cyberstrikeus
- 7.2k skills
- 0 followers
- 2 days ago last updated
- ▌ Cp 7 5 Equivalent Information Security Safeguards · cyberstrikeusEquivalent Information Security Safeguards
- ▌ Cp 8 1 Priority Of Service Provisions · cyberstrikeusDevelop primary and alternate telecommunications service agreements that contain priority-of-service provisions in accordance with availability req...
- ▌ Cp 9 7 Dual Authorization For Deletion Or Destruction · cyberstrikeusEnforce dual authorization for the deletion or destruction of [organization-defined].
- ▌ Ia 13 3 Token Management · cyberstrikeusIn accordance with [organization-defined], assertions and access tokens are: generated; issued; refreshed; revoked; time-restricted; and audience-rest
- ▌ Pe 11 Emergency Power · cyberstrikeusProvide an uninterruptible power supply to facilitate [organization-defined] in the event of a primary power source loss.
- ▌ Pe 13 Fire Protection · cyberstrikeusEmploy and maintain fire detection and suppression systems that are supported by an independent energy source.
- ▌ Pe 3 1 System Access · cyberstrikeusEnforce physical access authorizations to the system in addition to the physical access controls for the facility at [organization-defined].
- ▌ Pt 6 2 Exemption Rules · cyberstrikeusReview all Privacy Act exemptions claimed for the system of records at [organization-defined] to ensure they remain appropriate and necessary in accor
- ▌ Sa 10 4 Trusted Generation · cyberstrikeusRequire the developer of the system, system component, or system service to employ tools for comparing newly generated versions of security-relevant h
- ▌ Sa 11 2 Threat Modeling And Vulnerability Analyses · cyberstrikeusRequire the developer of the system, system component, or system service to perform threat modeling and vulnerability analyses during development and
- ▌
- ▌ Sa 15 4 Threat Modeling And Vulnerability Analysis · cyberstrikeusThreat Modeling and Vulnerability Analysis
- ▌ Sa 15 8 Reuse Of Threat And Vulnerability Information · cyberstrikeusRequire the developer of the system, system component, or system service to use threat modeling and vulnerability analyses from similar systems, compo
- ▌
- ▌ Sa 8 10 Hierarchical Trust · cyberstrikeusImplement the security design principle of hierarchical trust in [organization-defined].
- ▌ Sa 8 8 Secure Evolvability · cyberstrikeusImplement the security design principle of secure evolvability in [organization-defined].
- ▌ Sa 9 1 Risk Assessments And Organizational Approvals · cyberstrikeusConduct an organizational assessment of risk prior to the acquisition or outsourcing of information security services;
- ▌ Si 1 Policy And Procedures · cyberstrikeusDevelop, document, and disseminate to [organization-defined]: [organization-defined] system and information integrity policy that: Procedures to facil
- ▌ Si 17 Fail Safe Procedures · cyberstrikeusImplement the indicated fail-safe procedures when the indicated failures occur: [organization-defined].
- ▌
- ▌
- ▌
- ▌ Sr 10 Inspection Of Systems Or Components · cyberstrikeusInspect the following systems or system components [organization-defined] to detect tampering: [organization-defined].
- ▌
- ▌
- ▌
- ▌ Cis Docker 1 1 4 · cyberstrikeusEnsure auditing is configured for Docker files and directories - /run/containerd
- ▌ Cis Docker 1 1 5 · cyberstrikeusEnsure auditing is configured for Docker files and directories - /var/lib/docker
- ▌ Cis Docker 1 1 6 · cyberstrikeusEnsure auditing is configured for Docker files and directories - /etc/docker
- ▌ Cis Docker 1 1 7 · cyberstrikeusEnsure auditing is configured for Docker files and directories - docker.service
- ▌ Cis Docker 1 1 8 · cyberstrikeusEnsure auditing is configured for Docker files and directories - containerd.sock
- ▌ Cis Docker 1 1 9 · cyberstrikeusEnsure auditing is configured for Docker files and directories - docker.sock
- ▌
- ▌
- ▌
- ▌
- ▌ Cis Nginx V300 3 3 · cyberstrikeusEnsure error logging is enabled and set to the info logging level (Manual)
- ▌
- ▌ T1634 Credentials From Password Store · cyberstrikeusAdversaries may search common password storage locations to obtain user credentials.
- ▌ Baseline Configuration 03 04 01 Baseline Configuration · cyberstrikeusDevelop and maintain under configuration control, a current baseline configuration of the system.
- ▌ Configuration Settings 03 04 02 Configuration Settings · cyberstrikeusEstablish, document, and implement the following configuration settings for the system that reflect the most restrictive mode consistent with opera...
- ▌ Personnel Termination And Transfer 03 09 02 Personnel Termin · cyberstrikeusWhen individual employment is terminated: Disable system access within [organization-defined], Terminate or revoke authenticators and credentials asso
- ▌ Risk Assessment 03 11 01 Risk Assessment · cyberstrikeusAssess the risk (including supply chain risk) of unauthorized disclosure resulting from the processing, storage, or transmission of CUI.
- ▌ At 2 3 Social Engineering And Mining · cyberstrikeusProvide literacy training on recognizing and reporting potential and actual instances of social engineering and social mining.
- ▌ Au 13 3 Unauthorized Replication Of Information · cyberstrikeusEmploy discovery techniques, processes, and tools to determine if external entities are replicating organizational information in an unauthorized mann
- ▌
- ▌ Au 2 1 Compilation Of Audit Records From Multiple Sources · cyberstrikeusCompilation of Audit Records from Multiple Sources
- ▌ Cis K8S V1120 4 1 7 · cyberstrikeusEnsure that the certificate authorities file permissions are set to 644 or more restrictive (Manual)
- ▌ Cis K8S V1120 4 1 8 · cyberstrikeusEnsure that the client certificate authorities file ownership is set to root:root (Manual)
- ▌ Cis K8S V1120 4 1 9 · cyberstrikeusIf the kubelet config.yaml configuration file is being used validate permissions set to 600 or more restrictive (Automated)
- ▌ Cis K8S V1120 4 2 1 · cyberstrikeusEnsure that the --anonymous-auth argument is set to false (Automated)
- ▌ Cis K8S V1120 4 2 2 · cyberstrikeusEnsure that the --authorization-mode argument is not set to AlwaysAllow (Automated)
- ▌ Cis K8S V1120 4 2 3 · cyberstrikeusEnsure that the --client-ca-file argument is set as appropriate (Automated)
- ▌
- ▌ Cis K8S V1120 4 2 5 · cyberstrikeusEnsure that the --streaming-connection-idle-timeout argument is not set to 0 (Manual)
- ▌ Cis K8S V1120 4 2 6 · cyberstrikeusEnsure that the --make-iptables-util-chains argument is set to true (Automated)
- ▌ Cis K8S V1120 4 2 7 · cyberstrikeusEnsure that the --hostname-override argument is not set (Manual)
- ▌ Cis K8S V1120 4 2 8 · cyberstrikeusEnsure that the eventRecordQPS argument is set to a level which ensures appropriate event capture (Manual)
- ▌ Cis K8S V1120 4 2 9 · cyberstrikeusEnsure that the --tls-cert-file and --tls-private-key-file arguments are set as appropriate (Manual)
- ▌ Cis K8S V1120 4 3 1 · cyberstrikeusEnsure that the kube-proxy metrics service is bound to localhost (Manual)
- ▌ Cis K8S V1120 5 1 1 · cyberstrikeusEnsure that the cluster-admin role is only used where required (Manual)
- ▌
- ▌
- ▌
- ▌ Cis K8S V1120 5 1 5 · cyberstrikeusEnsure that default service accounts are not actively used (Manual)
- ▌ Cis K8S V1120 5 1 6 · cyberstrikeusEnsure that Service Account Tokens are only mounted where necessary (Manual)
- ▌
- ▌ Cis K8S V1120 5 1 8 · cyberstrikeusLimit use of the Bind, Impersonate and Escalate permissions in the Kubernetes cluster (Manual)
- ▌
- ▌ Cis K8S V1120 5 2 1 · cyberstrikeusEnsure that the cluster has at least one active policy control mechanism in place (Manual)
- ▌
- ▌ Cis K8S V1120 5 2 3 · cyberstrikeusMinimize the admission of containers wishing to share the host process ID namespace (Manual)
- ▌ Cis K8S V1120 5 2 4 · cyberstrikeusMinimize the admission of containers wishing to share the host IPC namespace (Manual)
- ▌ Cis K8S V1120 5 2 5 · cyberstrikeusMinimize the admission of containers wishing to share the host network namespace (Manual)
- ▌ Cis K8S V1120 5 2 6 · cyberstrikeusMinimize the admission of containers with allowPrivilegeEscalation (Manual)
- ▌
- ▌ Cis K8S V1120 5 2 8 · cyberstrikeusMinimize the admission of containers with the NET_RAW capability (Manual)
- ▌ Cis K8S V1120 5 2 9 · cyberstrikeusMinimize the admission of containers with capabilities assigned (Manual)
- ▌
- ▌ Cis K8S V1120 5 3 2 · cyberstrikeusEnsure that all Namespaces have Network Policies defined (Manual)
- ▌ Cis K8S V1120 5 4 1 · cyberstrikeusPrefer using secrets as files over secrets as environment variables (Manual)
- ▌
- ▌ Cis K8S V1120 5 5 1 · cyberstrikeusConfigure Image Provenance using ImagePolicyWebhook admission controller (Manual)
- ▌ Cis K8S V1120 5 6 1 · cyberstrikeusCreate administrative boundaries between resources using namespaces (Manual)
- ▌ Cis K8S V1120 5 6 2 · cyberstrikeusEnsure that the seccomp profile is set to docker/default in your pod definitions (Manual)
- ▌
- ▌
- ▌ Supply Chain Requirements And Processes 03 17 03 Supply Chai · cyberstrikeusEstablish a process for identifying and addressing weaknesses or deficiencies in the supply chain elements and processes.
- ▌ Supply Chain Risk Management Plan 03 17 01 Supply Chain Risk · cyberstrikeusDevelop a plan for managing supply chain risks associated with the research and development, design, manufacturing, acquisition, delivery, integrat...
- ▌ Ia 2 Identification And Authentication Organizational Users · cyberstrikeusUniquely identify and authenticate organizational users and associate that unique identification with processes acting on behalf of those users.
- ▌
- ▌ Ia 2 12 Acceptance Of Piv Credentials · cyberstrikeusAccept and electronically verify Personal Identity Verification-compliant credentials.
- ▌ Ia 4 1 Prohibit Account Identifiers As Public Identifiers · cyberstrikeusProhibit the use of system account identifiers that are the same as public identifiers for individual accounts.
- ▌ Ia 8 Identification And Authentication Non Organizational Us · cyberstrikeusUniquely identify and authenticate non-organizational users or processes acting on behalf of non-organizational users.
- ▌
- ▌ Pe 14 2 Monitoring With Alarms And Notifications · cyberstrikeusEmploy environmental control monitoring that provides an alarm or notification of changes potentially harmful to personnel or equipment to [organizati
- ▌ Pe 2 1 Access By Position Or Role · cyberstrikeusAuthorize physical access to the facility where the system resides based on position or role.
- ▌ Pe 2 3 Restrict Unescorted Access · cyberstrikeusRestrict unescorted access to the facility where the system resides to personnel with [organization-defined].
- ▌ Pe 9 2 Automatic Voltage Controls · cyberstrikeusEmploy automatic voltage controls for [organization-defined].
- ▌ Pt 2 Authority To Process Personally Identifiable Informatio · cyberstrikeusDetermine and document the [organization-defined] that permits the [organization-defined] of personally identifiable information;