cyberstrikeus
- 7.2k skills
- 0 followers
- 2 days ago last updated
- ▌ Cis Ocp V190 4 1 6 · cyberstrikeusEnsure that the --kubeconfig kubelet.conf file ownership is set to root:root (Automated)
- ▌ Cis Ocp V190 4 1 7 · cyberstrikeusEnsure that the certificate authorities file permissions are set to 644 or more restrictive (Automated)
- ▌ Cis Ocp V190 4 1 8 · cyberstrikeusEnsure that the client certificate authorities file ownership is set to root:root (Automated)
- ▌ Cis Ocp V190 4 1 9 · cyberstrikeusEnsure that the kubelet --config configuration file has permissions set to 600 or more restrictive (Automated)
- ▌ Cis Ocp V190 4 2 1 · cyberstrikeusActivate Garbage collection in OpenShift Container Platform 4, as appropriate (Manual)
- ▌ Cis Ocp V190 4 2 2 · cyberstrikeusEnsure that the --anonymous-auth argument is set to false (Automated)
- ▌ Cis Ocp V190 4 2 3 · cyberstrikeusEnsure that the --authorization-mode argument is not set to AlwaysAllow (Automated)
- ▌ Cis Ocp V190 4 2 4 · cyberstrikeusEnsure that the --client-ca-file argument is set as appropriate (Automated)
- ▌ Cis Ocp V190 4 2 5 · cyberstrikeusVerify that the read only port is not used or is set to 0 (Automated)
- ▌ Cis Ocp V190 4 2 6 · cyberstrikeusEnsure that the --streaming-connection-idle-timeout argument is not set to 0 (Automated)
- ▌ Cis Ocp V190 4 2 7 · cyberstrikeusEnsure that the --make-iptables-util-chains argument is set to true (Manual)
- ▌ Cis Ocp V190 4 2 8 · cyberstrikeusEnsure that the kubeAPIQPS [--event-qps] argument is set to a level which ensures appropriate event capture (Manual)
- ▌ Cis Ocp V190 4 2 9 · cyberstrikeusEnsure that the --tls-cert-file and --tls-private-key-file arguments are set as appropriate (Manual)
- ▌ Cis Ocp V190 5 1 1 · cyberstrikeusEnsure that the cluster-admin role is only used where required (Manual)
- ▌
- ▌
- ▌
- ▌ Cis Ocp V190 5 1 5 · cyberstrikeusEnsure that default service accounts are not actively used (Manual)
- ▌ Cis Ocp V190 5 1 6 · cyberstrikeusEnsure that Service Account Tokens are only mounted where necessary (Manual)
- ▌
- ▌ Cis Ocp V190 5 2 2 · cyberstrikeusMinimize the admission of containers wishing to share the host process ID namespace (Manual)
- ▌ Cis Ocp V190 5 2 3 · cyberstrikeusMinimize the admission of containers wishing to share the host IPC namespace (Manual)
- ▌ Cis Ocp V190 5 2 4 · cyberstrikeusMinimize the admission of containers wishing to share the host network namespace (Manual)
- ▌ Cis Ocp V190 5 2 5 · cyberstrikeusMinimize the admission of containers with allowPrivilegeEscalation (Manual)
- ▌
- ▌ Cis Ocp V190 5 2 7 · cyberstrikeusMinimize the admission of containers with the NET_RAW capability (Manual)
- ▌ Cis Ocp V190 5 2 8 · cyberstrikeusMinimize the admission of containers with added capabilities (Manual)
- ▌ Cis Ocp V190 5 2 9 · cyberstrikeusMinimize the admission of containers with capabilities assigned (Manual)
- ▌
- ▌ Cis Ocp V190 5 3 2 · cyberstrikeusEnsure that all Namespaces have Network Policies defined (Manual)
- ▌ Cis Ocp V190 5 4 1 · cyberstrikeusPrefer using secrets as files over secrets as environment variables (Manual)
- ▌
- ▌ Cis Ocp V190 5 5 1 · cyberstrikeusConfigure Image Provenance using image controller configuration parameters (Manual)
- ▌ Cis Ocp V190 5 7 1 · cyberstrikeusCreate administrative boundaries between resources using namespaces (Manual)
- ▌ Cis Ocp V190 5 7 2 · cyberstrikeusEnsure that the seccomp profile is set to docker/default in your pod definitions (Manual)
- ▌
- ▌
- ▌ Cis Ocp V180 1 1 1 · cyberstrikeusEnsure that the API server pod specification file permissions are set to 600 or more restrictive (Manual)
- ▌ Cis Ocp V180 1 1 2 · cyberstrikeusEnsure that the API server pod specification file ownership is set to root:root (Manual)
- ▌ Cis Ocp V180 1 1 3 · cyberstrikeusEnsure that the controller manager pod specification file permissions are set to 600 or more restrictive (Manual)
- ▌ Cis Ocp V180 1 1 4 · cyberstrikeusEnsure that the controller manager pod specification file ownership is set to root:root (Manual)
- ▌ Cis Ocp V180 1 1 5 · cyberstrikeusEnsure that the scheduler pod specification file permissions are set to 600 or more restrictive (Manual)
- ▌ Cis Ocp V180 1 1 6 · cyberstrikeusEnsure that the scheduler pod specification file ownership is set to root:root (Manual)
- ▌ Cis Ocp V180 1 1 7 · cyberstrikeusEnsure that the etcd pod specification file permissions are set to 600 or more restrictive (Manual)
- ▌ Cis Ocp V180 1 1 8 · cyberstrikeusEnsure that the etcd pod specification file ownership is set to root:root (Manual)
- ▌ Cis Ocp V180 1 1 9 · cyberstrikeusEnsure that the Container Network Interface file permissions are set to 600 or more restrictive (Manual)
- ▌
- ▌
- ▌
- ▌ Cis Docker 4 6 · cyberstrikeusEnsure that HEALTHCHECK instructions have been added to container images
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌ Cis Docker 5 4 · cyberstrikeusEnsure that Linux kernel capabilities are restricted within containers
- ▌
- ▌ Cis Docker 5 6 · cyberstrikeusEnsure sensitive host system directories are not mounted on containers
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌ Cis Docker 7 1 · cyberstrikeusEnsure that the minimum number of manager nodes have been created in a swarm
- ▌
- ▌
- ▌ Cis Docker 7 4 · cyberstrikeusEnsure that Docker's secret management commands are used for managing secrets in a swarm cluster
- ▌
- ▌
- ▌
- ▌
- ▌ Cis Docker 7 9 · cyberstrikeusEnsure that management plane traffic is separated from data plane traffic
- ▌ T1404 Exploitation For Privilege Escalation · cyberstrikeusAdversaries may exploit software vulnerabilities in order to elevate privileges.
- ▌ T1406 Obfuscated Files Or Information · cyberstrikeusAdversaries may attempt to make a payload or file difficult to discover or analyze by encrypting, encoding, or otherwise obfuscating its contents on the device or in transit.
- ▌ T1629 001 Prevent Application Removal · cyberstrikeusAdversaries may abuse the Android device administration API to prevent the user from uninstalling a target application.
- ▌ T1521 002 Asymmetric Cryptography · cyberstrikeusAdversaries may employ a known asymmetric encryption algorithm to conceal command and control traffic, rather than relying on any inherent protections provided by a communication protocol.
- ▌ T1548 Abuse Elevation Control Mechanism · cyberstrikeusAdversaries may circumvent mechanisms designed to control elevate privileges to gain higher-level permissions.
- ▌ Access Control For Mobile Devices 03 01 18 Access Control Fo · cyberstrikeusEstablish usage restrictions, configuration requirements, and connection requirements for mobile devices.
- ▌ Least Privilege Privileged Functions 03 01 07 Least Privileg · cyberstrikeusPrevent non-privileged users from executing privileged functions.
- ▌
- ▌ Use Of External Systems 03 01 20 Use Of External Systems · cyberstrikeusProhibit the use of external systems unless the systems are specifically authorized.
- ▌ Information Location 03 04 11 Information Location · cyberstrikeusIdentify and document the location of CUI and the system components on which the information is processed and stored.
- ▌
- ▌ Define Security Requirements For Software Development Po 1 D · cyberstrikeusEnsure that security requirements for software development are known at all times so that they can be taken into account throughout the SDLC and du...
- ▌ Au 12 4 Query Parameter Audits Of Personally Identifiable In · cyberstrikeusProvide and implement the capability for auditing the parameters of user query events for data sets containing personally identifiable information.
- ▌
- ▌
- ▌ Au 9 2 Store On Separate Physical Systems Or Components · cyberstrikeusStore audit records [organization-defined] in a repository that is part of a physically different system or system component than the system or compon
- ▌ Au 9 1 Hardware Write Once Media · cyberstrikeusWrite audit trails to hardware-enforced, write-once media.
- ▌ Ca 2 1 Independent Assessors · cyberstrikeusEmploy independent assessors or assessment teams to conduct control assessments.
- ▌ Cm 10 Software Usage Restrictions · cyberstrikeusUse software and associated documentation in accordance with contract agreements and copyright laws;
- ▌ Cm 11 3 Automated Enforcement And Monitoring · cyberstrikeusEnforce and monitor compliance with software installation policies using [organization-defined].
- ▌ Cm 3 Configuration Change Control · cyberstrikeusDetermine and document the types of changes to the system that are configuration-controlled;
- ▌
- ▌ Cm 7 6 Confined Environments With Limited Privileges · cyberstrikeusRequire that the following user-installed software execute in a confined physical or virtual machine environment with limited privileges: [organizatio
- ▌ Cm 7 2 Prevent Program Execution · cyberstrikeusPrevent program execution in accordance with [organization-defined].
- ▌
- ▌ Cp 13 Alternative Security Mechanisms · cyberstrikeusEmploy [organization-defined] for satisfying [organization-defined] when the primary means of implementing the security function is unavailable or com
- ▌ Cp 2 1 Coordinate With Related Plans · cyberstrikeusCoordinate contingency plan development with organizational elements responsible for related plans.