cyberstrikeus
- 7.2k skills
- 0 followers
- 2 days ago last updated
- ▌ Mp 6 1 Review Approve Track Document And Verify · cyberstrikeusReview, approve, track, document, and verify media sanitization and disposal actions.
- ▌ Pm 11 Mission And Business Process Definition · cyberstrikeusDefine organizational mission and business processes with consideration for information security and privacy and the resulting risk to organization...
- ▌ Pm 30 Supply Chain Risk Management Strategy · cyberstrikeusDevelop an organization-wide strategy for managing supply chain risks associated with the development, acquisition, maintenance, and disposal of sy...
- ▌ Pm 4 Plan Of Action And Milestones Process · cyberstrikeusImplement a process to ensure that plans of action and milestones for the information security, privacy, and supply chain risk management programs and
- ▌ Ra 5 3 Breadth And Depth Of Coverage · cyberstrikeusDefine the breadth and depth of vulnerability scanning coverage.
- ▌
- ▌ Sa 8 33 Minimization · cyberstrikeusImplement the privacy principle of minimization using [organization-defined].
- ▌ Sc 25 Thin Nodes · cyberstrikeusEmploy minimal functionality and information storage on the following system components: [organization-defined].
- ▌ Si 11 Error Handling · cyberstrikeusGenerate error messages that provide information necessary for corrective actions without revealing information that could be exploited;
- ▌ Si 8 Spam Protection · cyberstrikeusEmploy spam protection mechanisms at system entry and exit points to detect and act on unsolicited messages;
- ▌ Sr 12 Component Disposal · cyberstrikeusDispose of [organization-defined] using the following techniques and methods: [organization-defined].
- ▌ T0869 Standard Application Layer Protocol · cyberstrikeusAdversaries may establish command and control capabilities over commonly used application layer protocols such as HTTP(S), OPC, RDP, telnet, DNP3, and modbus.
- ▌ T0866 Exploitation Of Remote Services · cyberstrikeusAdversaries may exploit a software vulnerability to take advantage of a programming error in a program, service, or within the operating system software or kernel itself to enable remote service ab...
- ▌ T1629 003 Disable Or Modify Tools · cyberstrikeusAdversaries may disable security tools to avoid potential detection of their tools and activities.
- ▌ T1422 001 Internet Connection Discovery · cyberstrikeusAdversaries may check for Internet connectivity on compromised systems.
- ▌ T1623 Command And Scripting Interpreter · cyberstrikeusAdversaries may abuse command and script interpreters to execute commands, scripts, or binaries.
- ▌ T1658 Exploitation For Client Execution · cyberstrikeusAdversaries may exploit software vulnerabilities in client applications to execute code.
- ▌ T1055 001 Dynamic Link Library Injection · cyberstrikeusAdversaries may inject dynamic-link libraries (DLLs) into processes in order to evade process-based defenses as well as possibly elevate privileges.
- ▌ T1070 002 Clear Linux Or Mac System Logs · cyberstrikeusAdversaries may clear system logs to hide evidence of an intrusion.
- ▌ T1562 003 Impair Command History Logging · cyberstrikeusAdversaries may impair command history logging to hide commands they run on a compromised system.
- ▌ T1555 Credentials From Password Stores · cyberstrikeusAdversaries may search for common password storage locations to obtain user credentials.
- ▌ T1071 005 Publishsubscribe Protocols · cyberstrikeusAdversaries may communicate using publish/subscribe (pub/sub) application layer protocols to avoid detection/network filtering by blending in with existing traffic.
- ▌ T1095 Non Application Layer Protocol · cyberstrikeusAdversaries may use an OSI non-application layer protocol for communication between host and C2 server or among infected hosts within a network.
- ▌ T1587 002 Code Signing Certificates · cyberstrikeusAdversaries may create self-signed code signing certificates that can be used during targeting.
- ▌ T1588 003 Code Signing Certificates · cyberstrikeusAdversaries may buy and/or steal code signing certificates that can be used during targeting.
- ▌ Transmission And Storage Confidentiality 03 13 08 Transmissi · cyberstrikeusTransmission and Storage Confidentiality
- ▌ Account Management 03 01 01 Account Management · cyberstrikeusDefine the types of system accounts allowed and prohibited.
- ▌ Maintenance Tools 03 07 04 Maintenance Tools · cyberstrikeusApprove, control, and monitor the use of system maintenance tools.
- ▌ Nonlocal Maintenance 03 07 05 Nonlocal Maintenance · cyberstrikeusApprove and monitor nonlocal maintenance and diagnostic activities.
- ▌
- ▌ Ac 17 4 Privileged Commands And Access · cyberstrikeusAuthorize the execution of privileged commands and access to security-relevant information via remote access only in a format that provides assessa...
- ▌ Ac 18 5 Antennas And Transmission Power Levels · cyberstrikeusSelect radio antennas and calibrate transmission power levels to reduce the probability that signals from wireless access points can be received outsi
- ▌ Ac 19 Access Control For Mobile Devices · cyberstrikeusEstablish configuration requirements, connection requirements, and implementation guidance for organization-controlled mobile devices, to include w...
- ▌ Ac 19 3 Use Of Portable Storage Devices With No Identifiable · cyberstrikeusUse of Portable Storage Devices with No Identifiable Owner
- ▌ Ac 2 12 Account Monitoring For Atypical Usage · cyberstrikeusMonitor system accounts for [organization-defined] ;
- ▌ Ac 3 13 Attribute Based Access Control · cyberstrikeusEnforce attribute-based access control policy over defined subjects and objects and control access based upon [organization-defined].
- ▌
- ▌ Ac 9 3 Notification Of Account Changes · cyberstrikeusNotify the user, upon successful logon, of changes to [organization-defined] during [organization-defined].
- ▌ Au 12 Audit Record Generation · cyberstrikeusProvide audit record generation capability for the event types the system is capable of auditing as defined in [AU-2a](#au-2_smt.a) on [organizatio...
- ▌ Au 12 3 Changes By Authorized Individuals · cyberstrikeusProvide and implement the capability for [organization-defined] to change the logging to be performed on [organization-defined] based on [organization
- ▌ Au 12 2 Standardized Formats · cyberstrikeusProduce a system-wide (logical or physical) audit trail composed of audit records in a standardized format.
- ▌ Au 3 Content Of Audit Records · cyberstrikeusEnsure that audit records contain information that establishes the following: What type of event occurred; When the event occurred; Where the event oc
- ▌ Au 6 3 Correlate Audit Record Repositories · cyberstrikeusAnalyze and correlate audit records across different repositories to gain organization-wide situational awareness.
- ▌ Ca 3 Information Exchange · cyberstrikeusApprove and manage the exchange of information between the system and other systems using [organization-defined];
- ▌ Ca 9 1 Compliance Checks · cyberstrikeusPerform security and privacy compliance checks on constituent system components prior to the establishment of the internal connection.
- ▌ Cm 10 1 Open Source Software · cyberstrikeusEstablish the following restrictions on the use of open-source software: [organization-defined].
- ▌ Cm 11 User Installed Software · cyberstrikeusEstablish [organization-defined] governing the installation of software by users;
- ▌ Cis K8S V1111 1 1 18 · cyberstrikeusEnsure that the controller-manager.conf file ownership is set to root:root (Automated)
- ▌ Cis K8S V1111 1 1 19 · cyberstrikeusEnsure that the Kubernetes PKI directory and file ownership is set to root:root (Automated)
- ▌ Cis K8S V1111 1 1 20 · cyberstrikeusEnsure that the Kubernetes PKI certificate file permissions are set to 644 or more restrictive (Manual)
- ▌ Cis K8S V1111 1 1 21 · cyberstrikeusEnsure that the Kubernetes PKI key file permissions are set to 600 (Manual)
- ▌ Cis K8S V1111 1 2 10 · cyberstrikeusEnsure that the admission control plugin AlwaysAdmit is not set (Automated)
- ▌ Cis K8S V1111 1 2 11 · cyberstrikeusEnsure that the admission control plugin AlwaysPullImages is set (Manual)
- ▌ Cis K8S V1111 1 2 12 · cyberstrikeusEnsure that the admission control plugin ServiceAccount is set (Automated)
- ▌ Cis K8S V1111 1 2 13 · cyberstrikeusEnsure that the admission control plugin NamespaceLifecycle is set (Automated)
- ▌ Cis K8S V1111 1 2 14 · cyberstrikeusEnsure that the admission control plugin NodeRestriction is set (Automated)
- ▌ Cis K8S V1111 1 2 15 · cyberstrikeusEnsure that the --profiling argument is set to false (Automated)
- ▌
- ▌ Cis K8S V1111 1 2 17 · cyberstrikeusEnsure that the --audit-log-maxage argument is set to 30 or as appropriate (Automated)
- ▌ Cis K8S V1111 1 2 18 · cyberstrikeusEnsure that the --audit-log-maxbackup argument is set to 10 or as appropriate (Automated)
- ▌ Cis K8S V1111 1 2 19 · cyberstrikeusEnsure that the --audit-log-maxsize argument is set to 100 or as appropriate (Automated)
- ▌ Cis K8S V1111 1 2 20 · cyberstrikeusEnsure that the --request-timeout argument is set as appropriate (Manual)
- ▌ Cis K8S V1111 1 2 21 · cyberstrikeusEnsure that the --service-account-lookup argument is set to true (Automated)
- ▌ Cis K8S V1111 1 2 22 · cyberstrikeusEnsure that the --service-account-key-file argument is set as appropriate (Automated)
- ▌ Cis K8S V1111 1 2 23 · cyberstrikeusEnsure that the --etcd-certfile and --etcd-keyfile arguments are set as appropriate (Automated)
- ▌ Cis K8S V1111 1 2 24 · cyberstrikeusEnsure that the --tls-cert-file and --tls-private-key-file arguments are set as appropriate (Automated)
- ▌ Cis K8S V1111 1 2 25 · cyberstrikeusEnsure that the --client-ca-file argument is set as appropriate (Automated)
- ▌ Cis K8S V1111 1 2 26 · cyberstrikeusEnsure that the --etcd-cafile argument is set as appropriate (Automated)
- ▌ Cis K8S V1111 1 2 27 · cyberstrikeusEnsure that the --encryption-provider-config argument is set as appropriate (Manual)
- ▌ Cis K8S V1111 1 2 28 · cyberstrikeusEnsure that encryption providers are appropriately configured (Manual)
- ▌ Cis K8S V1111 1 2 29 · cyberstrikeusEnsure that the API Server only makes use of Strong Cryptographic Ciphers (Manual)
- ▌ Cis K8S V1111 1 2 30 · cyberstrikeusEnsure that the --service-account-extend-token-expiration parameter is set to false (Automated)
- ▌ Cis K8S V1111 4 2 10 · cyberstrikeusEnsure that the --rotate-certificates argument is not set to false (Automated)
- ▌ Cis K8S V1111 4 2 12 · cyberstrikeusEnsure that the Kubelet only makes use of Strong Cryptographic Ciphers (Manual)
- ▌
- ▌ Cis K8S V1111 4 2 14 · cyberstrikeusEnsure that the --seccomp-default parameter is set to true (Manual)
- ▌
- ▌
- ▌ Cis K8S V1111 5 1 11 · cyberstrikeusMinimize access to the approval sub-resource of certificatesigningrequests objects (Manual)
- ▌
- ▌
- ▌ Cis K8S V1111 5 2 10 · cyberstrikeusMinimize the admission of containers with capabilities assigned (Manual)
- ▌ Cis K8S V1111 5 2 11 · cyberstrikeusMinimize the admission of Windows HostProcess Containers (Manual)
- ▌
- ▌ Cis K8S V1111 5 2 13 · cyberstrikeusMinimize the admission of containers which use HostPorts (Manual)
- ▌ Cis K8S V1120 1 1 10 · cyberstrikeusEnsure that the Container Network Interface file ownership is set to root:root (Manual)
- ▌ Cis K8S V1120 1 1 11 · cyberstrikeusEnsure that the etcd data directory permissions are set to 700 or more restrictive (Automated)
- ▌ Cis K8S V1120 1 1 12 · cyberstrikeusEnsure that the etcd data directory ownership is set to etcd:etcd (Automated)
- ▌ Cis K8S V1120 1 1 13 · cyberstrikeusEnsure that the default administrative credential file permissions are set to 600 (Automated)
- ▌ Cis K8S V1120 1 1 14 · cyberstrikeusEnsure that the default administrative credential file ownership is set to root:root (Automated)
- ▌ Cis K8S V1120 1 1 15 · cyberstrikeusEnsure that the scheduler.conf file permissions are set to 600 or more restrictive (Automated)
- ▌ Cis K8S V1120 1 1 16 · cyberstrikeusEnsure that the scheduler.conf file ownership is set to root:root (Automated)
- ▌ Cis K8S V1120 1 1 17 · cyberstrikeusEnsure that the controller-manager.conf file permissions are set to 600 or more restrictive (Automated)
- ▌ Cis K8S V1120 1 1 18 · cyberstrikeusEnsure that the controller-manager.conf file ownership is set to root:root (Automated)
- ▌ Cis K8S V1120 1 1 19 · cyberstrikeusEnsure that the Kubernetes PKI directory and file ownership is set to root:root (Automated)
- ▌ Cis K8S V1120 1 1 20 · cyberstrikeusEnsure that the Kubernetes PKI certificate file permissions are set to 644 or more restrictive (Manual)
- ▌ Cis K8S V1120 1 1 21 · cyberstrikeusEnsure that the Kubernetes PKI key file permissions are set to 600 (Manual)
- ▌ Cis K8S V1120 1 2 10 · cyberstrikeusEnsure that the admission control plugin AlwaysAdmit is not set (Automated)
- ▌ Cis K8S V1120 1 2 11 · cyberstrikeusEnsure that the admission control plugin AlwaysPullImages is set (Manual)
- ▌ Cis K8S V1120 1 2 12 · cyberstrikeusEnsure that the admission control plugin ServiceAccount is set (Automated)