cyberstrikeus
- 7.2k skills
- 0 followers
- 2 days ago last updated
- ▌ Cis Gke V180 5 5 1 · cyberstrikeusEnsure Container-Optimized OS (cos_containerd) is used for GKE Node images (Automated)
- ▌
- ▌
- ▌ Cis Gke V180 5 5 4 · cyberstrikeusWhen creating New Clusters - Automate GKE version management using Release Channels (Automated)
- ▌
- ▌ Cis Gke V180 5 5 6 · cyberstrikeusEnsure Integrity Monitoring for Shielded GKE Nodes is Enabled (Automated)
- ▌
- ▌
- ▌
- ▌
- ▌ Cis Gke V180 5 6 4 · cyberstrikeusEnsure clusters are created with Private Endpoint Enabled and Public Access Disabled (Automated)
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌ Cis Gke V180 5 8 1 · cyberstrikeusEnsure authentication using Client Certificates is Disabled (Automated)
- ▌
- ▌
- ▌ Cis Gke V180 5 9 1 · cyberstrikeusEnable Customer-Managed Encryption Keys (CMEK) for GKE Persistent Disks (PD) (Manual)
- ▌ Cis Gke V180 5 9 2 · cyberstrikeusEnable Customer-Managed Encryption Keys (CMEK) for Boot Disks (Automated)
- ▌ Cis Gke V190 4 1 1 · cyberstrikeusEnsure that the cluster-admin role is only used where required (Manual)
- ▌
- ▌
- ▌ Cis Gke V190 4 1 5 · cyberstrikeusEnsure that Service Account Tokens are only mounted where necessary (Manual)
- ▌
- ▌ Cis Gke V190 5 8 2 · cyberstrikeusManage Kubernetes RBAC users with groups in Google Workspace (Manual)
- ▌ Cis Oke V150 2 1 1 · cyberstrikeusClient certificate authentication should not be used for users (Automated)
- ▌
- ▌ Cis Oke V150 3 1 1 · cyberstrikeusEnsure that the oke_kubelet_conf.json file permissions are set to 644 or more restrictive (Automated)
- ▌ Cis Oke V150 3 1 2 · cyberstrikeusEnsure that the proxy oke_kubelet_conf.json file ownership is set to root:root (Automated)
- ▌ Cis Oke V150 3 1 3 · cyberstrikeusEnsure that the kubelet configuration file has permissions set to 644 or more restrictive (Automated)
- ▌ Cis Oke V150 3 1 4 · cyberstrikeusEnsure that the kubelet configuration file ownership is set to root:root (Automated)
- ▌ Cis Oke V150 3 2 1 · cyberstrikeusEnsure that the --anonymous-auth argument is set to false (Automated)
- ▌ Cis Oke V150 3 2 2 · cyberstrikeusEnsure that the --authorization-mode argument is not set to AlwaysAllow (Automated)
- ▌ Cis Oke V150 3 2 3 · cyberstrikeusEnsure that the --client-ca-file argument is set as appropriate (Automated)
- ▌ Cis Oke V150 3 2 4 · cyberstrikeusEnsure that the --read-only-port argument is set to 0 (Automated)
- ▌ Cis Oke V150 3 2 5 · cyberstrikeusEnsure that the --streaming-connection-idle-timeout argument is not set to 0 (Automated)
- ▌ Cis Oke V150 3 2 6 · cyberstrikeusEnsure that the --make-iptables-util-chains argument is set to true (Automated)
- ▌ Cis Oke V150 3 2 7 · cyberstrikeusEnsure that the --event-qps argument is set to 0 or a level which ensures appropriate event capture (Automated)
- ▌ Cis Oke V150 3 2 8 · cyberstrikeusEnsure that the --tls-cert-file and --tls-private-key-file arguments are set as appropriate (Automated)
- ▌ Cis Oke V150 3 2 9 · cyberstrikeusEnsure that the --rotate-certificates argument is not set to false (Automated)
- ▌ Cis Oke V150 4 1 1 · cyberstrikeusEnsure that the cluster-admin role is only used where required (Automated)
- ▌
- ▌
- ▌
- ▌ Cis Oke V150 4 1 5 · cyberstrikeusEnsure that default service accounts are not actively used (Automated)
- ▌ Sc 7 25 Unclassified National Security System Connections · cyberstrikeusProhibit the direct connection of [organization-defined] to an external network without the use of [organization-defined].
- ▌ Sc 7 15 Networked Privileged Accesses · cyberstrikeusRoute networked, privileged accesses through a dedicated, managed interface for purposes of access control and auditing.
- ▌
- ▌ Cis Ocp Vm V100 1 2 · cyberstrikeusEnable nonRoot feature gate in OCPvirt prior to 4.18 (Automated)
- ▌
- ▌
- ▌
- ▌ Cis Ocp Vm V100 1 6 · cyberstrikeusRestrict patching operations in the annotations for Hyperconverged (Manual)
- ▌
- ▌ Cis Ocp Vm V100 1 8 · cyberstrikeusEnsure kubevirt seccomp profile file permission is set to 700 or more restrictive (Automated)
- ▌ Cis Ocp Vm V100 1 9 · cyberstrikeusEnsure kubevirt cache directory permission is set to 755 or more restrictive (Automated)
- ▌ Cis Ocp Vm V100 2 1 · cyberstrikeusRestrict pass through of GPUs and Host devices to the Virtual Machine (Manual)
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌ User Identification And Authentication 03 05 01 User Identif · cyberstrikeusUniquely identify and authenticate system users, and associate that unique identification with processes acting on behalf of those users.
- ▌
- ▌ Information Management And Retention 03 14 08 Information Ma · cyberstrikeusInformation Management and Retention
- ▌ Pe 11 1 Alternate Power Supply Minimal Operational Capabilit · cyberstrikeusProvide an alternate power supply for the system that is activated [organization-defined] and that can maintain minimally required operational capabil
- ▌ Pe 12 1 Essential Mission And Business Functions · cyberstrikeusProvide emergency lighting for all areas within the facility supporting essential mission and business functions.
- ▌ Pe 21 Electromagnetic Pulse Protection · cyberstrikeusEmploy [organization-defined] against electromagnetic pulse damage for [organization-defined].
- ▌ Pe 5 Access Control For Output Devices · cyberstrikeusControl physical access to output from [organization-defined] to prevent unauthorized individuals from obtaining the output.
- ▌ Pe 6 2 Automated Intrusion Recognition And Responses · cyberstrikeusRecognize [organization-defined] and initiate [organization-defined] using [organization-defined].
- ▌ Sc 15 3 Disabling And Removal In Secure Work Areas · cyberstrikeusDisable or remove collaborative computing devices and applications from [organization-defined] in [organization-defined].
- ▌ Sc 15 1 Physical Or Logical Disconnect · cyberstrikeusProvide [organization-defined] disconnect of collaborative computing devices in a manner that supports ease of use.
- ▌ Sc 22 Architecture And Provisioning For Nameaddress Resoluti · cyberstrikeusEnsure the systems that collectively provide name/address resolution service for an organization are fault-tolerant and implement internal and externa
- ▌ Sc 23 3 Unique System Generated Session Identifiers · cyberstrikeusGenerate a unique session identifier for each session with [organization-defined] and recognize only session identifiers that are system-generated.
- ▌ Sc 23 4 Unique Session Identifiers With Randomization · cyberstrikeusUnique Session Identifiers with Randomization
- ▌ Sc 27 Platform Independent Applications · cyberstrikeusInclude within organizational systems the following platform independent applications: [organization-defined].
- ▌ Sc 28 Protection Of Information At REST · cyberstrikeusProtect the [organization-defined] of the following information at rest: [organization-defined].
- ▌ Sc 5 1 Restrict Ability To Attack Other Systems · cyberstrikeusRestrict the ability of individuals to launch the following denial-of-service attacks against other systems: [organization-defined].
- ▌ Sc 7 22 Separate Subnets For Connecting To Different Securit · cyberstrikeusImplement separate network addresses to connect to systems in different security domains.
- ▌ Sc 7 21 Isolation Of System Components · cyberstrikeusEmploy boundary protection mechanisms to isolate [organization-defined] supporting [organization-defined].
- ▌ Sc 7 28 Connections To Public Networks · cyberstrikeusProhibit the direct connection of [organization-defined] to a public network.
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌ Cis Ocp V170 1 1 1 · cyberstrikeusEnsure that the API server pod specification file permissions are set to 600 or more restrictive (Manual)
- ▌ Cis Ocp V170 1 1 2 · cyberstrikeusEnsure that the API server pod specification file ownership is set to root:root (Manual)