cyberstrikeus
- 7.2k skills
- 0 followers
- 1 day ago last updated
- ▌
- ▌ Cis Gke Autopilot V100 5 1 1 · cyberstrikeusEnsure Image Vulnerability Scanning is enabled (Automated)
- ▌ Cis Gke Autopilot V100 5 1 2 · cyberstrikeusMinimize user access to Container Image repositories (Manual)
- ▌ Cis Gke Autopilot V100 5 1 3 · cyberstrikeusMinimize cluster access to read-only for Container Image repositories (Manual)
- ▌ Cis Gke Autopilot V100 5 1 4 · cyberstrikeusEnsure only trusted container images are used (Automated)
- ▌ Cis Gke Autopilot V100 5 2 1 · cyberstrikeusEnsure GKE clusters are not running using the Compute Engine default service account (Automated)
- ▌ Cis Gke Autopilot V100 5 3 1 · cyberstrikeusEnsure Kubernetes Secrets are encrypted using keys managed in Cloud KMS (Automated)
- ▌ Cis Gke Autopilot V100 5 4 1 · cyberstrikeusEnable VPC Flow Logs and Intranode Visibility (Automated)
- ▌ Cis Gke Autopilot V100 5 4 2 · cyberstrikeusEnsure Control Plane Authorized Networks is Enabled (Automated)
- ▌ Cis Gke Autopilot V100 5 4 3 · cyberstrikeusEnsure clusters are created with Private Endpoint Enabled and Public Access Disabled (Automated)
- ▌ Cis Gke Autopilot V100 5 4 4 · cyberstrikeusEnsure clusters are created with Private Nodes (Automated)
- ▌ Cis Gke Autopilot V100 5 4 5 · cyberstrikeusEnsure use of Google-managed SSL Certificates (Automated)
- ▌ Cis Gke Autopilot V100 5 5 1 · cyberstrikeusManage Kubernetes RBAC users with Google Groups for GKE (Manual)
- ▌ Cis Gke Autopilot V100 5 6 1 · cyberstrikeusEnable Customer-Managed Encryption Keys (CMEK) for GKE Persistent Disks (PD) (Manual)
- ▌
- ▌ Cis Gke Autopilot V130 4 1 1 · cyberstrikeusEnsure that the cluster-admin role is only used where required (Manual)
- ▌
- ▌ Cis Gke Autopilot V130 5 4 2 · cyberstrikeusEnsure Control Plane Authorized Networks is Enabled (Manual)
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌ Cis GCP Cos 4 1 1 1 · cyberstrikeusEnsure correct container image is set for stackdriver logging agent
- ▌
- ▌
- ▌
- ▌ Cis GCP Cos 4 1 2 2 · cyberstrikeusEnsure journald is configured to write logfiles to persistent disk
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌ Cis Azure Compute 15 1 · cyberstrikeusEnsure Batch account is set to use customer-managed keys to encrypt data
- ▌
- ▌ Cis Azure Compute 15 3 · cyberstrikeusEnsure local authentication methods for accounts are disabled
- ▌
- ▌
- ▌ Cis Azure Compute 15 6 · cyberstrikeusEnsure private DNS zones for private endpoints that connect to Batch accounts are configured
- ▌ Cis Azure Compute 15 7 · cyberstrikeusEnsure Diagnostics settings logs for Batch accounts are enabled
- ▌ Cis Azure Compute 2 10 · cyberstrikeusEnsure App Service Environment has TLS cipher suite ordering configured
- ▌
- ▌ Cis Azure Compute 20 2 · cyberstrikeusEnsure that 'OS and Data' disks are encrypted with Customer Managed Key (CMK)
- ▌ Cis Azure Compute 20 3 · cyberstrikeusEnsure that 'Unattached disks' are encrypted with 'Customer Managed Key' (CMK)
- ▌ Cis Azure Compute 20 4 · cyberstrikeusEnsure that 'Disk Network Access' is NOT set to 'Enable public access from all networks'
- ▌
- ▌
- ▌ Cis Azure Compute 20 7 · cyberstrikeusEnsure that Endpoint Protection for all Virtual Machines is installed
- ▌
- ▌ Cis Azure Compute 20 9 · cyberstrikeusEnsure only MFA enabled identities can access privileged Virtual Machine
- ▌ Cis Azure Foundations 2 1 1 · cyberstrikeusEnsure Azure Databricks is deployed in a customer-managed VNet
- ▌ Cis Azure Foundations 2 1 2 · cyberstrikeusEnsure network security groups are configured for Databricks subnets
- ▌ Cis Azure Foundations 2 1 3 · cyberstrikeusEnsure traffic is encrypted between cluster worker nodes
- ▌ Cis Azure Foundations 2 1 4 · cyberstrikeusEnsure users and groups are synced from Microsoft Entra ID to Azure Databricks
- ▌
- ▌ Cis Azure Foundations 2 1 6 · cyberstrikeusEnsure usage is restricted and expiry is enforced for Databricks personal access tokens
- ▌ Cis Azure Foundations 2 1 7 · cyberstrikeusEnsure diagnostic log delivery is configured for Azure Databricks
- ▌ Cis Azure Foundations 2 1 8 · cyberstrikeusEnsure critical data in Azure Databricks is encrypted with customer-managed keys (CMK)
- ▌
- ▌ Cis Azure Foundations 3 1 1 · cyberstrikeusEnsure only MFA enabled identities can access privileged Virtual Machine
- ▌ Cis Azure Foundations 5 1 1 · cyberstrikeusEnsure 'security defaults' is enabled in Microsoft Entra ID
- ▌ Cis Azure Foundations 5 1 2 · cyberstrikeusEnsure 'multifactor authentication' is 'enabled' for all users
- ▌ Cis Azure Foundations 5 1 3 · cyberstrikeusEnsure 'Allow users to remember multifactor authentication on devices they trust' is disabled
- ▌
- ▌ Cis Azure Foundations 5 2 2 · cyberstrikeusEnsure an exclusionary geographic Conditional Access policy is considered
- ▌ Cis Azure Foundations 5 2 3 · cyberstrikeusEnsure an exclusionary device code flow policy is considered
- ▌ Cis Azure Foundations 5 2 4 · cyberstrikeusEnsure a multifactor authentication policy exists for all users
- ▌ Cis Azure Foundations 5 2 5 · cyberstrikeusEnsure multifactor authentication is required for risky sign-ins
- ▌ Cis Azure Foundations 5 2 6 · cyberstrikeusEnsure multifactor authentication is required for Windows Azure Service Management API
- ▌ Cis Azure Foundations 5 2 7 · cyberstrikeusEnsure multifactor authentication is required to access Microsoft Admin Portals
- ▌ Cis Azure Foundations 5 2 8 · cyberstrikeusEnsure a Token Protection Conditional Access policy is considered
- ▌ Cis Azure Foundations 5 3 1 · cyberstrikeusEnsure Azure admin accounts are not used for daily operations
- ▌
- ▌ Cis Azure Foundations 5 3 3 · cyberstrikeusEnsure use of the 'User Access Administrator' role is restricted
- ▌ Cis Azure Foundations 5 3 4 · cyberstrikeusEnsure all 'privileged' role assignments are periodically reviewed
- ▌ Cis Azure Foundations 5 3 5 · cyberstrikeusEnsure disabled user accounts do not have read, write, or owner permissions
- ▌ Cis Azure Foundations 5 3 6 · cyberstrikeusEnsure 'Tenant Creator' role assignments are periodically reviewed
- ▌ Cis Azure Foundations 5 3 7 · cyberstrikeusEnsure all non-privileged role assignments are periodically reviewed
- ▌ Cis Azure Foundations 6 1 4 · cyberstrikeusEnsure that Azure Monitor Resource Logging is Enabled for All Services that Support it
- ▌ Cis Azure Foundations 6 1 5 · cyberstrikeusEnsure that SKU Basic/Consumption is not used on artifacts that need to be monitored
- ▌
- ▌ Cis Azure Foundations 8 3 1 · cyberstrikeusEnsure that the Expiration Date is set for all Keys in RBAC Key Vaults
- ▌ Cis Azure Foundations 8 3 2 · cyberstrikeusEnsure that the Expiration Date is set for all Keys in Non-RBAC Key Vaults
- ▌ Cis Azure Foundations 8 3 3 · cyberstrikeusEnsure that the Expiration Date is set for all Secrets in RBAC Key Vaults
- ▌ Cis Azure Foundations 8 3 4 · cyberstrikeusEnsure that the Expiration Date is set for all Secrets in Non-RBAC Key Vaults
- ▌
- ▌ Cis Azure Foundations 8 3 6 · cyberstrikeusEnsure that Private Endpoints are Used for Azure Key Vault
- ▌ Cis Azure Foundations 8 3 7 · cyberstrikeusEnsure that Azure Key Vaults Use Azure RBAC for access management