cyberstrikeus
- 7.2k skills
- 0 followers
- 2 days ago last updated
- ▌
- ▌
- ▌ Cis AWS Database 9 11 · cyberstrikeusEnsure Neptune DB instances are deployed across multiple Availability Zones (AZs)
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌ Cis K8S V1110 1 1 10 · cyberstrikeusEnsure that the Container Network Interface file ownership is set to root:root (Manual)
- ▌ Cis K8S V1110 1 1 11 · cyberstrikeusEnsure that the etcd data directory permissions are set to 700 or more restrictive (Automated)
- ▌ Cis K8S V1110 1 1 12 · cyberstrikeusEnsure that the etcd data directory ownership is set to etcd:etcd (Automated)
- ▌ Cis K8S V1110 1 1 13 · cyberstrikeusEnsure that the default administrative credential file permissions are set to 600 (Automated)
- ▌ Cis K8S V1110 1 1 14 · cyberstrikeusEnsure that the default administrative credential file ownership is set to root:root (Automated)
- ▌ Cis K8S V1110 1 1 15 · cyberstrikeusEnsure that the scheduler.conf file permissions are set to 600 or more restrictive (Automated)
- ▌ Cis K8S V1110 1 1 16 · cyberstrikeusEnsure that the scheduler.conf file ownership is set to root:root (Automated)
- ▌ Cis K8S V1110 1 1 17 · cyberstrikeusEnsure that the controller-manager.conf file permissions are set to 600 or more restrictive (Automated)
- ▌ Cis K8S V1110 1 1 18 · cyberstrikeusEnsure that the controller-manager.conf file ownership is set to root:root (Automated)
- ▌ Cis K8S V1110 1 1 19 · cyberstrikeusEnsure that the Kubernetes PKI directory and file ownership is set to root:root (Automated)
- ▌ Cis K8S V1110 1 1 20 · cyberstrikeusEnsure that the Kubernetes PKI certificate file permissions are set to 644 or more restrictive (Manual)
- ▌ Cis K8S V1110 1 1 21 · cyberstrikeusEnsure that the Kubernetes PKI key file permissions are set to 600 (Manual)
- ▌ Cis K8S V1110 1 2 29 · cyberstrikeusEnsure that the API Server only makes use of Strong Cryptographic Ciphers (Manual)
- ▌ Cis K8S V1110 1 2 30 · cyberstrikeusEnsure that the --service-account-extend-token-expiration parameter is set to false (Automated)
- ▌ Cis K8S V1110 4 1 10 · cyberstrikeusIf the kubelet config.yaml configuration file is being used validate file ownership is set to root:root (Automated)
- ▌ Cis K8S V1110 4 2 10 · cyberstrikeusEnsure that the --rotate-certificates argument is not set to false (Automated)
- ▌ Cis K8S V1110 4 2 11 · cyberstrikeusVerify that the RotateKubeletServerCertificate argument is set to true (Manual)
- ▌ Cis K8S V1110 4 2 12 · cyberstrikeusEnsure that the Kubelet only makes use of Strong Cryptographic Ciphers (Manual)
- ▌
- ▌ Cis K8S V1110 4 2 14 · cyberstrikeusEnsure that the --seccomp-default parameter is set to true (Manual)
- ▌
- ▌ Cis K8S V1110 5 2 10 · cyberstrikeusMinimize the admission of containers with capabilities assigned (Manual)
- ▌ Cis K8S V1110 5 2 11 · cyberstrikeusMinimize the admission of Windows HostProcess Containers (Manual)
- ▌
- ▌ Cis K8S V1110 5 2 13 · cyberstrikeusMinimize the admission of containers which use HostPorts (Manual)
- ▌ Cis K8S V1111 1 1 10 · cyberstrikeusEnsure that the Container Network Interface file ownership is set to root:root (Manual)
- ▌ Cis K8S V1111 1 1 11 · cyberstrikeusEnsure that the etcd data directory permissions are set to 700 or more restrictive (Automated)
- ▌ Cis K8S V1111 1 1 12 · cyberstrikeusEnsure that the etcd data directory ownership is set to etcd:etcd (Automated)
- ▌ Cis K8S V1111 1 1 13 · cyberstrikeusEnsure that the default administrative credential file permissions are set to 600 (Automated)
- ▌ Cis K8S V1111 1 1 14 · cyberstrikeusEnsure that the default administrative credential file ownership is set to root:root (Automated)
- ▌ Cis K8S V1111 1 1 15 · cyberstrikeusEnsure that the scheduler.conf file permissions are set to 600 or more restrictive (Automated)
- ▌ Cis K8S V1111 1 1 16 · cyberstrikeusEnsure that the scheduler.conf file ownership is set to root:root (Automated)
- ▌ Cis K8S V1111 1 1 17 · cyberstrikeusEnsure that the controller-manager.conf file permissions are set to 600 or more restrictive (Automated)
- ▌ Si 7 2 Automated Notifications Of Integrity Violations · cyberstrikeusEmploy automated tools that provide notification to [organization-defined] upon discovering discrepancies during integrity verification.
- ▌ Sr 5 2 Assessments Prior To Selection Acceptance Modificatio · cyberstrikeusAssess the system, system component, or system service prior to selection, acceptance, modification, or update.
- ▌ Sr 5 Acquisition Strategies Tools And Methods · cyberstrikeusEmploy the following acquisition strategies, contract tools, and procurement methods to protect against, identify, and mitigate supply chain risks: [o
- ▌ Sr 6 Supplier Assessments And Reviews · cyberstrikeusAssess and review the supply chain-related risks associated with suppliers or contractors and the system, system component, or system service they pro
- ▌ Sr 7 Supply Chain Operations Security · cyberstrikeusEmploy the following Operations Security (OPSEC) controls to protect supply chain-related information for the system, system component, or system serv
- ▌ Boundary Protection 03 13 01 Boundary Protection · cyberstrikeusMonitor and control communications at external managed interfaces to the system and key internal managed interfaces within the system.
- ▌
- ▌ Audit Record Generation 03 03 03 Audit Record Generation · cyberstrikeusGenerate audit records for the selected event types and audit record content specified in 03.03.01 and 03.03.02.
- ▌ Event Logging 03 03 01 Event Logging · cyberstrikeusSpecify the following event types selected for logging within the system: [organization-defined].
- ▌ Authorized Software Allow By Exception 03 04 08 Authorized S · cyberstrikeusIdentify software programs authorized to execute on the system.
- ▌ System And Component Configuration For High Risk Areas 03 04 · cyberstrikeusIssue systems or system components with the following configurations to individuals traveling to high-risk locations: [organization-defined].
- ▌ Flaw Remediation 03 14 01 Flaw Remediation · cyberstrikeusIdentify, report, and correct system flaws.
- ▌ Security Alerts Advisories And Directives 03 14 03 Security · cyberstrikeusReceive system security alerts, advisories, and directives from external organizations on an ongoing basis.
- ▌ Reuse Existing Well Secured Software When Feasible Instead O · cyberstrikeusLower the costs of software development, expedite software development, and decrease the likelihood of introducing additional security vulnerabilit...
- ▌ Review And Or Analyze Human Readable Code To Identify Vulner · cyberstrikeusHelp identify vulnerabilities so that they can be corrected before the software is released to prevent exploitation.
- ▌ Review The Software Design To Verify Compliance With Securit · cyberstrikeusHelp ensure that the software will meet the security requirements and satisfactorily address the identified risk information.
- ▌ Identify And Confirm Vulnerabilities On An Ongoing Basis Rv · cyberstrikeusHelp ensure that vulnerabilities are identified more quickly so that they can be remediated more quickly in accordance with risk, reducing the window
- ▌ Ca 3 5 Restrictions On External System Connections · cyberstrikeusRestrictions on External System Connections
- ▌
- ▌ Ca 5 1 Automation Support For Accuracy And Currency · cyberstrikeusEnsure the accuracy, currency, and availability of the plan of action and milestones for the system using [organization-defined].
- ▌ Ca 8 1 Independent Penetration Testing Agent Or Team · cyberstrikeusEmploy an independent penetration testing agent or team to perform penetration testing on the system or system components.
- ▌ Ia 12 6 Accept Externally Proofed Identities · cyberstrikeusAccept externally-proofed identities at [organization-defined].
- ▌ Ia 12 1 Supervisor Authorization · cyberstrikeusRequire that the registration process to receive an account for logical access includes supervisor or sponsor authorization.
- ▌
- ▌ Ia 5 15 Gsa Approved Products And Services · cyberstrikeusUse only General Services Administration-approved products and services for identity, credential, and access management.
- ▌
- ▌ Pe 15 Water Damage Protection · cyberstrikeusProtect the system from damage resulting from water leakage by providing master shutoff or isolation valves that are accessible, working properly, and
- ▌ Pt 7 1 Social Security Numbers · cyberstrikeusWhen a system processes Social Security numbers: Eliminate unnecessary collection, maintenance, and use of Social Security numbers, and explore altern
- ▌ Sa 11 3 Independent Verification Of Assessment Plans And Evi · cyberstrikeusRequire an independent agent satisfying [organization-defined] to verify the correct implementation of the developer security and privacy assessmen...
- ▌ Sa 11 7 Verify Scope Of Testing And Evaluation · cyberstrikeusRequire the developer of the system, system component, or system service to verify that the scope of testing and evaluation provides complete coverage
- ▌
- ▌ Sa 14 1 Critical Components With No Viable Alternative Sourc · cyberstrikeusCritical Components with No Viable Alternative Sourcing
- ▌ Sa 17 5 Conceptually Simple Design · cyberstrikeusRequire the developer of the system, system component, or system service to: Design and structure the security-relevant hardware, software, and firmwa
- ▌ Sa 22 Unsupported System Components · cyberstrikeusReplace system components when support for the components is no longer available from the developer, vendor, or manufacturer;
- ▌ Sa 4 5 System Component And Service Configurations · cyberstrikeusRequire the developer of the system, system component, or system service to: Deliver the system, component, or service with [organization-defined] imp
- ▌ Sa 4 6 Use Of Information Assurance Products · cyberstrikeusEmploy only government off-the-shelf or commercial off-the-shelf information assurance and information assurance-enabled information technology pro...
- ▌ Sa 8 20 Secure Metadata Management · cyberstrikeusImplement the security design principle of secure metadata management in [organization-defined].
- ▌ Sa 8 31 Secure System Modification · cyberstrikeusImplement the security design principle of secure system modification in [organization-defined].
- ▌ Sa 8 5 Efficiently Mediated Access · cyberstrikeusImplement the security design principle of efficiently mediated access in [organization-defined].
- ▌ Sa 9 3 Establish And Maintain Trust Relationship With Provid · cyberstrikeusEstablish, document, and maintain trust relationships with external service providers based on the following requirements, properties, factors, or con
- ▌
- ▌ Sc 16 3 Cryptographic Binding · cyberstrikeusImplement [organization-defined] to bind security and privacy attributes to transmitted information.
- ▌ Sc 40 Wireless Link Protection · cyberstrikeusProtect external and internal [organization-defined] from the following signal parameter attacks: [organization-defined].
- ▌ Sc 7 12 Host Based Protection · cyberstrikeusImplement [organization-defined] at [organization-defined].
- ▌ Si 10 Information Input Validation · cyberstrikeusCheck the validity of the following information inputs: [organization-defined].
- ▌ Si 10 5 Restrict Inputs To Trusted Sources And Approved Form · cyberstrikeusRestrict the use of information inputs to [organization-defined] and/or [organization-defined].
- ▌ Si 10 2 Review And Resolve Errors · cyberstrikeusReview and resolve input validation errors within [organization-defined].
- ▌ Si 15 Information Output Filtering · cyberstrikeusValidate information output from the following software programs and/or applications to ensure that the information is consistent with the expected co
- ▌ Si 19 4 Removal Masking Encryption Hashing Or Replacement Of · cyberstrikeusRemove, mask, encrypt, hash, or replace direct identifiers in a dataset.
- ▌ Si 2 3 Time To Remediate Flaws And Benchmarks For Corrective · cyberstrikeusMeasure the time between flaw identification and flaw remediation;
- ▌ Si 4 18 Analyze Traffic And Covert Exfiltration · cyberstrikeusAnalyze outbound communications traffic at external interfaces to the system and at the following interior points to detect covert exfiltration of inf
- ▌ Si 6 Security And Privacy Function Verification · cyberstrikeusVerify the correct operation of [organization-defined];
- ▌ Si 7 11 Confined Environments With Limited Privileges · cyberstrikeusConfined Environments with Limited Privileges