← all publishers

cyberstrikeus

@cyberstrikeus source repo

7171 published skills · page 35 of 72

  1. Cis Gke V180 5 5 1 · cyberstrikeus
    Ensure Container-Optimized OS (cos_containerd) is used for GKE Node images (Automated)
    0 installs
  2. Cis Gke V180 5 5 2 · cyberstrikeus
    Ensure Node Auto-Repair is Enabled for GKE Nodes (Automated)
    0 installs
  3. Cis Gke V180 5 5 3 · cyberstrikeus
    Ensure Node Auto-Upgrade is Enabled for GKE Nodes (Automated)
    0 installs
  4. Cis Gke V180 5 5 4 · cyberstrikeus
    When creating New Clusters - Automate GKE version management using Release Channels (Automated)
    0 installs
  5. Cis Gke V180 5 5 5 · cyberstrikeus
    Ensure Shielded GKE Nodes are Enabled (Automated)
    0 installs
  6. Cis Gke V180 5 5 6 · cyberstrikeus
    Ensure Integrity Monitoring for Shielded GKE Nodes is Enabled (Automated)
    0 installs
  7. Cis Gke V180 5 5 7 · cyberstrikeus
    Ensure Secure Boot for Shielded GKE Nodes is Enabled (Automated)
    0 installs
  8. Cis Gke V180 5 6 1 · cyberstrikeus
    Enable VPC Flow Logs and Intranode Visibility (Automated)
    0 installs
  9. Cis Gke V180 5 6 2 · cyberstrikeus
    Ensure use of VPC-native clusters (Automated)
    0 installs
  10. Cis Gke V180 5 6 3 · cyberstrikeus
    Ensure Control Plane Authorized Networks is Enabled (Automated)
    0 installs
  11. Cis Gke V180 5 6 4 · cyberstrikeus
    Ensure clusters are created with Private Endpoint Enabled and Public Access Disabled (Automated)
    0 installs
  12. Cis Gke V180 5 6 5 · cyberstrikeus
    Ensure clusters are created with Private Nodes (Automated)
    0 installs
  13. Cis Gke V180 5 6 6 · cyberstrikeus
    Consider firewalling GKE worker nodes (Manual)
    0 installs
  14. Cis Gke V180 5 6 7 · cyberstrikeus
    Ensure use of Google-managed SSL Certificates (Automated)
    0 installs
  15. Cis Gke V180 5 7 1 · cyberstrikeus
    Ensure Logging and Cloud Monitoring is Enabled (Automated)
    0 installs
  16. Cis Gke V180 5 7 2 · cyberstrikeus
    Enable Linux auditd logging (Manual)
    0 installs
  17. Cis Gke V180 5 8 1 · cyberstrikeus
    Ensure authentication using Client Certificates is Disabled (Automated)
    0 installs
  18. Cis Gke V180 5 8 2 · cyberstrikeus
    Manage Kubernetes RBAC users with Google Groups for GKE (Manual)
    0 installs
  19. Cis Gke V180 5 8 3 · cyberstrikeus
    Ensure Legacy Authorization (ABAC) is Disabled (Automated)
    0 installs
  20. Cis Gke V180 5 9 1 · cyberstrikeus
    Enable Customer-Managed Encryption Keys (CMEK) for GKE Persistent Disks (PD) (Manual)
    0 installs
  21. Cis Gke V180 5 9 2 · cyberstrikeus
    Enable Customer-Managed Encryption Keys (CMEK) for Boot Disks (Automated)
    0 installs
  22. Cis Gke V190 4 1 1 · cyberstrikeus
    Ensure that the cluster-admin role is only used where required (Manual)
    0 installs
  23. Cis Gke V190 4 1 2 · cyberstrikeus
    Minimize access to secrets (Manual)
    0 installs
  24. Cis Gke V190 4 1 3 · cyberstrikeus
    Minimize wildcard use in Roles and ClusterRoles (Manual)
    0 installs
  25. Cis Gke V190 4 1 5 · cyberstrikeus
    Ensure that Service Account Tokens are only mounted where necessary (Manual)
    0 installs
  26. Cis Gke V190 4 6 4 · cyberstrikeus
    The default namespace should not be used (Manual)
    0 installs
  27. Cis Gke V190 5 8 2 · cyberstrikeus
    Manage Kubernetes RBAC users with groups in Google Workspace (Manual)
    0 installs
  28. Cis Oke V150 2 1 1 · cyberstrikeus
    Client certificate authentication should not be used for users (Automated)
    0 installs
  29. Cis Oke V150 2 2 1 · cyberstrikeus
    Ensure access to OCI Audit service Log for OKE (Manual)
    0 installs
  30. Cis Oke V150 3 1 1 · cyberstrikeus
    Ensure that the oke_kubelet_conf.json file permissions are set to 644 or more restrictive (Automated)
    0 installs
  31. Cis Oke V150 3 1 2 · cyberstrikeus
    Ensure that the proxy oke_kubelet_conf.json file ownership is set to root:root (Automated)
    0 installs
  32. Cis Oke V150 3 1 3 · cyberstrikeus
    Ensure that the kubelet configuration file has permissions set to 644 or more restrictive (Automated)
    0 installs
  33. Cis Oke V150 3 1 4 · cyberstrikeus
    Ensure that the kubelet configuration file ownership is set to root:root (Automated)
    2 installs
  34. Cis Oke V150 3 2 1 · cyberstrikeus
    Ensure that the --anonymous-auth argument is set to false (Automated)
    0 installs
  35. Cis Oke V150 3 2 2 · cyberstrikeus
    Ensure that the --authorization-mode argument is not set to AlwaysAllow (Automated)
    0 installs
  36. Cis Oke V150 3 2 3 · cyberstrikeus
    Ensure that the --client-ca-file argument is set as appropriate (Automated)
    0 installs
  37. Cis Oke V150 3 2 4 · cyberstrikeus
    Ensure that the --read-only-port argument is set to 0 (Automated)
    0 installs
  38. Cis Oke V150 3 2 5 · cyberstrikeus
    Ensure that the --streaming-connection-idle-timeout argument is not set to 0 (Automated)
    0 installs
  39. Cis Oke V150 3 2 6 · cyberstrikeus
    Ensure that the --make-iptables-util-chains argument is set to true (Automated)
    0 installs
  40. Cis Oke V150 3 2 7 · cyberstrikeus
    Ensure that the --event-qps argument is set to 0 or a level which ensures appropriate event capture (Automated)
    0 installs
  41. Cis Oke V150 3 2 8 · cyberstrikeus
    Ensure that the --tls-cert-file and --tls-private-key-file arguments are set as appropriate (Automated)
    0 installs
  42. Cis Oke V150 3 2 9 · cyberstrikeus
    Ensure that the --rotate-certificates argument is not set to false (Automated)
    0 installs
  43. Cis Oke V150 4 1 1 · cyberstrikeus
    Ensure that the cluster-admin role is only used where required (Automated)
    0 installs
  44. Cis Oke V150 4 1 2 · cyberstrikeus
    Minimize access to secrets (Automated)
    0 installs
  45. Cis Oke V150 4 1 3 · cyberstrikeus
    Minimize wildcard use in Roles and ClusterRoles (Automated)
    0 installs
  46. Cis Oke V150 4 1 4 · cyberstrikeus
    Minimize access to create pods (Automated)
    0 installs
  47. Cis Oke V150 4 1 5 · cyberstrikeus
    Ensure that default service accounts are not actively used (Automated)
    0 installs
  48. Sc 7 25 Unclassified National Security System Connections · cyberstrikeus
    Prohibit the direct connection of [organization-defined] to an external network without the use of [organization-defined].
    0 installs
  49. Sc 7 15 Networked Privileged Accesses · cyberstrikeus
    Route networked, privileged accesses through a dedicated, managed interface for purposes of access control and auditing.
    0 installs
  50. Cis Ocp Vm V100 1 1 · cyberstrikeus
    Restrict GPU and USB pass through to approved devices (Manual)
    0 installs
  51. Cis Ocp Vm V100 1 2 · cyberstrikeus
    Enable nonRoot feature gate in OCPvirt prior to 4.18 (Automated)
    0 installs
  52. Cis Ocp Vm V100 1 3 · cyberstrikeus
    Disable persistentReservations feature gate (Automated)
    0 installs
  53. Cis Ocp Vm V100 1 4 · cyberstrikeus
    Disable downwardMetrics feature gate (Automated)
    0 installs
  54. Cis Ocp Vm V100 1 5 · cyberstrikeus
    Enforce the use of trusted registries using TLS (Automated)
    0 installs
  55. Cis Ocp Vm V100 1 6 · cyberstrikeus
    Restrict patching operations in the annotations for Hyperconverged (Manual)
    0 installs
  56. Cis Ocp Vm V100 1 7 · cyberstrikeus
    Ensure KSM is disabled (Automated)
    0 installs
  57. Cis Ocp Vm V100 1 8 · cyberstrikeus
    Ensure kubevirt seccomp profile file permission is set to 700 or more restrictive (Automated)
    0 installs
  58. Cis Ocp Vm V100 1 9 · cyberstrikeus
    Ensure kubevirt cache directory permission is set to 755 or more restrictive (Automated)
    0 installs
  59. Cis Ocp Vm V100 2 1 · cyberstrikeus
    Restrict pass through of GPUs and Host devices to the Virtual Machine (Manual)
    0 installs
  60. Cis Ocp Vm V100 2 2 · cyberstrikeus
    Disable overcommitting guest memory (Manual)
    0 installs
  61. Cis Ocp Vm V100 3 1 · cyberstrikeus
    Restrict access to cross datavolumes cloning (Manual)
    0 installs
  62. Cis Ocp Vm V100 3 2 · cyberstrikeus
    Disable Shareable disks (Automated)
    0 installs
  63. Cis Ocp Vm V100 3 3 · cyberstrikeus
    Ensure errorPolicy is not set to ignore (Manual)
    0 installs
  64. Cis Ocp Vm V100 4 1 · cyberstrikeus
    Use dedicated VLANs to segment network traffic (Automated)
    0 installs
  65. Cis Ocp Vm V100 4 2 · cyberstrikeus
    Enable MAC spoof filtering (Automated)
    0 installs
  66. Cis Ocp Vm V100 4 3 · cyberstrikeus
    Use multi-network policies (Manual)
    0 installs
  67. Cis Ocp Vm V100 5 1 · cyberstrikeus
    Disable Intel Trusted Execution Technology (TXT) (Manual)
    0 installs
  68. Cis Ocp Vm V100 6 1 · cyberstrikeus
    Disable nested virtualization (Manual)
    0 installs
  69. Cis Ocp Vm V100 6 2 · cyberstrikeus
    Enable vCPU metrics (Manual)
    0 installs
  70. Cis Ocp Vm V100 6 3 · cyberstrikeus
    Ensure all CPU vulnerabilities are mitigated (Manual)
    0 installs
  71. User Identification And Authentication 03 05 01 User Identif · cyberstrikeus
    Uniquely identify and authenticate system users, and associate that unique identification with processes acting on behalf of those users.
    0 installs
  72. Security Assessment 03 12 01 Security Assessment · cyberstrikeus
    Security Assessment
    0 installs
  73. Information Management And Retention 03 14 08 Information Ma · cyberstrikeus
    Information Management and Retention
    0 installs
  74. Pe 11 1 Alternate Power Supply Minimal Operational Capabilit · cyberstrikeus
    Provide an alternate power supply for the system that is activated [organization-defined] and that can maintain minimally required operational capabil
    0 installs
  75. Pe 12 1 Essential Mission And Business Functions · cyberstrikeus
    Provide emergency lighting for all areas within the facility supporting essential mission and business functions.
    0 installs
  76. Pe 21 Electromagnetic Pulse Protection · cyberstrikeus
    Employ [organization-defined] against electromagnetic pulse damage for [organization-defined].
    0 installs
  77. Pe 5 Access Control For Output Devices · cyberstrikeus
    Control physical access to output from [organization-defined] to prevent unauthorized individuals from obtaining the output.
    0 installs
  78. Pe 6 2 Automated Intrusion Recognition And Responses · cyberstrikeus
    Recognize [organization-defined] and initiate [organization-defined] using [organization-defined].
    0 installs
  79. Sc 15 3 Disabling And Removal In Secure Work Areas · cyberstrikeus
    Disable or remove collaborative computing devices and applications from [organization-defined] in [organization-defined].
    0 installs
  80. Sc 15 1 Physical Or Logical Disconnect · cyberstrikeus
    Provide [organization-defined] disconnect of collaborative computing devices in a manner that supports ease of use.
    0 installs
  81. Sc 22 Architecture And Provisioning For Nameaddress Resoluti · cyberstrikeus
    Ensure the systems that collectively provide name/address resolution service for an organization are fault-tolerant and implement internal and externa
    0 installs
  82. Sc 23 3 Unique System Generated Session Identifiers · cyberstrikeus
    Generate a unique session identifier for each session with [organization-defined] and recognize only session identifiers that are system-generated.
    0 installs
  83. Sc 23 4 Unique Session Identifiers With Randomization · cyberstrikeus
    Unique Session Identifiers with Randomization
    0 installs
  84. Sc 27 Platform Independent Applications · cyberstrikeus
    Include within organizational systems the following platform independent applications: [organization-defined].
    0 installs
  85. Sc 28 Protection Of Information At REST · cyberstrikeus
    Protect the [organization-defined] of the following information at rest: [organization-defined].
    0 installs
  86. Sc 5 1 Restrict Ability To Attack Other Systems · cyberstrikeus
    Restrict the ability of individuals to launch the following denial-of-service attacks against other systems: [organization-defined].
    0 installs
  87. Sc 7 22 Separate Subnets For Connecting To Different Securit · cyberstrikeus
    Implement separate network addresses to connect to systems in different security domains.
    0 installs
  88. Sc 7 21 Isolation Of System Components · cyberstrikeus
    Employ boundary protection mechanisms to isolate [organization-defined] supporting [organization-defined].
    0 installs
  89. Sc 7 28 Connections To Public Networks · cyberstrikeus
    Prohibit the direct connection of [organization-defined] to a public network.
    0 installs
  90. Sc 7 6 Response To Recognized Failures · cyberstrikeus
    Response to Recognized Failures
    0 installs
  91. Cis Gworkspace 6 1 · cyberstrikeus
    Ensure User's password changed is configured
    0 installs
  92. Cis Gworkspace 6 2 · cyberstrikeus
    Ensure Government-backed attacks is configured
    0 installs
  93. Cis Gworkspace 6 3 · cyberstrikeus
    Ensure User suspended due to suspicious activity is configured
    0 installs
  94. Cis Gworkspace 6 4 · cyberstrikeus
    Ensure User granted Admin privilege is configured
    0 installs
  95. Cis Gworkspace 6 5 · cyberstrikeus
    Ensure Suspicious programmatic login is configured
    0 installs
  96. Cis Gworkspace 6 6 · cyberstrikeus
    Ensure Suspicious login is configured
    0 installs
  97. Cis Gworkspace 6 7 · cyberstrikeus
    Ensure Leaked password is configured
    0 installs
  98. Cis Gworkspace 6 8 · cyberstrikeus
    Ensure Gmail potential employee spoofing is configured
    0 installs
  99. Cis Ocp V170 1 1 1 · cyberstrikeus
    Ensure that the API server pod specification file permissions are set to 600 or more restrictive (Manual)
    0 installs
  100. Cis Ocp V170 1 1 2 · cyberstrikeus
    Ensure that the API server pod specification file ownership is set to root:root (Manual)
    0 installs