← all publishers

cyberstrikeus

@cyberstrikeus source repo

7171 published skills · page 48 of 72

  1. Cis K8S V1120 1 2 13 · cyberstrikeus
    Ensure that the admission control plugin NamespaceLifecycle is set (Automated)
    0 installs
  2. Cis K8S V1120 1 2 14 · cyberstrikeus
    Ensure that the admission control plugin NodeRestriction is set (Automated)
    0 installs
  3. Cis K8S V1120 1 2 15 · cyberstrikeus
    Ensure that the --profiling argument is set to false (Automated)
    0 installs
  4. Cis K8S V1120 1 2 16 · cyberstrikeus
    Ensure that the --audit-log-path argument is set (Automated)
    0 installs
  5. Cis K8S V1120 1 2 17 · cyberstrikeus
    Ensure that the --audit-log-maxage argument is set to 30 or as appropriate (Automated)
    0 installs
  6. Cis K8S V1120 1 2 18 · cyberstrikeus
    Ensure that the --audit-log-maxbackup argument is set to 10 or as appropriate (Automated)
    0 installs
  7. Cis K8S V1120 1 2 19 · cyberstrikeus
    Ensure that the --audit-log-maxsize argument is set to 100 or as appropriate (Automated)
    0 installs
  8. Cis K8S V1120 1 2 20 · cyberstrikeus
    Ensure that the --request-timeout argument is set as appropriate (Manual)
    0 installs
  9. Cis K8S V1120 1 2 21 · cyberstrikeus
    Ensure that the --service-account-lookup argument is set to true (Automated)
    0 installs
  10. Cis K8S V1120 1 2 22 · cyberstrikeus
    Ensure that the --service-account-key-file argument is set as appropriate (Automated)
    0 installs
  11. Cis K8S V1120 1 2 23 · cyberstrikeus
    Ensure that the --etcd-certfile and --etcd-keyfile arguments are set as appropriate (Automated)
    0 installs
  12. Cis K8S V1120 1 2 24 · cyberstrikeus
    Ensure that the --tls-cert-file and --tls-private-key-file arguments are set as appropriate (Automated)
    0 installs
  13. Cis K8S V1120 1 2 25 · cyberstrikeus
    Ensure that the --client-ca-file argument is set as appropriate (Automated)
    0 installs
  14. Cis K8S V1120 1 2 26 · cyberstrikeus
    Ensure that the --etcd-cafile argument is set as appropriate (Automated)
    0 installs
  15. Cis K8S V1120 1 2 27 · cyberstrikeus
    Ensure that the --encryption-provider-config argument is set as appropriate (Manual)
    0 installs
  16. Cis K8S V1120 1 2 28 · cyberstrikeus
    Ensure that encryption providers are appropriately configured (Manual)
    0 installs
  17. Cis K8S V1120 1 2 29 · cyberstrikeus
    Ensure that the API Server only makes use of Strong Cryptographic Ciphers (Manual)
    0 installs
  18. Cis K8S V1120 1 2 30 · cyberstrikeus
    Ensure that the --service-account-extend-token-expiration parameter is set to false (Automated)
    0 installs
  19. Cis K8S V1120 4 1 10 · cyberstrikeus
    If the kubelet config.yaml configuration file is being used validate file ownership is set to root:root (Automated)
    0 installs
  20. Cis K8S V1120 4 2 10 · cyberstrikeus
    Ensure that the --rotate-certificates argument is not set to false (Automated)
    0 installs
  21. Cis K8S V1120 4 2 11 · cyberstrikeus
    Verify that the RotateKubeletServerCertificate argument is set to true (Manual)
    0 installs
  22. Cis K8S V1120 4 2 12 · cyberstrikeus
    Ensure that the Kubelet only makes use of Strong Cryptographic Ciphers (Manual)
    0 installs
  23. Cis K8S V1120 4 2 13 · cyberstrikeus
    Ensure that a limit is set on pod PIDs (Manual)
    0 installs
  24. Cis K8S V1120 4 2 14 · cyberstrikeus
    Ensure that the --seccomp-default parameter is set to true (Manual)
    0 installs
  25. Cis K8S V1120 5 1 10 · cyberstrikeus
    Minimize access to the proxy sub-resource of nodes (Manual)
    0 installs
  26. Cis K8S V1120 5 1 11 · cyberstrikeus
    Minimize access to the approval sub-resource of certificatesigningrequests objects (Manual)
    0 installs
  27. Cis K8S V1120 5 1 12 · cyberstrikeus
    Minimize access to webhook configuration objects (Manual)
    0 installs
  28. Cis K8S V1120 5 1 13 · cyberstrikeus
    Minimize access to the service account token creation (Manual)
    0 installs
  29. Cis K8S V1120 5 2 10 · cyberstrikeus
    Minimize the admission of Windows HostProcess Containers (Manual)
    0 installs
  30. Cis K8S V1120 5 2 11 · cyberstrikeus
    Minimize the admission of HostPath volumes (Manual)
    0 installs
  31. Cis K8S V1120 5 2 12 · cyberstrikeus
    Minimize the admission of containers which use HostPorts (Manual)
    0 installs
  32. Security Engineering Principles 03 16 01 Security Engineerin · cyberstrikeus
    Security Engineering Principles
    0 installs
  33. Ia 2 7 Network Access To Non Privileged Accounts Separate De · cyberstrikeus
    Network Access to Non-privileged Accounts — Separate Device
    0 installs
  34. Ia 2 9 Network Access To Non Privileged Accounts Replay Resi · cyberstrikeus
    Network Access to Non-privileged Accounts — Replay Resistant
    0 installs
  35. Ia 4 3 Multiple Forms Of Certification · cyberstrikeus
    Multiple Forms of Certification
    0 installs
  36. Ia 5 2 Public Key Based Authentication · cyberstrikeus
    For public key-based authentication: Enforce authorized access to the corresponding private key; and Map the authenticated identity to the account of
    0 installs
  37. Ia 5 9 Federated Credential Management · cyberstrikeus
    Use the following external organizations to federate credentials: [organization-defined].
    0 installs
  38. Ia 8 5 Acceptance Of Piv I Credentials · cyberstrikeus
    Accept and verify federated or PKI credentials that meet [organization-defined].
    0 installs
  39. Pe 10 1 Accidental And Unauthorized Activation · cyberstrikeus
    Accidental and Unauthorized Activation
    0 installs
  40. Pe 11 2 Alternate Power Supply Self Contained · cyberstrikeus
    Provide an alternate power supply for the system that is activated [organization-defined] and that is: Self-contained; Not reliant on external power g
    0 installs
  41. Pe 13 1 Detection Systems Automatic Activation And Notificat · cyberstrikeus
    Employ fire detection systems that activate automatically and notify [organization-defined] and [organization-defined] in the event of a fire.
    0 installs
  42. Pe 13 3 Automatic Fire Suppression · cyberstrikeus
    Automatic Fire Suppression
    0 installs
  43. Pe 18 Location Of System Components · cyberstrikeus
    Position system components within the facility to minimize potential damage from [organization-defined] and to minimize the opportunity for unauthoriz
    0 installs
  44. Pe 2 Physical Access Authorizations · cyberstrikeus
    Develop, approve, and maintain a list of individuals with authorized access to the facility where the system resides;
    0 installs
  45. Pe 2 2 Two Forms Of Identification · cyberstrikeus
    Require two forms of identification from the following forms of identification for visitor access to the facility where the system resides: [organizat
    0 installs
  46. Pe 20 Asset Monitoring And Tracking · cyberstrikeus
    Employ [organization-defined] to track and monitor the location and movement of [organization-defined] within [organization-defined].
    0 installs
  47. Pe 5 2 Link To Individual Identity · cyberstrikeus
    Link individual identity to receipt of output from output devices.
    0 installs
  48. Sc 13 1 Fips Validated Cryptography · cyberstrikeus
    FIPS-validated Cryptography
    0 installs
  49. Sc 18 4 Prevent Automatic Execution · cyberstrikeus
    Prevent the automatic execution of mobile code in [organization-defined] and enforce [organization-defined] prior to executing the code.
    0 installs
  50. Sc 2 1 Interfaces For Non Privileged Users · cyberstrikeus
    Prevent the presentation of system management functionality at interfaces to non-privileged users.
    0 installs
  51. Sc 26 1 Detection Of Malicious Code · cyberstrikeus
    Detection of Malicious Code
    0 installs
  52. Sc 34 2 Integrity Protection On Read Only Media · cyberstrikeus
    Protect the integrity of information prior to storage on read-only media and control the media after such information has been recorded onto the media
    0 installs
  53. Sc 45 2 Secondary Authoritative Time Source · cyberstrikeus
    Identify a secondary authoritative time source that is in a different geographic region than the primary authoritative time source;
    0 installs
  54. Sc 47 Alternate Communications Paths · cyberstrikeus
    Establish [organization-defined] for system operations organizational command and control.
    0 installs
  55. Sc 7 14 Protect Against Unauthorized Physical Connections · cyberstrikeus
    Protect against unauthorized physical connections at [organization-defined].
    0 installs
  56. Sc 7 19 Block Communication From Non Organizationally Config · cyberstrikeus
    Block inbound and outbound communications traffic between [organization-defined] that are independently configured by end users and external service p
    0 installs
  57. Sc 7 26 Classified National Security System Connections · cyberstrikeus
    Prohibit the direct connection of a classified national security system to an external network without the use of [organization-defined].
    0 installs
  58. Sc 7 9 Restrict Threatening Outgoing Communications Traffic · cyberstrikeus
    Detect and deny outgoing communications traffic posing a threat to external systems;
    0 installs
  59. Si 18 5 Notice Of Correction Or Deletion · cyberstrikeus
    Notify [organization-defined] and individuals that the personally identifiable information has been corrected or deleted.
    0 installs
  60. Si 2 2 Automated Flaw Remediation Status · cyberstrikeus
    Determine if system components have applicable security-relevant software and firmware updates installed using [organization-defined] [organization-de
    0 installs
  61. Si 2 4 Automated Patch Management Tools · cyberstrikeus
    Employ automated patch management tools to facilitate flaw remediation to the following system components: [organization-defined].
    0 installs
  62. Si 3 4 Updates Only By Privileged Users · cyberstrikeus
    Update malicious code protection mechanisms only when directed by a privileged user.
    0 installs
  63. Si 4 16 Correlate Monitoring Information · cyberstrikeus
    Correlate information from monitoring tools and mechanisms employed throughout the system.
    0 installs
  64. Si 4 17 Integrated Situational Awareness · cyberstrikeus
    Correlate information from monitoring physical, cyber, and supply chain activities to achieve integrated, organization-wide situational awareness.
    0 installs
  65. Si 7 3 Centrally Managed Integrity Tools · cyberstrikeus
    Employ centrally managed integrity verification tools.
    0 installs
  66. Cis AWS Foundations 2 1 1 · cyberstrikeus
    Ensure centralized root access in AWS Organizations
    0 installs
  67. Cis AWS Foundations 2 1 2 · cyberstrikeus
    Ensure authorization guardrails for all AWS Organization accounts
    0 installs
  68. Cis AWS Foundations 2 1 3 · cyberstrikeus
    Ensure Organizations management account is not used for workloads
    0 installs
  69. Cis AWS Foundations 2 1 4 · cyberstrikeus
    Ensure Organizational Units are structured by environment and sensitivity
    0 installs
  70. Cis AWS Foundations 2 1 5 · cyberstrikeus
    Ensure delegated admin manages AWS Organizations policies
    0 installs
  71. Cis AWS Foundations 2 1 6 · cyberstrikeus
    Ensure delegated admins manage AWS Organizations-integrated services
    0 installs
  72. Cis AWS Foundations 3 1 1 · cyberstrikeus
    Ensure S3 Bucket Policy is set to deny HTTP requests
    0 installs
  73. Cis AWS Foundations 3 1 2 · cyberstrikeus
    Ensure MFA Delete is enabled on S3 buckets
    0 installs
  74. Cis AWS Foundations 3 1 3 · cyberstrikeus
    Ensure all data in Amazon S3 has been discovered, classified, and secured when necessary
    0 installs
  75. Cis AWS Foundations 3 1 4 · cyberstrikeus
    Ensure that S3 is configured with 'Block Public Access' enabled
    0 installs
  76. Cis AWS Foundations 3 2 1 · cyberstrikeus
    Ensure that encryption-at-rest is enabled for RDS instances
    0 installs
  77. Cis AWS Foundations 3 2 2 · cyberstrikeus
    Ensure the Auto Minor Version Upgrade feature is enabled for RDS instances
    0 installs
  78. Cis AWS Foundations 3 2 3 · cyberstrikeus
    Ensure that RDS instances are not publicly accessible
    0 installs
  79. Cis AWS Foundations 3 2 4 · cyberstrikeus
    Ensure Multi-AZ deployments are used for enhanced availability in Amazon RDS
    0 installs
  80. Cis AWS Foundations 3 3 1 · cyberstrikeus
    Ensure that encryption is enabled for EFS file systems
    0 installs
  81. Cis AWS Foundations 6 1 1 · cyberstrikeus
    Ensure EBS volume encryption is enabled in all regions
    0 installs
  82. Cis AWS Foundations 6 1 2 · cyberstrikeus
    Ensure CIFS access is restricted to trusted networks to prevent unauthorized access
    0 installs
  83. Cis AWS Compute 12 10 · cyberstrikeus
    Ensure Lambda functions do not allow unknown cross account access via permission policies
    0 installs
  84. Cis AWS Compute 12 11 · cyberstrikeus
    Ensure that the runtime environment versions used for your Lambda functions do not have end of support dates
    0 installs
  85. Cis AWS Compute 12 12 · cyberstrikeus
    Ensure encryption in transit is enabled for Lambda environment variables
    0 installs
  86. Cis AWS Compute 2 1 1 · cyberstrikeus
    Ensure Consistent Naming Convention is used for Organizational AMI
    0 installs
  87. Cis AWS Compute 2 1 2 · cyberstrikeus
    Ensure Amazon Machine Images (AMIs) are encrypted
    0 installs
  88. Cis AWS Compute 2 1 3 · cyberstrikeus
    Ensure Only Approved Amazon Machine Images (AMIs) are Used
    0 installs
  89. Cis AWS Compute 2 1 4 · cyberstrikeus
    Ensure Images (AMI) are not older than 90 days
    0 installs
  90. Cis AWS Compute 2 1 5 · cyberstrikeus
    Ensure Images are not Publicly Available
    0 installs
  91. Cis AWS Compute 2 2 1 · cyberstrikeus
    Ensure EBS volume encryption is enabled
    1 install
  92. Cis AWS Compute 2 2 2 · cyberstrikeus
    Ensure Public Access to EBS Snapshots is Disabled
    0 installs
  93. Cis AWS Compute 2 2 3 · cyberstrikeus
    Ensure EBS volume snapshots are encrypted
    0 installs
  94. Cis AWS Compute 2 2 4 · cyberstrikeus
    Ensure unused EBS volumes are removed
    0 installs
  95. Cis AWS Database 10 10 · cyberstrikeus
    Ensure Database has automated Backups enabled
    0 installs
  96. Multi Factor Authentication 03 05 03 Multi Factor Authentica · cyberstrikeus
    Multi-Factor Authentication
    0 installs
  97. Unsupported System Components 03 16 02 Unsupported System Co · cyberstrikeus
    Replace system components when support for the components is no longer available from the developer, vendor, or manufacturer.
    0 installs
  98. Ia 13 1 Protection Of Cryptographic Keys · cyberstrikeus
    Cryptographic keys that protect access tokens are generated, managed, and protected from disclosure and misuse.
    0 installs
  99. Ia 4 8 Pairwise Pseudonymous Identifiers · cyberstrikeus
    Generate pairwise pseudonymous identifiers.
    0 installs
  100. Ia 7 Cryptographic Module Authentication · cyberstrikeus
    Implement mechanisms for authentication to a cryptographic module that meet the requirements of applicable laws, executive orders, directives, policie
    0 installs