cyberstrikeus
- 7.2k skills
- 0 followers
- 2 days ago last updated
- ▌
- ▌ Cis Docker V170 5 4 · cyberstrikeusEnsure that Linux kernel capabilities are restricted within containers
- ▌
- ▌ Cis Docker V170 5 6 · cyberstrikeusEnsure sensitive host system directories are not mounted on containers
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌ Cis Docker V170 7 1 · cyberstrikeusEnsure that the minimum number of manager nodes have been created in a swarm
- ▌ Cis Docker V170 7 2 · cyberstrikeusEnsure that swarm services are bound to a specific host interface
- ▌
- ▌ Cis Docker V170 7 4 · cyberstrikeusEnsure that Docker's secret management commands are used for managing secrets in a swarm cluster
- ▌
- ▌ Cis Docker V170 7 6 · cyberstrikeusEnsure that the swarm manager auto-lock key is rotated periodically
- ▌
- ▌
- ▌ Cis Docker V170 7 9 · cyberstrikeusEnsure that management plane traffic is separated from data plane traffic
- ▌ Cis Gke V170 3 1 1 · cyberstrikeusEnsure that the proxy kubeconfig file permissions are set to 644 or more restrictive (Automated)
- ▌ Cis Gke V170 3 1 2 · cyberstrikeusEnsure that the proxy kubeconfig file ownership is set to root:root (Automated)
- ▌ Cis Gke V170 3 1 3 · cyberstrikeusEnsure that the kubelet configuration file has permissions set to 644 (Automated)
- ▌ Cis Gke V170 3 1 4 · cyberstrikeusEnsure that the kubelet configuration file ownership is set to root:root (Automated)
- ▌
- ▌ Cis Gke V170 3 2 2 · cyberstrikeusEnsure that the --authorization-mode argument is not set to AlwaysAllow (Automated)
- ▌
- ▌
- ▌ Cis Gke V170 3 2 5 · cyberstrikeusEnsure that the --streaming-connection-idle-timeout argument is not set to 0 (Automated)
- ▌ Cis Gke V170 3 2 6 · cyberstrikeusEnsure that the --make-iptables-util-chains argument is set to true (Automated)
- ▌ Cis Gke V170 3 2 7 · cyberstrikeusEnsure that the --eventRecordQPS argument is set to 0 or a level which ensures appropriate event capture (Automated)
- ▌ Cis Gke V170 3 2 8 · cyberstrikeusEnsure that the --rotate-certificates argument is not present or is set to true (Automated)
- ▌ Cis Gke V170 3 2 9 · cyberstrikeusEnsure that the RotateKubeletServerCertificate argument is set to true (Automated)
- ▌ Cis Gke V170 4 1 1 · cyberstrikeusEnsure that the cluster-admin role is only used where required (Automated)
- ▌
- ▌
- ▌ Cis Gke V170 4 1 4 · cyberstrikeusEnsure that default service accounts are not actively used (Automated)
- ▌ Cis Gke V170 4 1 5 · cyberstrikeusEnsure that Service Account Tokens are only mounted where necessary (Automated)
- ▌
- ▌ Cis Gke V170 4 1 7 · cyberstrikeusLimit use of the Bind, Impersonate and Escalate permissions in the Kubernetes cluster (Manual)
- ▌
- ▌
- ▌ Cis Gke V170 4 2 1 · cyberstrikeusEnsure that the cluster enforces Pod Security Standard Baseline profile or stricter for all namespaces (Manual)
- ▌
- ▌ Cis Gke V170 4 3 2 · cyberstrikeusEnsure that all Namespaces have Network Policies defined (Automated)
- ▌ Cis Gke V170 4 4 1 · cyberstrikeusPrefer using secrets as files over secrets as environment variables (Automated)
- ▌
- ▌ Cis Gke V170 4 5 1 · cyberstrikeusConfigure Image Provenance using ImagePolicyWebhook admission controller (Manual)
- ▌ Cis Gke V170 4 6 1 · cyberstrikeusCreate administrative boundaries between resources using namespaces (Manual)
- ▌ Cis Gke V170 4 6 2 · cyberstrikeusEnsure that the seccomp profile is set to RuntimeDefault in the pod definitions (Automated)
- ▌
- ▌
- ▌
- ▌
- ▌ Cis Gke V170 5 1 3 · cyberstrikeusMinimize cluster access to read-only for Container Image repositories (Manual)
- ▌
- ▌ Cis Gke V170 5 2 1 · cyberstrikeusEnsure GKE clusters are not running using the Compute Engine default service account (Automated)
- ▌ Cis Gke V170 5 2 2 · cyberstrikeusPrefer using dedicated GCP Service Accounts and Workload Identity (Manual)
- ▌ Cis Gke V170 5 3 1 · cyberstrikeusEnsure Kubernetes Secrets are encrypted using keys managed in Cloud KMS (Automated)
- ▌
- ▌ Cis Gke V170 5 5 1 · cyberstrikeusEnsure Container-Optimized OS (cos_containerd) is used for GKE node images (Automated)
- ▌
- ▌
- ▌ Cis Gke V170 5 5 4 · cyberstrikeusWhen creating New Clusters - Automate GKE version management using Release Channels (Automated)
- ▌
- ▌ Cis Gke V170 5 5 6 · cyberstrikeusEnsure Integrity Monitoring for Shielded GKE Nodes is Enabled (Automated)
- ▌
- ▌
- ▌
- ▌
- ▌ Cis Gke V170 5 6 4 · cyberstrikeusEnsure clusters are created with Private Endpoint Enabled and Public Access Disabled (Automated)
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌ Cis Gke V170 5 8 1 · cyberstrikeusEnsure authentication using Client Certificates is Disabled (Automated)
- ▌
- ▌
- ▌ Cis Gke V170 5 9 1 · cyberstrikeusEnable Customer-Managed Encryption Keys (CMEK) for GKE Persistent Disks (PD) (Manual)
- ▌ Cis Gke V170 5 9 2 · cyberstrikeusEnable Customer-Managed Encryption Keys (CMEK) for Boot Disks (Automated)
- ▌ Cis Gke V180 3 1 1 · cyberstrikeusEnsure that the kubeconfig file permissions are set to 644 or more restrictive (Automated)
- ▌ Cis Gke V180 3 1 2 · cyberstrikeusEnsure that the kubelet kubeconfig file ownership is set to root:root (Automated)
- ▌ Cis Gke V180 3 1 3 · cyberstrikeusEnsure that the kubelet configuration file has permissions set to 644 (Automated)
- ▌ Cis Gke V180 3 1 4 · cyberstrikeusEnsure that the kubelet configuration file ownership is set to root:root (Automated)
- ▌ Cis Gke V180 4 1 1 · cyberstrikeusEnsure that the cluster-admin role is only used where required (Automated)
- ▌
- ▌
- ▌
- ▌ Cis Gke V180 4 2 1 · cyberstrikeusEnsure that the cluster enforces Pod Security Standard Baseline profile or stricter for all namespaces (Manual)
- ▌ Cis Gke V180 4 3 2 · cyberstrikeusEnsure that all Namespaces have Network Policies defined (Automated)
- ▌ Cis Gke V180 4 5 1 · cyberstrikeusConfigure Image Provenance using ImagePolicyWebhook admission controller (Manual)
- ▌ Cis Gke V180 4 6 1 · cyberstrikeusCreate administrative boundaries between resources using namespaces (Manual)
- ▌
- ▌
- ▌
- ▌ Cis Gke V180 5 1 3 · cyberstrikeusMinimize cluster access to read-only for Container Image repositories (Manual)
- ▌
- ▌ Cis Gke V180 5 2 1 · cyberstrikeusEnsure GKE clusters are not running using the Compute Engine default service account (Automated)
- ▌ Cis Gke V180 5 2 2 · cyberstrikeusPrefer using dedicated GCP Service Accounts and Workload Identity (Manual)
- ▌ Cis Gke V180 5 3 1 · cyberstrikeusEnsure Kubernetes Secrets are encrypted using keys managed in Cloud KMS (Automated)
- ▌