← all publishers

cyberstrikeus

@cyberstrikeus source repo

7171 published skills · page 33 of 72

  1. Cis Ocp V190 1 2 15 · cyberstrikeus
    Ensure that the --insecure-port argument is set to 0 (Manual)
    2 installs
  2. Cis Ocp V190 1 2 16 · cyberstrikeus
    Ensure that the --secure-port argument is not set to 0 (Manual)
    2 installs
  3. Cis Ocp V190 1 2 17 · cyberstrikeus
    Ensure that the healthz endpoint is protected by RBAC (Manual)
    0 installs
  4. Cis Ocp V190 1 2 18 · cyberstrikeus
    Ensure that the --audit-log-path argument is set (Manual)
    0 installs
  5. Cis Ocp V190 1 2 19 · cyberstrikeus
    Ensure that the audit logs are forwarded off the cluster for retention (Manual)
    0 installs
  6. Cis Ocp V190 1 2 20 · cyberstrikeus
    Ensure that the maximumRetainedFiles argument is set to 10 or as appropriate (Manual)
    2 installs
  7. Cis Ocp V190 1 2 21 · cyberstrikeus
    Configure Kubernetes API Server Maximum Audit Log Size (Manual)
    0 installs
  8. Cis Ocp V190 1 2 22 · cyberstrikeus
    Ensure that the --request-timeout argument is set (Manual)
    0 installs
  9. Cis Ocp V190 1 2 23 · cyberstrikeus
    Ensure that the --service-account-lookup argument is set to true (Manual)
    0 installs
  10. Cis Ocp V190 1 2 24 · cyberstrikeus
    Ensure that the --service-account-key-file argument is set as appropriate (Manual)
    0 installs
  11. Cis Ocp V190 1 2 25 · cyberstrikeus
    Ensure that the --etcd-certfile and --etcd-keyfile arguments are set as appropriate (Manual)
    0 installs
  12. Cis Ocp V190 1 2 26 · cyberstrikeus
    Ensure that the --tls-cert-file and --tls-private-key-file arguments are set as appropriate (Manual)
    0 installs
  13. Cis Ocp V190 1 2 27 · cyberstrikeus
    Ensure that the --client-ca-file argument is set as appropriate (Manual)
    0 installs
  14. Cis Ocp V190 1 2 28 · cyberstrikeus
    Ensure that the --etcd-cafile argument is set as appropriate (Manual)
    0 installs
  15. Cis Ocp V190 1 2 29 · cyberstrikeus
    Ensure that encryption providers are appropriately configured (Manual)
    2 installs
  16. Cis Ocp V190 1 2 30 · cyberstrikeus
    Ensure that the API Server only makes use of Strong Cryptographic Ciphers (Manual)
    0 installs
  17. Cis Ocp V190 1 2 31 · cyberstrikeus
    Ensure unsupported configuration overrides are not used (Manual)
    0 installs
  18. Cis Ocp V190 4 1 10 · cyberstrikeus
    Ensure that the kubelet configuration file ownership is set to root:root (Automated)
    0 installs
  19. Cis Ocp V190 4 2 10 · cyberstrikeus
    Ensure that the --rotate-certificates argument is not set to false (Manual)
    0 installs
  20. Cis Ocp V190 4 2 11 · cyberstrikeus
    Verify that the RotateKubeletServerCertificate argument is set to true (Manual)
    0 installs
  21. Cis Ocp V190 4 2 12 · cyberstrikeus
    Ensure that the Kubelet only makes use of Strong Cryptographic Ciphers (Manual)
    0 installs
  22. Cis Ocp V190 5 2 10 · cyberstrikeus
    Minimize access to privileged Security Context Constraints (Manual)
    0 installs
  23. Cis Ocp V180 1 1 10 · cyberstrikeus
    Ensure that the Container Network Interface file ownership is set to root:root (Manual)
    2 installs
  24. Cis Ocp V180 1 1 11 · cyberstrikeus
    Ensure that the etcd data directory permissions are set to 700 or more restrictive (Manual)
    0 installs
  25. Cis Ocp V180 1 1 12 · cyberstrikeus
    Ensure that the etcd data directory ownership is set to etcd:etcd (Manual)
    0 installs
  26. Cis Ocp V180 1 1 13 · cyberstrikeus
    Ensure that the kubeconfig file permissions are set to 600 or more restrictive (Manual)
    0 installs
  27. Cis Ocp V180 1 1 14 · cyberstrikeus
    Ensure that the kubeconfig file ownership is set to root:root (Manual)
    0 installs
  28. Cis Ocp V180 1 1 15 · cyberstrikeus
    Ensure that the Scheduler kubeconfig file permissions are set to 600 or more restrictive (Manual)
    0 installs
  29. Cis Ocp V180 1 1 16 · cyberstrikeus
    Ensure that the Scheduler kubeconfig file ownership is set to root:root (Manual)
    0 installs
  30. Cis Ocp V180 1 1 17 · cyberstrikeus
    Ensure that the Controller Manager kubeconfig file permissions are set to 600 or more restrictive (Manual)
    0 installs
  31. Cis Ocp V180 1 1 18 · cyberstrikeus
    Ensure that the Controller Manager kubeconfig file ownership is set to root:root (Manual)
    0 installs
  32. Cis Ocp V180 1 1 19 · cyberstrikeus
    Ensure that the OpenShift PKI directory and file ownership is set to root:root (Manual)
    0 installs
  33. Cis Ocp V180 1 1 20 · cyberstrikeus
    Ensure that the OpenShift PKI certificate file permissions are set to 600 or more restrictive (Manual)
    0 installs
  34. Cis Ocp V180 1 1 21 · cyberstrikeus
    Ensure that the OpenShift PKI key file permissions are set to 600 (Manual)
    0 installs
  35. Cis Ocp V180 1 2 10 · cyberstrikeus
    Ensure that the admission control plugin ServiceAccount is set (Manual)
    0 installs
  36. Cis Ocp V180 1 2 11 · cyberstrikeus
    Ensure that the admission control plugin NamespaceLifecycle is set (Manual)
    0 installs
  37. Cis Ocp V180 1 2 12 · cyberstrikeus
    Ensure that the admission control plugin SecurityContextConstraint is set (Manual)
    0 installs
  38. Cis Ocp V180 1 2 13 · cyberstrikeus
    Ensure that the admission control plugin NodeRestriction is set (Manual)
    0 installs
  39. Cis Ocp V180 1 2 14 · cyberstrikeus
    Ensure that the --insecure-bind-address argument is not set (Manual)
    0 installs
  40. Cis Ocp V180 1 2 15 · cyberstrikeus
    Ensure that the --insecure-port argument is set to 0 (Manual)
    0 installs
  41. Cis Ocp V180 1 2 16 · cyberstrikeus
    Ensure that the --secure-port argument is not set to 0 (Manual)
    0 installs
  42. Cis Ocp V180 1 2 17 · cyberstrikeus
    Ensure that the healthz endpoint is protected by RBAC (Manual)
    0 installs
  43. Cis Ocp V180 1 2 18 · cyberstrikeus
    Ensure that the --audit-log-path argument is set (Manual)
    0 installs
  44. Cis Ocp V180 1 2 19 · cyberstrikeus
    Ensure that the audit logs are forwarded off the cluster for retention (Manual)
    0 installs
  45. Cis Ocp V180 1 2 20 · cyberstrikeus
    Ensure that the maximumRetainedFiles argument is set to 10 or as appropriate (Manual)
    2 installs
  46. Cis Ocp V180 1 2 21 · cyberstrikeus
    Configure Kubernetes API Server Maximum Audit Log Size (Manual)
    0 installs
  47. Cis Ocp V180 1 2 22 · cyberstrikeus
    Ensure that the --request-timeout argument is set (Manual)
    0 installs
  48. Si 18 Personally Identifiable Information Quality Operations · cyberstrikeus
    Check the accuracy, relevance, timeliness, and completeness of personally identifiable information across the information life cycle [organization-...
    0 installs
  49. Si 19 6 Differential Privacy · cyberstrikeus
    Prevent disclosure of personally identifiable information by adding non-deterministic noise to the results of mathematical operations before the resul
    0 installs
  50. Si 4 19 Risk For Individuals · cyberstrikeus
    Implement [organization-defined] of individuals who have been identified by [organization-defined] as posing an increased level of risk.
    0 installs
  51. Si 4 21 Probationary Periods · cyberstrikeus
    Implement the following additional monitoring of individuals during [organization-defined]: [organization-defined].
    0 installs
  52. Si 6 2 Automation Support For Distributed Testing · cyberstrikeus
    Implement automated mechanisms to support the management of distributed security and privacy function testing.
    0 installs
  53. Sr 11 2 Configuration Control For Component Service And Repa · cyberstrikeus
    Maintain configuration control over the following system components awaiting service or repair and serviced or repaired components awaiting return to
    0 installs
  54. Cis AWS Euc 2 10 · cyberstrikeus
    Ensure that patches and updates are performed on the operating system for Workstations
    0 installs
  55. Cis AWS Euc 2 11 · cyberstrikeus
    Ensure your WorkSpaces image has the appropriate CIS Operating System Benchmark applied
    0 installs
  56. Cis AWS Euc 2 12 · cyberstrikeus
    Restrict WorkSpaces Bundle options to organization approved versions
    0 installs
  57. Cis AWS Euc 2 13 · cyberstrikeus
    Ensure Workspaces images are not older than 90 days
    1 install
  58. Cis AWS Euc 2 14 · cyberstrikeus
    Ensure WorkSpaces that are not being utilized are removed
    0 installs
  59. Cis AWS Euc 2 15 · cyberstrikeus
    Ensure primary interface ports for Workspaces are not open to all inbound traffic
    0 installs
  60. Cis AWS Euc 2 16 · cyberstrikeus
    Ensure FIPS Endpoint encryption is enabled for WorkSpaces
    0 installs
  61. Cis AWS Euc 2 17 · cyberstrikeus
    Ensure WorkSpaces API requests flow through a VPC Endpoint
    0 installs
  62. Cis AWS Euc 2 18 · cyberstrikeus
    Ensure Radius server is using the recommended security protocol
    0 installs
  63. Cis Docker V160 2 1 · cyberstrikeus
    Run the Docker daemon as a non-root user, if possible
    0 installs
  64. Cis Docker V160 2 2 · cyberstrikeus
    Ensure network traffic is restricted between containers on the default bridge
    0 installs
  65. Cis Docker V160 2 3 · cyberstrikeus
    Ensure the logging level is set to 'info'
    0 installs
  66. Cis Docker V160 2 4 · cyberstrikeus
    Ensure Docker is allowed to make changes to iptables
    0 installs
  67. Cis Docker V160 2 5 · cyberstrikeus
    Ensure insecure registries are not used
    0 installs
  68. Cis Docker V160 2 6 · cyberstrikeus
    Ensure aufs storage driver is not used
    0 installs
  69. Cis Docker V160 2 7 · cyberstrikeus
    Ensure TLS authentication for Docker daemon is configured
    0 installs
  70. Cis Docker V160 2 8 · cyberstrikeus
    Ensure the default ulimit is configured appropriately
    0 installs
  71. Cis Docker V160 2 9 · cyberstrikeus
    Enable user namespace support
    0 installs
  72. Cis Docker V170 2 1 · cyberstrikeus
    Run the Docker daemon as a non-root user, if possible
    0 installs
  73. Cis Docker V170 2 2 · cyberstrikeus
    Ensure network traffic is restricted between containers on the default bridge
    0 installs
  74. Cis Docker V170 2 3 · cyberstrikeus
    Ensure the logging level is set to 'info'
    0 installs
  75. Cis Docker V170 2 4 · cyberstrikeus
    Ensure Docker is allowed to make changes to iptables
    0 installs
  76. Cis Docker V170 2 5 · cyberstrikeus
    Ensure insecure registries are not used
    0 installs
  77. Cis Docker V170 2 6 · cyberstrikeus
    Ensure aufs storage driver is not used
    0 installs
  78. Cis Docker V170 2 7 · cyberstrikeus
    Ensure TLS authentication for Docker daemon is configured
    0 installs
  79. Cis Docker V170 2 8 · cyberstrikeus
    Ensure the default ulimit is configured appropriately
    0 installs
  80. Cis Docker V170 2 9 · cyberstrikeus
    Enable user namespace support
    0 installs
  81. Cis Docker V170 3 1 · cyberstrikeus
    Ensure that the docker.service file ownership is set to root:root
    0 installs
  82. Cis Docker V170 3 2 · cyberstrikeus
    Ensure that docker.service file permissions are appropriately set
    0 installs
  83. Cis Docker V170 3 3 · cyberstrikeus
    Ensure that docker.socket file ownership is set to root:root
    0 installs
  84. Cis Docker V170 3 4 · cyberstrikeus
    Ensure that docker.socket file permissions are set to 644 or more restrictive
    0 installs
  85. Cis Docker V170 3 5 · cyberstrikeus
    Ensure that the /etc/docker directory ownership is set to root:root
    0 installs
  86. Cis Docker V170 3 6 · cyberstrikeus
    Ensure that /etc/docker directory permissions are set to 755 or more restrictively
    0 installs
  87. Cis Docker V170 3 7 · cyberstrikeus
    Ensure that registry certificate file ownership is set to root:root
    0 installs
  88. Cis Docker V170 3 8 · cyberstrikeus
    Ensure that registry certificate file permissions are set to 444 or more restrictively
    0 installs
  89. Cis Docker V170 3 9 · cyberstrikeus
    Ensure that TLS CA certificate file ownership is set to root:root
    0 installs
  90. Cis Docker V170 4 1 · cyberstrikeus
    Ensure that a user for the container has been created
    0 installs
  91. Cis Docker V170 4 2 · cyberstrikeus
    Ensure that containers use only trusted base images
    0 installs
  92. Cis Docker V170 4 3 · cyberstrikeus
    Ensure that unnecessary packages are not installed in the container
    0 installs
  93. Cis Docker V170 4 4 · cyberstrikeus
    Ensure images are scanned and rebuilt to include security patches
    0 installs
  94. Cis Docker V170 4 5 · cyberstrikeus
    Ensure Content trust for Docker is Enabled
    0 installs
  95. Cis Docker V170 4 6 · cyberstrikeus
    Ensure that HEALTHCHECK instructions have been added to container images
    0 installs
  96. Cis Docker V170 4 7 · cyberstrikeus
    Ensure update instructions are not used alone in Dockerfiles
    0 installs
  97. Cis Docker V170 4 8 · cyberstrikeus
    Ensure setuid and setgid permissions are removed
    0 installs
  98. Cis Docker V170 4 9 · cyberstrikeus
    Ensure that COPY is used instead of ADD in Dockerfiles
    0 installs
  99. Cis Docker V170 5 1 · cyberstrikeus
    Ensure swarm mode is not Enabled, if not needed
    0 installs
  100. Cis Docker V170 5 2 · cyberstrikeus
    Ensure that, if applicable, an AppArmor Profile is enabled
    0 installs