cyberstrikeus
- 7.2k skills
- 0 followers
- 2 days ago last updated
- ▌
- ▌
- ▌
- ▌
- ▌ Cis Ocp V190 1 2 19 · cyberstrikeusEnsure that the audit logs are forwarded off the cluster for retention (Manual)
- ▌ Cis Ocp V190 1 2 20 · cyberstrikeusEnsure that the maximumRetainedFiles argument is set to 10 or as appropriate (Manual)
- ▌
- ▌
- ▌ Cis Ocp V190 1 2 23 · cyberstrikeusEnsure that the --service-account-lookup argument is set to true (Manual)
- ▌ Cis Ocp V190 1 2 24 · cyberstrikeusEnsure that the --service-account-key-file argument is set as appropriate (Manual)
- ▌ Cis Ocp V190 1 2 25 · cyberstrikeusEnsure that the --etcd-certfile and --etcd-keyfile arguments are set as appropriate (Manual)
- ▌ Cis Ocp V190 1 2 26 · cyberstrikeusEnsure that the --tls-cert-file and --tls-private-key-file arguments are set as appropriate (Manual)
- ▌ Cis Ocp V190 1 2 27 · cyberstrikeusEnsure that the --client-ca-file argument is set as appropriate (Manual)
- ▌ Cis Ocp V190 1 2 28 · cyberstrikeusEnsure that the --etcd-cafile argument is set as appropriate (Manual)
- ▌ Cis Ocp V190 1 2 29 · cyberstrikeusEnsure that encryption providers are appropriately configured (Manual)
- ▌ Cis Ocp V190 1 2 30 · cyberstrikeusEnsure that the API Server only makes use of Strong Cryptographic Ciphers (Manual)
- ▌ Cis Ocp V190 1 2 31 · cyberstrikeusEnsure unsupported configuration overrides are not used (Manual)
- ▌ Cis Ocp V190 4 1 10 · cyberstrikeusEnsure that the kubelet configuration file ownership is set to root:root (Automated)
- ▌ Cis Ocp V190 4 2 10 · cyberstrikeusEnsure that the --rotate-certificates argument is not set to false (Manual)
- ▌ Cis Ocp V190 4 2 11 · cyberstrikeusVerify that the RotateKubeletServerCertificate argument is set to true (Manual)
- ▌ Cis Ocp V190 4 2 12 · cyberstrikeusEnsure that the Kubelet only makes use of Strong Cryptographic Ciphers (Manual)
- ▌ Cis Ocp V190 5 2 10 · cyberstrikeusMinimize access to privileged Security Context Constraints (Manual)
- ▌ Cis Ocp V180 1 1 10 · cyberstrikeusEnsure that the Container Network Interface file ownership is set to root:root (Manual)
- ▌ Cis Ocp V180 1 1 11 · cyberstrikeusEnsure that the etcd data directory permissions are set to 700 or more restrictive (Manual)
- ▌ Cis Ocp V180 1 1 12 · cyberstrikeusEnsure that the etcd data directory ownership is set to etcd:etcd (Manual)
- ▌ Cis Ocp V180 1 1 13 · cyberstrikeusEnsure that the kubeconfig file permissions are set to 600 or more restrictive (Manual)
- ▌ Cis Ocp V180 1 1 14 · cyberstrikeusEnsure that the kubeconfig file ownership is set to root:root (Manual)
- ▌ Cis Ocp V180 1 1 15 · cyberstrikeusEnsure that the Scheduler kubeconfig file permissions are set to 600 or more restrictive (Manual)
- ▌ Cis Ocp V180 1 1 16 · cyberstrikeusEnsure that the Scheduler kubeconfig file ownership is set to root:root (Manual)
- ▌ Cis Ocp V180 1 1 17 · cyberstrikeusEnsure that the Controller Manager kubeconfig file permissions are set to 600 or more restrictive (Manual)
- ▌ Cis Ocp V180 1 1 18 · cyberstrikeusEnsure that the Controller Manager kubeconfig file ownership is set to root:root (Manual)
- ▌ Cis Ocp V180 1 1 19 · cyberstrikeusEnsure that the OpenShift PKI directory and file ownership is set to root:root (Manual)
- ▌ Cis Ocp V180 1 1 20 · cyberstrikeusEnsure that the OpenShift PKI certificate file permissions are set to 600 or more restrictive (Manual)
- ▌ Cis Ocp V180 1 1 21 · cyberstrikeusEnsure that the OpenShift PKI key file permissions are set to 600 (Manual)
- ▌ Cis Ocp V180 1 2 10 · cyberstrikeusEnsure that the admission control plugin ServiceAccount is set (Manual)
- ▌ Cis Ocp V180 1 2 11 · cyberstrikeusEnsure that the admission control plugin NamespaceLifecycle is set (Manual)
- ▌ Cis Ocp V180 1 2 12 · cyberstrikeusEnsure that the admission control plugin SecurityContextConstraint is set (Manual)
- ▌ Cis Ocp V180 1 2 13 · cyberstrikeusEnsure that the admission control plugin NodeRestriction is set (Manual)
- ▌ Cis Ocp V180 1 2 14 · cyberstrikeusEnsure that the --insecure-bind-address argument is not set (Manual)
- ▌
- ▌
- ▌
- ▌
- ▌ Cis Ocp V180 1 2 19 · cyberstrikeusEnsure that the audit logs are forwarded off the cluster for retention (Manual)
- ▌ Cis Ocp V180 1 2 20 · cyberstrikeusEnsure that the maximumRetainedFiles argument is set to 10 or as appropriate (Manual)
- ▌
- ▌
- ▌ Si 18 Personally Identifiable Information Quality Operations · cyberstrikeusCheck the accuracy, relevance, timeliness, and completeness of personally identifiable information across the information life cycle [organization-...
- ▌ Si 19 6 Differential Privacy · cyberstrikeusPrevent disclosure of personally identifiable information by adding non-deterministic noise to the results of mathematical operations before the resul
- ▌ Si 4 19 Risk For Individuals · cyberstrikeusImplement [organization-defined] of individuals who have been identified by [organization-defined] as posing an increased level of risk.
- ▌ Si 4 21 Probationary Periods · cyberstrikeusImplement the following additional monitoring of individuals during [organization-defined]: [organization-defined].
- ▌ Si 6 2 Automation Support For Distributed Testing · cyberstrikeusImplement automated mechanisms to support the management of distributed security and privacy function testing.
- ▌ Sr 11 2 Configuration Control For Component Service And Repa · cyberstrikeusMaintain configuration control over the following system components awaiting service or repair and serviced or repaired components awaiting return to
- ▌ Cis AWS Euc 2 10 · cyberstrikeusEnsure that patches and updates are performed on the operating system for Workstations
- ▌ Cis AWS Euc 2 11 · cyberstrikeusEnsure your WorkSpaces image has the appropriate CIS Operating System Benchmark applied
- ▌ Cis AWS Euc 2 12 · cyberstrikeusRestrict WorkSpaces Bundle options to organization approved versions
- ▌
- ▌
- ▌ Cis AWS Euc 2 15 · cyberstrikeusEnsure primary interface ports for Workspaces are not open to all inbound traffic
- ▌
- ▌
- ▌
- ▌
- ▌ Cis Docker V160 2 2 · cyberstrikeusEnsure network traffic is restricted between containers on the default bridge
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌ Cis Docker V170 2 2 · cyberstrikeusEnsure network traffic is restricted between containers on the default bridge
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌ Cis Docker V170 3 1 · cyberstrikeusEnsure that the docker.service file ownership is set to root:root
- ▌ Cis Docker V170 3 2 · cyberstrikeusEnsure that docker.service file permissions are appropriately set
- ▌
- ▌ Cis Docker V170 3 4 · cyberstrikeusEnsure that docker.socket file permissions are set to 644 or more restrictive
- ▌ Cis Docker V170 3 5 · cyberstrikeusEnsure that the /etc/docker directory ownership is set to root:root
- ▌ Cis Docker V170 3 6 · cyberstrikeusEnsure that /etc/docker directory permissions are set to 755 or more restrictively
- ▌ Cis Docker V170 3 7 · cyberstrikeusEnsure that registry certificate file ownership is set to root:root
- ▌ Cis Docker V170 3 8 · cyberstrikeusEnsure that registry certificate file permissions are set to 444 or more restrictively
- ▌ Cis Docker V170 3 9 · cyberstrikeusEnsure that TLS CA certificate file ownership is set to root:root
- ▌
- ▌
- ▌ Cis Docker V170 4 3 · cyberstrikeusEnsure that unnecessary packages are not installed in the container
- ▌ Cis Docker V170 4 4 · cyberstrikeusEnsure images are scanned and rebuilt to include security patches
- ▌
- ▌ Cis Docker V170 4 6 · cyberstrikeusEnsure that HEALTHCHECK instructions have been added to container images
- ▌
- ▌
- ▌
- ▌
- ▌