cyberstrikeus
- 7.2k skills
- 0 followers
- 2 days ago last updated
- ▌ Cis K8S V1120 1 2 13 · cyberstrikeusEnsure that the admission control plugin NamespaceLifecycle is set (Automated)
- ▌ Cis K8S V1120 1 2 14 · cyberstrikeusEnsure that the admission control plugin NodeRestriction is set (Automated)
- ▌ Cis K8S V1120 1 2 15 · cyberstrikeusEnsure that the --profiling argument is set to false (Automated)
- ▌
- ▌ Cis K8S V1120 1 2 17 · cyberstrikeusEnsure that the --audit-log-maxage argument is set to 30 or as appropriate (Automated)
- ▌ Cis K8S V1120 1 2 18 · cyberstrikeusEnsure that the --audit-log-maxbackup argument is set to 10 or as appropriate (Automated)
- ▌ Cis K8S V1120 1 2 19 · cyberstrikeusEnsure that the --audit-log-maxsize argument is set to 100 or as appropriate (Automated)
- ▌ Cis K8S V1120 1 2 20 · cyberstrikeusEnsure that the --request-timeout argument is set as appropriate (Manual)
- ▌ Cis K8S V1120 1 2 21 · cyberstrikeusEnsure that the --service-account-lookup argument is set to true (Automated)
- ▌ Cis K8S V1120 1 2 22 · cyberstrikeusEnsure that the --service-account-key-file argument is set as appropriate (Automated)
- ▌ Cis K8S V1120 1 2 23 · cyberstrikeusEnsure that the --etcd-certfile and --etcd-keyfile arguments are set as appropriate (Automated)
- ▌ Cis K8S V1120 1 2 24 · cyberstrikeusEnsure that the --tls-cert-file and --tls-private-key-file arguments are set as appropriate (Automated)
- ▌ Cis K8S V1120 1 2 25 · cyberstrikeusEnsure that the --client-ca-file argument is set as appropriate (Automated)
- ▌ Cis K8S V1120 1 2 26 · cyberstrikeusEnsure that the --etcd-cafile argument is set as appropriate (Automated)
- ▌ Cis K8S V1120 1 2 27 · cyberstrikeusEnsure that the --encryption-provider-config argument is set as appropriate (Manual)
- ▌ Cis K8S V1120 1 2 28 · cyberstrikeusEnsure that encryption providers are appropriately configured (Manual)
- ▌ Cis K8S V1120 1 2 29 · cyberstrikeusEnsure that the API Server only makes use of Strong Cryptographic Ciphers (Manual)
- ▌ Cis K8S V1120 1 2 30 · cyberstrikeusEnsure that the --service-account-extend-token-expiration parameter is set to false (Automated)
- ▌ Cis K8S V1120 4 1 10 · cyberstrikeusIf the kubelet config.yaml configuration file is being used validate file ownership is set to root:root (Automated)
- ▌ Cis K8S V1120 4 2 10 · cyberstrikeusEnsure that the --rotate-certificates argument is not set to false (Automated)
- ▌ Cis K8S V1120 4 2 11 · cyberstrikeusVerify that the RotateKubeletServerCertificate argument is set to true (Manual)
- ▌ Cis K8S V1120 4 2 12 · cyberstrikeusEnsure that the Kubelet only makes use of Strong Cryptographic Ciphers (Manual)
- ▌
- ▌ Cis K8S V1120 4 2 14 · cyberstrikeusEnsure that the --seccomp-default parameter is set to true (Manual)
- ▌
- ▌ Cis K8S V1120 5 1 11 · cyberstrikeusMinimize access to the approval sub-resource of certificatesigningrequests objects (Manual)
- ▌
- ▌
- ▌ Cis K8S V1120 5 2 10 · cyberstrikeusMinimize the admission of Windows HostProcess Containers (Manual)
- ▌
- ▌ Cis K8S V1120 5 2 12 · cyberstrikeusMinimize the admission of containers which use HostPorts (Manual)
- ▌ Security Engineering Principles 03 16 01 Security Engineerin · cyberstrikeusSecurity Engineering Principles
- ▌ Ia 2 7 Network Access To Non Privileged Accounts Separate De · cyberstrikeusNetwork Access to Non-privileged Accounts — Separate Device
- ▌ Ia 2 9 Network Access To Non Privileged Accounts Replay Resi · cyberstrikeusNetwork Access to Non-privileged Accounts — Replay Resistant
- ▌
- ▌ Ia 5 2 Public Key Based Authentication · cyberstrikeusFor public key-based authentication: Enforce authorized access to the corresponding private key; and Map the authenticated identity to the account of
- ▌ Ia 5 9 Federated Credential Management · cyberstrikeusUse the following external organizations to federate credentials: [organization-defined].
- ▌ Ia 8 5 Acceptance Of Piv I Credentials · cyberstrikeusAccept and verify federated or PKI credentials that meet [organization-defined].
- ▌ Pe 10 1 Accidental And Unauthorized Activation · cyberstrikeusAccidental and Unauthorized Activation
- ▌ Pe 11 2 Alternate Power Supply Self Contained · cyberstrikeusProvide an alternate power supply for the system that is activated [organization-defined] and that is: Self-contained; Not reliant on external power g
- ▌ Pe 13 1 Detection Systems Automatic Activation And Notificat · cyberstrikeusEmploy fire detection systems that activate automatically and notify [organization-defined] and [organization-defined] in the event of a fire.
- ▌
- ▌ Pe 18 Location Of System Components · cyberstrikeusPosition system components within the facility to minimize potential damage from [organization-defined] and to minimize the opportunity for unauthoriz
- ▌ Pe 2 Physical Access Authorizations · cyberstrikeusDevelop, approve, and maintain a list of individuals with authorized access to the facility where the system resides;
- ▌ Pe 2 2 Two Forms Of Identification · cyberstrikeusRequire two forms of identification from the following forms of identification for visitor access to the facility where the system resides: [organizat
- ▌ Pe 20 Asset Monitoring And Tracking · cyberstrikeusEmploy [organization-defined] to track and monitor the location and movement of [organization-defined] within [organization-defined].
- ▌ Pe 5 2 Link To Individual Identity · cyberstrikeusLink individual identity to receipt of output from output devices.
- ▌
- ▌ Sc 18 4 Prevent Automatic Execution · cyberstrikeusPrevent the automatic execution of mobile code in [organization-defined] and enforce [organization-defined] prior to executing the code.
- ▌ Sc 2 1 Interfaces For Non Privileged Users · cyberstrikeusPrevent the presentation of system management functionality at interfaces to non-privileged users.
- ▌
- ▌ Sc 34 2 Integrity Protection On Read Only Media · cyberstrikeusProtect the integrity of information prior to storage on read-only media and control the media after such information has been recorded onto the media
- ▌ Sc 45 2 Secondary Authoritative Time Source · cyberstrikeusIdentify a secondary authoritative time source that is in a different geographic region than the primary authoritative time source;
- ▌ Sc 47 Alternate Communications Paths · cyberstrikeusEstablish [organization-defined] for system operations organizational command and control.
- ▌ Sc 7 14 Protect Against Unauthorized Physical Connections · cyberstrikeusProtect against unauthorized physical connections at [organization-defined].
- ▌ Sc 7 19 Block Communication From Non Organizationally Config · cyberstrikeusBlock inbound and outbound communications traffic between [organization-defined] that are independently configured by end users and external service p
- ▌ Sc 7 26 Classified National Security System Connections · cyberstrikeusProhibit the direct connection of a classified national security system to an external network without the use of [organization-defined].
- ▌ Sc 7 9 Restrict Threatening Outgoing Communications Traffic · cyberstrikeusDetect and deny outgoing communications traffic posing a threat to external systems;
- ▌ Si 18 5 Notice Of Correction Or Deletion · cyberstrikeusNotify [organization-defined] and individuals that the personally identifiable information has been corrected or deleted.
- ▌ Si 2 2 Automated Flaw Remediation Status · cyberstrikeusDetermine if system components have applicable security-relevant software and firmware updates installed using [organization-defined] [organization-de
- ▌ Si 2 4 Automated Patch Management Tools · cyberstrikeusEmploy automated patch management tools to facilitate flaw remediation to the following system components: [organization-defined].
- ▌ Si 3 4 Updates Only By Privileged Users · cyberstrikeusUpdate malicious code protection mechanisms only when directed by a privileged user.
- ▌ Si 4 16 Correlate Monitoring Information · cyberstrikeusCorrelate information from monitoring tools and mechanisms employed throughout the system.
- ▌ Si 4 17 Integrated Situational Awareness · cyberstrikeusCorrelate information from monitoring physical, cyber, and supply chain activities to achieve integrated, organization-wide situational awareness.
- ▌ Si 7 3 Centrally Managed Integrity Tools · cyberstrikeusEmploy centrally managed integrity verification tools.
- ▌
- ▌ Cis AWS Foundations 2 1 2 · cyberstrikeusEnsure authorization guardrails for all AWS Organization accounts
- ▌ Cis AWS Foundations 2 1 3 · cyberstrikeusEnsure Organizations management account is not used for workloads
- ▌ Cis AWS Foundations 2 1 4 · cyberstrikeusEnsure Organizational Units are structured by environment and sensitivity
- ▌
- ▌ Cis AWS Foundations 2 1 6 · cyberstrikeusEnsure delegated admins manage AWS Organizations-integrated services
- ▌
- ▌
- ▌ Cis AWS Foundations 3 1 3 · cyberstrikeusEnsure all data in Amazon S3 has been discovered, classified, and secured when necessary
- ▌ Cis AWS Foundations 3 1 4 · cyberstrikeusEnsure that S3 is configured with 'Block Public Access' enabled
- ▌ Cis AWS Foundations 3 2 1 · cyberstrikeusEnsure that encryption-at-rest is enabled for RDS instances
- ▌ Cis AWS Foundations 3 2 2 · cyberstrikeusEnsure the Auto Minor Version Upgrade feature is enabled for RDS instances
- ▌
- ▌ Cis AWS Foundations 3 2 4 · cyberstrikeusEnsure Multi-AZ deployments are used for enhanced availability in Amazon RDS
- ▌
- ▌
- ▌ Cis AWS Foundations 6 1 2 · cyberstrikeusEnsure CIFS access is restricted to trusted networks to prevent unauthorized access
- ▌ Cis AWS Compute 12 10 · cyberstrikeusEnsure Lambda functions do not allow unknown cross account access via permission policies
- ▌ Cis AWS Compute 12 11 · cyberstrikeusEnsure that the runtime environment versions used for your Lambda functions do not have end of support dates
- ▌ Cis AWS Compute 12 12 · cyberstrikeusEnsure encryption in transit is enabled for Lambda environment variables
- ▌ Cis AWS Compute 2 1 1 · cyberstrikeusEnsure Consistent Naming Convention is used for Organizational AMI
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌ Multi Factor Authentication 03 05 03 Multi Factor Authentica · cyberstrikeusMulti-Factor Authentication
- ▌ Unsupported System Components 03 16 02 Unsupported System Co · cyberstrikeusReplace system components when support for the components is no longer available from the developer, vendor, or manufacturer.
- ▌ Ia 13 1 Protection Of Cryptographic Keys · cyberstrikeusCryptographic keys that protect access tokens are generated, managed, and protected from disclosure and misuse.
- ▌ Ia 4 8 Pairwise Pseudonymous Identifiers · cyberstrikeusGenerate pairwise pseudonymous identifiers.
- ▌ Ia 7 Cryptographic Module Authentication · cyberstrikeusImplement mechanisms for authentication to a cryptographic module that meet the requirements of applicable laws, executive orders, directives, policie