← all publishers

cyberstrikeus

@cyberstrikeus source repo

7171 published skills · page 41 of 72

  1. Cis AWS Database 7 12 · cyberstrikeus
    Ensure DocumentDB has delete protection enabled
    0 installs
  2. Cis AWS Database 9 10 · cyberstrikeus
    Ensure Database has delete protection enabled
    0 installs
  3. Cis AWS Database 9 11 · cyberstrikeus
    Ensure Neptune DB instances are deployed across multiple Availability Zones (AZs)
    0 installs
  4. Cis AWS Storage 2 10 · cyberstrikeus
    Ensure Resource Access via Tag-based Policies
    0 installs
  5. Cis AWS Storage 2 11 · cyberstrikeus
    Ensure Secure Password Policy Implementation
    0 installs
  6. Cis AWS Storage 2 12 · cyberstrikeus
    Ensure Monitoring EC2 and EBS with CloudWatch
    0 installs
  7. Cis AWS Storage 2 13 · cyberstrikeus
    Ensure creating an SNS subscription
    0 installs
  8. Cis AWS Storage 3 10 · cyberstrikeus
    Ensure managing AWS EFS access points
    0 installs
  9. Cis AWS Storage 3 11 · cyberstrikeus
    Ensure accessing Points and IAM Policies for EFS
    0 installs
  10. Cis AWS Storage 3 12 · cyberstrikeus
    Ensure configuring IAM for AWS Elastic Disaster Recovery
    0 installs
  11. Cis AWS Storage 6 10 · cyberstrikeus
    Ensure execution of a Disaster Recovery Failover
    0 installs
  12. Cis AWS Storage 6 11 · cyberstrikeus
    Ensure execution of a failback
    0 installs
  13. Cis AWS Storage 6 12 · cyberstrikeus
    Ensure CloudWatch Metrics for AWS EDR
    0 installs
  14. Cis AWS Storage 6 13 · cyberstrikeus
    Ensure working of EDR
    0 installs
  15. Cis K8S V1110 1 1 10 · cyberstrikeus
    Ensure that the Container Network Interface file ownership is set to root:root (Manual)
    0 installs
  16. Cis K8S V1110 1 1 11 · cyberstrikeus
    Ensure that the etcd data directory permissions are set to 700 or more restrictive (Automated)
    0 installs
  17. Cis K8S V1110 1 1 12 · cyberstrikeus
    Ensure that the etcd data directory ownership is set to etcd:etcd (Automated)
    0 installs
  18. Cis K8S V1110 1 1 13 · cyberstrikeus
    Ensure that the default administrative credential file permissions are set to 600 (Automated)
    0 installs
  19. Cis K8S V1110 1 1 14 · cyberstrikeus
    Ensure that the default administrative credential file ownership is set to root:root (Automated)
    0 installs
  20. Cis K8S V1110 1 1 15 · cyberstrikeus
    Ensure that the scheduler.conf file permissions are set to 600 or more restrictive (Automated)
    0 installs
  21. Cis K8S V1110 1 1 16 · cyberstrikeus
    Ensure that the scheduler.conf file ownership is set to root:root (Automated)
    0 installs
  22. Cis K8S V1110 1 1 17 · cyberstrikeus
    Ensure that the controller-manager.conf file permissions are set to 600 or more restrictive (Automated)
    0 installs
  23. Cis K8S V1110 1 1 18 · cyberstrikeus
    Ensure that the controller-manager.conf file ownership is set to root:root (Automated)
    0 installs
  24. Cis K8S V1110 1 1 19 · cyberstrikeus
    Ensure that the Kubernetes PKI directory and file ownership is set to root:root (Automated)
    0 installs
  25. Cis K8S V1110 1 1 20 · cyberstrikeus
    Ensure that the Kubernetes PKI certificate file permissions are set to 644 or more restrictive (Manual)
    0 installs
  26. Cis K8S V1110 1 1 21 · cyberstrikeus
    Ensure that the Kubernetes PKI key file permissions are set to 600 (Manual)
    0 installs
  27. Cis K8S V1110 1 2 29 · cyberstrikeus
    Ensure that the API Server only makes use of Strong Cryptographic Ciphers (Manual)
    0 installs
  28. Cis K8S V1110 1 2 30 · cyberstrikeus
    Ensure that the --service-account-extend-token-expiration parameter is set to false (Automated)
    0 installs
  29. Cis K8S V1110 4 1 10 · cyberstrikeus
    If the kubelet config.yaml configuration file is being used validate file ownership is set to root:root (Automated)
    0 installs
  30. Cis K8S V1110 4 2 10 · cyberstrikeus
    Ensure that the --rotate-certificates argument is not set to false (Automated)
    0 installs
  31. Cis K8S V1110 4 2 11 · cyberstrikeus
    Verify that the RotateKubeletServerCertificate argument is set to true (Manual)
    0 installs
  32. Cis K8S V1110 4 2 12 · cyberstrikeus
    Ensure that the Kubelet only makes use of Strong Cryptographic Ciphers (Manual)
    0 installs
  33. Cis K8S V1110 4 2 13 · cyberstrikeus
    Ensure that a limit is set on pod PIDs (Manual)
    2 installs
  34. Cis K8S V1110 4 2 14 · cyberstrikeus
    Ensure that the --seccomp-default parameter is set to true (Manual)
    0 installs
  35. Cis K8S V1110 4 2 15 · cyberstrikeus
    Ensure that the --IPAddressDeny is set to any (Manual)
    0 installs
  36. Cis K8S V1110 5 2 10 · cyberstrikeus
    Minimize the admission of containers with capabilities assigned (Manual)
    0 installs
  37. Cis K8S V1110 5 2 11 · cyberstrikeus
    Minimize the admission of Windows HostProcess Containers (Manual)
    0 installs
  38. Cis K8S V1110 5 2 12 · cyberstrikeus
    Minimize the admission of HostPath volumes (Manual)
    0 installs
  39. Cis K8S V1110 5 2 13 · cyberstrikeus
    Minimize the admission of containers which use HostPorts (Manual)
    0 installs
  40. Cis K8S V1111 1 1 10 · cyberstrikeus
    Ensure that the Container Network Interface file ownership is set to root:root (Manual)
    0 installs
  41. Cis K8S V1111 1 1 11 · cyberstrikeus
    Ensure that the etcd data directory permissions are set to 700 or more restrictive (Automated)
    0 installs
  42. Cis K8S V1111 1 1 12 · cyberstrikeus
    Ensure that the etcd data directory ownership is set to etcd:etcd (Automated)
    0 installs
  43. Cis K8S V1111 1 1 13 · cyberstrikeus
    Ensure that the default administrative credential file permissions are set to 600 (Automated)
    0 installs
  44. Cis K8S V1111 1 1 14 · cyberstrikeus
    Ensure that the default administrative credential file ownership is set to root:root (Automated)
    2 installs
  45. Cis K8S V1111 1 1 15 · cyberstrikeus
    Ensure that the scheduler.conf file permissions are set to 600 or more restrictive (Automated)
    0 installs
  46. Cis K8S V1111 1 1 16 · cyberstrikeus
    Ensure that the scheduler.conf file ownership is set to root:root (Automated)
    0 installs
  47. Cis K8S V1111 1 1 17 · cyberstrikeus
    Ensure that the controller-manager.conf file permissions are set to 600 or more restrictive (Automated)
    0 installs
  48. Si 7 2 Automated Notifications Of Integrity Violations · cyberstrikeus
    Employ automated tools that provide notification to [organization-defined] upon discovering discrepancies during integrity verification.
    0 installs
  49. Sr 5 2 Assessments Prior To Selection Acceptance Modificatio · cyberstrikeus
    Assess the system, system component, or system service prior to selection, acceptance, modification, or update.
    0 installs
  50. Sr 5 Acquisition Strategies Tools And Methods · cyberstrikeus
    Employ the following acquisition strategies, contract tools, and procurement methods to protect against, identify, and mitigate supply chain risks: [o
    0 installs
  51. Sr 6 Supplier Assessments And Reviews · cyberstrikeus
    Assess and review the supply chain-related risks associated with suppliers or contractors and the system, system component, or system service they pro
    0 installs
  52. Sr 7 Supply Chain Operations Security · cyberstrikeus
    Employ the following Operations Security (OPSEC) controls to protect supply chain-related information for the system, system component, or system serv
    0 installs
  53. Boundary Protection 03 13 01 Boundary Protection · cyberstrikeus
    Monitor and control communications at external managed interfaces to the system and key internal managed interfaces within the system.
    0 installs
  54. Session Authenticity 03 13 15 Session Authenticity · cyberstrikeus
    Session Authenticity
    0 installs
  55. Audit Record Generation 03 03 03 Audit Record Generation · cyberstrikeus
    Generate audit records for the selected event types and audit record content specified in 03.03.01 and 03.03.02.
    0 installs
  56. Event Logging 03 03 01 Event Logging · cyberstrikeus
    Specify the following event types selected for logging within the system: [organization-defined].
    0 installs
  57. Authorized Software Allow By Exception 03 04 08 Authorized S · cyberstrikeus
    Identify software programs authorized to execute on the system.
    0 installs
  58. System And Component Configuration For High Risk Areas 03 04 · cyberstrikeus
    Issue systems or system components with the following configurations to individuals traveling to high-risk locations: [organization-defined].
    0 installs
  59. Flaw Remediation 03 14 01 Flaw Remediation · cyberstrikeus
    Identify, report, and correct system flaws.
    0 installs
  60. Security Alerts Advisories And Directives 03 14 03 Security · cyberstrikeus
    Receive system security alerts, advisories, and directives from external organizations on an ongoing basis.
    0 installs
  61. Reuse Existing Well Secured Software When Feasible Instead O · cyberstrikeus
    Lower the costs of software development, expedite software development, and decrease the likelihood of introducing additional security vulnerabilit...
    0 installs
  62. Review And Or Analyze Human Readable Code To Identify Vulner · cyberstrikeus
    Help identify vulnerabilities so that they can be corrected before the software is released to prevent exploitation.
    0 installs
  63. Review The Software Design To Verify Compliance With Securit · cyberstrikeus
    Help ensure that the software will meet the security requirements and satisfactorily address the identified risk information.
    0 installs
  64. Identify And Confirm Vulnerabilities On An Ongoing Basis Rv · cyberstrikeus
    Help ensure that vulnerabilities are identified more quickly so that they can be remediated more quickly in accordance with risk, reducing the window
    0 installs
  65. Ca 3 5 Restrictions On External System Connections · cyberstrikeus
    Restrictions on External System Connections
    0 installs
  66. Ca 3 4 Connections To Public Networks · cyberstrikeus
    Connections to Public Networks
    0 installs
  67. Ca 5 1 Automation Support For Accuracy And Currency · cyberstrikeus
    Ensure the accuracy, currency, and availability of the plan of action and milestones for the system using [organization-defined].
    0 installs
  68. Ca 8 1 Independent Penetration Testing Agent Or Team · cyberstrikeus
    Employ an independent penetration testing agent or team to perform penetration testing on the system or system components.
    0 installs
  69. Ia 12 6 Accept Externally Proofed Identities · cyberstrikeus
    Accept externally-proofed identities at [organization-defined].
    0 installs
  70. Ia 12 1 Supervisor Authorization · cyberstrikeus
    Require that the registration process to receive an account for logical access includes supervisor or sponsor authorization.
    0 installs
  71. Ia 2 3 Local Access To Privileged Accounts · cyberstrikeus
    Local Access to Privileged Accounts
    0 installs
  72. Ia 5 15 Gsa Approved Products And Services · cyberstrikeus
    Use only General Services Administration-approved products and services for identity, credential, and access management.
    0 installs
  73. Ia 9 2 Transmission Of Decisions · cyberstrikeus
    Transmission of Decisions
    0 installs
  74. Pe 15 Water Damage Protection · cyberstrikeus
    Protect the system from damage resulting from water leakage by providing master shutoff or isolation valves that are accessible, working properly, and
    0 installs
  75. Pt 7 1 Social Security Numbers · cyberstrikeus
    When a system processes Social Security numbers: Eliminate unnecessary collection, maintenance, and use of Social Security numbers, and explore altern
    0 installs
  76. Sa 11 3 Independent Verification Of Assessment Plans And Evi · cyberstrikeus
    Require an independent agent satisfying [organization-defined] to verify the correct implementation of the developer security and privacy assessmen...
    0 installs
  77. Sa 11 7 Verify Scope Of Testing And Evaluation · cyberstrikeus
    Require the developer of the system, system component, or system service to verify that the scope of testing and evaluation provides complete coverage
    0 installs
  78. Sa 12 14 Identity And Traceability · cyberstrikeus
    Identity and Traceability
    0 installs
  79. Sa 14 1 Critical Components With No Viable Alternative Sourc · cyberstrikeus
    Critical Components with No Viable Alternative Sourcing
    0 installs
  80. Sa 17 5 Conceptually Simple Design · cyberstrikeus
    Require the developer of the system, system component, or system service to: Design and structure the security-relevant hardware, software, and firmwa
    0 installs
  81. Sa 22 Unsupported System Components · cyberstrikeus
    Replace system components when support for the components is no longer available from the developer, vendor, or manufacturer;
    0 installs
  82. Sa 4 5 System Component And Service Configurations · cyberstrikeus
    Require the developer of the system, system component, or system service to: Deliver the system, component, or service with [organization-defined] imp
    0 installs
  83. Sa 4 6 Use Of Information Assurance Products · cyberstrikeus
    Employ only government off-the-shelf or commercial off-the-shelf information assurance and information assurance-enabled information technology pro...
    0 installs
  84. Sa 8 20 Secure Metadata Management · cyberstrikeus
    Implement the security design principle of secure metadata management in [organization-defined].
    0 installs
  85. Sa 8 31 Secure System Modification · cyberstrikeus
    Implement the security design principle of secure system modification in [organization-defined].
    0 installs
  86. Sa 8 5 Efficiently Mediated Access · cyberstrikeus
    Implement the security design principle of efficiently mediated access in [organization-defined].
    0 installs
  87. Sa 9 3 Establish And Maintain Trust Relationship With Provid · cyberstrikeus
    Establish, document, and maintain trust relationships with external service providers based on the following requirements, properties, factors, or con
    0 installs
  88. Sc 13 Cryptographic Protection · cyberstrikeus
    Determine the [organization-defined] ;
    0 installs
  89. Sc 16 3 Cryptographic Binding · cyberstrikeus
    Implement [organization-defined] to bind security and privacy attributes to transmitted information.
    0 installs
  90. Sc 40 Wireless Link Protection · cyberstrikeus
    Protect external and internal [organization-defined] from the following signal parameter attacks: [organization-defined].
    0 installs
  91. Sc 7 12 Host Based Protection · cyberstrikeus
    Implement [organization-defined] at [organization-defined].
    0 installs
  92. Si 10 Information Input Validation · cyberstrikeus
    Check the validity of the following information inputs: [organization-defined].
    0 installs
  93. Si 10 5 Restrict Inputs To Trusted Sources And Approved Form · cyberstrikeus
    Restrict the use of information inputs to [organization-defined] and/or [organization-defined].
    0 installs
  94. Si 10 2 Review And Resolve Errors · cyberstrikeus
    Review and resolve input validation errors within [organization-defined].
    0 installs
  95. Si 15 Information Output Filtering · cyberstrikeus
    Validate information output from the following software programs and/or applications to ensure that the information is consistent with the expected co
    0 installs
  96. Si 19 4 Removal Masking Encryption Hashing Or Replacement Of · cyberstrikeus
    Remove, mask, encrypt, hash, or replace direct identifiers in a dataset.
    0 installs
  97. Si 2 3 Time To Remediate Flaws And Benchmarks For Corrective · cyberstrikeus
    Measure the time between flaw identification and flaw remediation;
    0 installs
  98. Si 4 18 Analyze Traffic And Covert Exfiltration · cyberstrikeus
    Analyze outbound communications traffic at external interfaces to the system and at the following interior points to detect covert exfiltration of inf
    0 installs
  99. Si 6 Security And Privacy Function Verification · cyberstrikeus
    Verify the correct operation of [organization-defined];
    0 installs
  100. Si 7 11 Confined Environments With Limited Privileges · cyberstrikeus
    Confined Environments with Limited Privileges
    0 installs