstrikeusEnsure that the Controller Manager kubeconfig file ownership is set to root:root (Manual)
- ▌ Cis Ocp V190 1 1 19 · cyberstrikeusEnsure that the OpenShift PKI directory and file ownership is set to root:root (Manual)
- ▌ Cis Ocp V190 1 1 20 · cyberstrikeusEnsure that the OpenShift PKI certificate file permissions are set to 600 or more restrictive (Manual)
- ▌ Cis Ocp V190 1 1 21 · cyberstrikeusEnsure that the OpenShift PKI key file permissions are set to 600 (Manual)
- ▌ Cis Ocp V190 1 2 10 · cyberstrikeusEnsure that the admission control plugin ServiceAccount is set (Manual)
- ▌ Cis Ocp V190 1 2 11 · cyberstrikeusEnsure that the admission control plugin NamespaceLifecycle is set (Manual)
- ▌ Cis Ocp V190 1 2 12 · cyberstrikeusEnsure that the admission control plugin SecurityContextConstraint is set (Manual)
- ▌ Cis Ocp V190 1 2 13 · cyberstrikeusEnsure that the admission control plugin NodeRestriction is set (Manual)
- ▌ Cis Ocp V190 1 2 14 · cyberstrikeusEnsure that the --insecure-bind-address argument is not set (Manual)