← all publishers

cyberstrikeus

@cyberstrikeus source repo

7171 published skills · page 39 of 72

  1. Cp 7 5 Equivalent Information Security Safeguards · cyberstrikeus
    Equivalent Information Security Safeguards
    0 installs
  2. Cp 8 1 Priority Of Service Provisions · cyberstrikeus
    Develop primary and alternate telecommunications service agreements that contain priority-of-service provisions in accordance with availability req...
    0 installs
  3. Cp 9 7 Dual Authorization For Deletion Or Destruction · cyberstrikeus
    Enforce dual authorization for the deletion or destruction of [organization-defined].
    0 installs
  4. Ia 13 3 Token Management · cyberstrikeus
    In accordance with [organization-defined], assertions and access tokens are: generated; issued; refreshed; revoked; time-restricted; and audience-rest
    0 installs
  5. Pe 11 Emergency Power · cyberstrikeus
    Provide an uninterruptible power supply to facilitate [organization-defined] in the event of a primary power source loss.
    0 installs
  6. Pe 13 Fire Protection · cyberstrikeus
    Employ and maintain fire detection and suppression systems that are supported by an independent energy source.
    0 installs
  7. Pe 3 1 System Access · cyberstrikeus
    Enforce physical access authorizations to the system in addition to the physical access controls for the facility at [organization-defined].
    0 installs
  8. Pt 6 2 Exemption Rules · cyberstrikeus
    Review all Privacy Act exemptions claimed for the system of records at [organization-defined] to ensure they remain appropriate and necessary in accor
    0 installs
  9. Sa 10 4 Trusted Generation · cyberstrikeus
    Require the developer of the system, system component, or system service to employ tools for comparing newly generated versions of security-relevant h
    0 installs
  10. Sa 11 2 Threat Modeling And Vulnerability Analyses · cyberstrikeus
    Require the developer of the system, system component, or system service to perform threat modeling and vulnerability analyses during development and
    0 installs
  11. Sa 12 5 Limitation Of Harm · cyberstrikeus
    Limitation of Harm
    0 installs
  12. Sa 15 4 Threat Modeling And Vulnerability Analysis · cyberstrikeus
    Threat Modeling and Vulnerability Analysis
    0 installs
  13. Sa 15 8 Reuse Of Threat And Vulnerability Information · cyberstrikeus
    Require the developer of the system, system component, or system service to use threat modeling and vulnerability analyses from similar systems, compo
    0 installs
  14. Sa 19 3 Component Disposal · cyberstrikeus
    Component Disposal
    0 installs
  15. Sa 8 10 Hierarchical Trust · cyberstrikeus
    Implement the security design principle of hierarchical trust in [organization-defined].
    0 installs
  16. Sa 8 8 Secure Evolvability · cyberstrikeus
    Implement the security design principle of secure evolvability in [organization-defined].
    0 installs
  17. Sa 9 1 Risk Assessments And Organizational Approvals · cyberstrikeus
    Conduct an organizational assessment of risk prior to the acquisition or outsourcing of information security services;
    0 installs
  18. Si 1 Policy And Procedures · cyberstrikeus
    Develop, document, and disseminate to [organization-defined]: [organization-defined] system and information integrity policy that: Procedures to facil
    0 installs
  19. Si 17 Fail Safe Procedures · cyberstrikeus
    Implement the indicated fail-safe procedures when the indicated failures occur: [organization-defined].
    0 installs
  20. Si 2 1 Central Management · cyberstrikeus
    Central Management
    0 installs
  21. Si 3 1 Central Management · cyberstrikeus
    Central Management
    0 installs
  22. Si 8 1 Central Management · cyberstrikeus
    Central Management
    0 installs
  23. Sr 10 Inspection Of Systems Or Components · cyberstrikeus
    Inspect the following systems or system components [organization-defined] to detect tampering: [organization-defined].
    0 installs
  24. Cis Docker 1 1 1 · cyberstrikeus
    Ensure a separate partition for containers has been created
    0 installs
  25. Cis Docker 1 1 2 · cyberstrikeus
    Ensure only trusted users are allowed to control Docker daemon
    0 installs
  26. Cis Docker 1 1 3 · cyberstrikeus
    Ensure auditing is configured for the Docker daemon
    0 installs
  27. Cis Docker 1 1 4 · cyberstrikeus
    Ensure auditing is configured for Docker files and directories - /run/containerd
    0 installs
  28. Cis Docker 1 1 5 · cyberstrikeus
    Ensure auditing is configured for Docker files and directories - /var/lib/docker
    0 installs
  29. Cis Docker 1 1 6 · cyberstrikeus
    Ensure auditing is configured for Docker files and directories - /etc/docker
    0 installs
  30. Cis Docker 1 1 7 · cyberstrikeus
    Ensure auditing is configured for Docker files and directories - docker.service
    0 installs
  31. Cis Docker 1 1 8 · cyberstrikeus
    Ensure auditing is configured for Docker files and directories - containerd.sock
    0 installs
  32. Cis Docker 1 1 9 · cyberstrikeus
    Ensure auditing is configured for Docker files and directories - docker.sock
    0 installs
  33. Cis Docker 1 2 1 · cyberstrikeus
    Ensure the container host has been Hardened
    0 installs
  34. Cis Docker 1 2 2 · cyberstrikeus
    Ensure that the version of Docker is up to date
    0 installs
  35. Cis Nginx V300 3 1 · cyberstrikeus
    Ensure detailed logging is enabled (Manual)
    0 installs
  36. Cis Nginx V300 3 2 · cyberstrikeus
    Ensure access logging is enabled (Manual)
    0 installs
  37. Cis Nginx V300 3 3 · cyberstrikeus
    Ensure error logging is enabled and set to the info logging level (Manual)
    0 installs
  38. Cis Nginx V300 3 4 · cyberstrikeus
    Ensure proxies pass source IP information (Manual)
    0 installs
  39. T1634 Credentials From Password Store · cyberstrikeus
    Adversaries may search common password storage locations to obtain user credentials.
    0 installs
  40. Baseline Configuration 03 04 01 Baseline Configuration · cyberstrikeus
    Develop and maintain under configuration control, a current baseline configuration of the system.
    0 installs
  41. Configuration Settings 03 04 02 Configuration Settings · cyberstrikeus
    Establish, document, and implement the following configuration settings for the system that reflect the most restrictive mode consistent with opera...
    0 installs
  42. Personnel Termination And Transfer 03 09 02 Personnel Termin · cyberstrikeus
    When individual employment is terminated: Disable system access within [organization-defined], Terminate or revoke authenticators and credentials asso
    0 installs
  43. Risk Assessment 03 11 01 Risk Assessment · cyberstrikeus
    Assess the risk (including supply chain risk) of unauthorized disclosure resulting from the processing, storage, or transmission of CUI.
    0 installs
  44. At 2 3 Social Engineering And Mining · cyberstrikeus
    Provide literacy training on recognizing and reporting potential and actual instances of social engineering and social mining.
    0 installs
  45. Au 13 3 Unauthorized Replication Of Information · cyberstrikeus
    Employ discovery techniques, processes, and tools to determine if external entities are replicating organizational information in an unauthorized mann
    0 installs
  46. Au 14 2 Capture And Record Content · cyberstrikeus
    Capture and Record Content
    0 installs
  47. Au 2 1 Compilation Of Audit Records From Multiple Sources · cyberstrikeus
    Compilation of Audit Records from Multiple Sources
    0 installs
  48. Cis K8S V1120 4 1 7 · cyberstrikeus
    Ensure that the certificate authorities file permissions are set to 644 or more restrictive (Manual)
    0 installs
  49. Cis K8S V1120 4 1 8 · cyberstrikeus
    Ensure that the client certificate authorities file ownership is set to root:root (Manual)
    0 installs
  50. Cis K8S V1120 4 1 9 · cyberstrikeus
    If the kubelet config.yaml configuration file is being used validate permissions set to 600 or more restrictive (Automated)
    0 installs
  51. Cis K8S V1120 4 2 1 · cyberstrikeus
    Ensure that the --anonymous-auth argument is set to false (Automated)
    2 installs
  52. Cis K8S V1120 4 2 2 · cyberstrikeus
    Ensure that the --authorization-mode argument is not set to AlwaysAllow (Automated)
    0 installs
  53. Cis K8S V1120 4 2 3 · cyberstrikeus
    Ensure that the --client-ca-file argument is set as appropriate (Automated)
    0 installs
  54. Cis K8S V1120 4 2 4 · cyberstrikeus
    Verify that if defined, readOnlyPort is set to 0 (Manual)
    0 installs
  55. Cis K8S V1120 4 2 5 · cyberstrikeus
    Ensure that the --streaming-connection-idle-timeout argument is not set to 0 (Manual)
    0 installs
  56. Cis K8S V1120 4 2 6 · cyberstrikeus
    Ensure that the --make-iptables-util-chains argument is set to true (Automated)
    0 installs
  57. Cis K8S V1120 4 2 7 · cyberstrikeus
    Ensure that the --hostname-override argument is not set (Manual)
    0 installs
  58. Cis K8S V1120 4 2 8 · cyberstrikeus
    Ensure that the eventRecordQPS argument is set to a level which ensures appropriate event capture (Manual)
    0 installs
  59. Cis K8S V1120 4 2 9 · cyberstrikeus
    Ensure that the --tls-cert-file and --tls-private-key-file arguments are set as appropriate (Manual)
    0 installs
  60. Cis K8S V1120 4 3 1 · cyberstrikeus
    Ensure that the kube-proxy metrics service is bound to localhost (Manual)
    0 installs
  61. Cis K8S V1120 5 1 1 · cyberstrikeus
    Ensure that the cluster-admin role is only used where required (Manual)
    0 installs
  62. Cis K8S V1120 5 1 2 · cyberstrikeus
    Minimize access to secrets (Manual)
    0 installs
  63. Cis K8S V1120 5 1 3 · cyberstrikeus
    Minimize wildcard use in Roles and ClusterRoles (Manual)
    0 installs
  64. Cis K8S V1120 5 1 4 · cyberstrikeus
    Minimize access to create pods (Manual)
    0 installs
  65. Cis K8S V1120 5 1 5 · cyberstrikeus
    Ensure that default service accounts are not actively used (Manual)
    0 installs
  66. Cis K8S V1120 5 1 6 · cyberstrikeus
    Ensure that Service Account Tokens are only mounted where necessary (Manual)
    0 installs
  67. Cis K8S V1120 5 1 7 · cyberstrikeus
    Avoid use of system:masters group (Manual)
    0 installs
  68. Cis K8S V1120 5 1 8 · cyberstrikeus
    Limit use of the Bind, Impersonate and Escalate permissions in the Kubernetes cluster (Manual)
    0 installs
  69. Cis K8S V1120 5 1 9 · cyberstrikeus
    Minimize access to create persistent volumes (Manual)
    0 installs
  70. Cis K8S V1120 5 2 1 · cyberstrikeus
    Ensure that the cluster has at least one active policy control mechanism in place (Manual)
    0 installs
  71. Cis K8S V1120 5 2 2 · cyberstrikeus
    Minimize the admission of privileged containers (Manual)
    0 installs
  72. Cis K8S V1120 5 2 3 · cyberstrikeus
    Minimize the admission of containers wishing to share the host process ID namespace (Manual)
    0 installs
  73. Cis K8S V1120 5 2 4 · cyberstrikeus
    Minimize the admission of containers wishing to share the host IPC namespace (Manual)
    0 installs
  74. Cis K8S V1120 5 2 5 · cyberstrikeus
    Minimize the admission of containers wishing to share the host network namespace (Manual)
    0 installs
  75. Cis K8S V1120 5 2 6 · cyberstrikeus
    Minimize the admission of containers with allowPrivilegeEscalation (Manual)
    0 installs
  76. Cis K8S V1120 5 2 7 · cyberstrikeus
    Minimize the admission of root containers (Manual)
    0 installs
  77. Cis K8S V1120 5 2 8 · cyberstrikeus
    Minimize the admission of containers with the NET_RAW capability (Manual)
    0 installs
  78. Cis K8S V1120 5 2 9 · cyberstrikeus
    Minimize the admission of containers with capabilities assigned (Manual)
    2 installs
  79. Cis K8S V1120 5 3 1 · cyberstrikeus
    Ensure that the CNI in use supports Network Policies (Manual)
    2 installs
  80. Cis K8S V1120 5 3 2 · cyberstrikeus
    Ensure that all Namespaces have Network Policies defined (Manual)
    0 installs
  81. Cis K8S V1120 5 4 1 · cyberstrikeus
    Prefer using secrets as files over secrets as environment variables (Manual)
    0 installs
  82. Cis K8S V1120 5 4 2 · cyberstrikeus
    Consider external secret storage (Manual)
    0 installs
  83. Cis K8S V1120 5 5 1 · cyberstrikeus
    Configure Image Provenance using ImagePolicyWebhook admission controller (Manual)
    0 installs
  84. Cis K8S V1120 5 6 1 · cyberstrikeus
    Create administrative boundaries between resources using namespaces (Manual)
    0 installs
  85. Cis K8S V1120 5 6 2 · cyberstrikeus
    Ensure that the seccomp profile is set to docker/default in your pod definitions (Manual)
    0 installs
  86. Cis K8S V1120 5 6 3 · cyberstrikeus
    Apply Security Context to Your Pods and Containers (Manual)
    0 installs
  87. Cis K8S V1120 5 6 4 · cyberstrikeus
    The default namespace should not be used (Manual)
    0 installs
  88. Supply Chain Requirements And Processes 03 17 03 Supply Chai · cyberstrikeus
    Establish a process for identifying and addressing weaknesses or deficiencies in the supply chain elements and processes.
    0 installs
  89. Supply Chain Risk Management Plan 03 17 01 Supply Chain Risk · cyberstrikeus
    Develop a plan for managing supply chain risks associated with the research and development, design, manufacturing, acquisition, delivery, integrat...
    0 installs
  90. Ia 2 Identification And Authentication Organizational Users · cyberstrikeus
    Uniquely identify and authenticate organizational users and associate that unique identification with processes acting on behalf of those users.
    0 installs
  91. Ia 2 11 Remote Access Separate Device · cyberstrikeus
    Remote Access — Separate Device
    0 installs
  92. Ia 2 12 Acceptance Of Piv Credentials · cyberstrikeus
    Accept and electronically verify Personal Identity Verification-compliant credentials.
    0 installs
  93. Ia 4 1 Prohibit Account Identifiers As Public Identifiers · cyberstrikeus
    Prohibit the use of system account identifiers that are the same as public identifiers for individual accounts.
    0 installs
  94. Ia 8 Identification And Authentication Non Organizational Us · cyberstrikeus
    Uniquely identify and authenticate non-organizational users or processes acting on behalf of non-organizational users.
    0 installs
  95. Ia 8 3 Use Of Ficam Approved Products · cyberstrikeus
    Use of FICAM-approved Products
    0 installs
  96. Pe 14 2 Monitoring With Alarms And Notifications · cyberstrikeus
    Employ environmental control monitoring that provides an alarm or notification of changes potentially harmful to personnel or equipment to [organizati
    0 installs
  97. Pe 2 1 Access By Position Or Role · cyberstrikeus
    Authorize physical access to the facility where the system resides based on position or role.
    0 installs
  98. Pe 2 3 Restrict Unescorted Access · cyberstrikeus
    Restrict unescorted access to the facility where the system resides to personnel with [organization-defined].
    0 installs
  99. Pe 9 2 Automatic Voltage Controls · cyberstrikeus
    Employ automatic voltage controls for [organization-defined].
    0 installs
  100. Pt 2 Authority To Process Personally Identifiable Informatio · cyberstrikeus
    Determine and document the [organization-defined] that permits the [organization-defined] of personally identifiable information;
    0 installs