cyberstrikeus
- 7.2k skills
- 0 followers
- 1 day ago last updated
- ▌ Cis Oke V170 4 4 1 · cyberstrikeusPrefer using secrets as files over secrets as environment variables (Automated)
- ▌
- ▌ Cis Oke V170 4 5 1 · cyberstrikeusCreate administrative boundaries between resources using namespaces (Manual)
- ▌
- ▌
- ▌ Cis Oke V170 5 1 1 · cyberstrikeusOracle Cloud Security Penetration and Vulnerability Testing (Manual)
- ▌ Cis Oke V170 5 1 2 · cyberstrikeusMinimize user access control to Container Engine for Kubernetes (Manual)
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌ Cis Oke V170 5 4 2 · cyberstrikeusEnsure clusters created with Private Endpoint Enabled and Public Access Disabled (Automated)
- ▌
- ▌ Cis Oke V170 5 4 4 · cyberstrikeusEnsure Network Policy is Enabled and set as appropriate (Automated)
- ▌ Cis Oke V170 5 4 5 · cyberstrikeusEncrypt traffic to HTTPS load balancers with TLS certificates (Manual)
- ▌
- ▌ Cis Oke V180 2 1 1 · cyberstrikeusClient certificate authentication should not be used for users (Manual)
- ▌
- ▌ Cis Oke V180 3 1 1 · cyberstrikeusEnsure that the kubelet-config.json file permissions are set to 644 or more restrictive (Automated)
- ▌ Cis Oke V180 3 1 2 · cyberstrikeusEnsure that the kubelet-config.json file ownership is set to root:root (Automated)
- ▌ Cis Oke V180 3 1 3 · cyberstrikeusEnsure that the kubelet configuration file has permissions set to 644 or more restrictive (Automated)
- ▌ Cis Oke V180 3 1 4 · cyberstrikeusEnsure that the kubelet configuration file ownership is set to root:root (Automated)
- ▌ Cis Oke V180 3 2 1 · cyberstrikeusEnsure that the --anonymous-auth argument is set to false (Automated)
- ▌ Cis Oke V180 3 2 2 · cyberstrikeusEnsure that the --authorization-mode argument is not set to AlwaysAllow (Automated)
- ▌ Cis Oke V180 3 2 3 · cyberstrikeusEnsure that the --client-ca-file argument is set as appropriate (Automated)
- ▌
- ▌ Cis Oke V180 3 2 5 · cyberstrikeusEnsure that the --streaming-connection-idle-timeout argument is not set to 0 (Automated)
- ▌ Cis Oke V180 3 2 6 · cyberstrikeusEnsure that the --make-iptables-util-chains argument is set to true (Automated)
- ▌ Cis Oke V180 3 2 7 · cyberstrikeusEnsure that the --event-qps argument is set to 0 or a level which ensures appropriate event capture (Automated)
- ▌ Cis Oke V180 3 2 8 · cyberstrikeusEnsure that the --tls-cert-file and --tls-private-key-file arguments are set as appropriate (Automated)
- ▌ Cis Oke V180 3 2 9 · cyberstrikeusEnsure that the --rotate-certificates argument is not set to false (Automated)
- ▌ Cis Oke V180 4 1 1 · cyberstrikeusEnsure that the cluster-admin role is only used where required (Manual)
- ▌
- ▌
- ▌
- ▌ Cis Oke V180 4 1 5 · cyberstrikeusEnsure that default service accounts are not actively used (Automated)
- ▌ Cis Oke V180 4 1 6 · cyberstrikeusEnsure that Service Account Tokens are only mounted where necessary (Automated)
- ▌
- ▌ Cis Oke V180 4 2 2 · cyberstrikeusMinimize the admission of containers wishing to share the host process ID namespace (Automated)
- ▌ Cis Oke V180 4 2 3 · cyberstrikeusMinimize the admission of containers wishing to share the host IPC namespace (Automated)
- ▌ Cis Oke V180 4 2 4 · cyberstrikeusMinimize the admission of containers wishing to share the host network namespace (Automated)
- ▌ Cis Oke V180 4 2 5 · cyberstrikeusMinimize the admission of containers with allowPrivilegeEscalation (Automated)
- ▌
- ▌ Cis Oke V180 4 3 2 · cyberstrikeusEnsure that all Namespaces have Network Policies defined (Manual)
- ▌ Cis Oke V180 4 4 1 · cyberstrikeusPrefer using secrets as files over secrets as environment variables (Automated)
- ▌
- ▌ Cis Oke V180 4 5 1 · cyberstrikeusCreate administrative boundaries between resources using namespaces (Manual)
- ▌
- ▌
- ▌ Cis Oke V180 5 1 1 · cyberstrikeusOracle Cloud Security Penetration and Vulnerability Testing (Manual)
- ▌ Cis Oke V180 5 1 2 · cyberstrikeusMinimize user access control to Container Engine for Kubernetes (Manual)
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌ Cis Oke V180 5 4 2 · cyberstrikeusEnsure clusters are created with Private Endpoint Enabled and Public Access Disabled (Automated)
- ▌
- ▌
- ▌ Cis Oke V180 5 4 5 · cyberstrikeusEncrypt traffic to HTTPS load balancers with TLS certificates (Manual)
- ▌
- ▌ Cis Nginx V300 4 1 10 · cyberstrikeusEnsure the upstream traffic server certificate is trusted (Manual)
- ▌
- ▌
- ▌ T0800 Activate Firmware Update Mode · cyberstrikeusAdversaries may activate firmware update mode on devices to prevent expected response functions from engaging in reaction to an emergency or process malfunction.
- ▌ T1637 001 Domain Generation Algorithms · cyberstrikeusAdversaries may use Domain Generation Algorithms (DGAs) to procedurally generate domain names for uses such as command and control communication or malicious application distribution.
- ▌
- ▌ Time Stamps 03 03 07 Time Stamps · cyberstrikeusUse internal system clocks to generate time stamps for audit records.
- ▌ Least Functionality 03 04 06 Least Functionality · cyberstrikeusConfigure the system to provide only mission-essential capabilities.
- ▌ Device Identification And Authentication 03 05 02 Device Ide · cyberstrikeusDevice Identification and Authentication
- ▌ Physical Access Authorizations 03 10 01 Physical Access Auth · cyberstrikeusDevelop, approve, and maintain a list of individuals with authorized access to the facility where the system resides.
- ▌
- ▌
- ▌
- ▌ Design Software To Meet Security Requirements And Mitigate S · cyberstrikeusIdentify and evaluate the security requirements for the software;
- ▌ Test Executable Code To Identify Vulnerabilities And Verify · cyberstrikeusHelp identify vulnerabilities so that they can be corrected before the software is released in order to prevent exploitation.
- ▌ Analyze Vulnerabilities To Identify Their Root Causes Rv 3 A · cyberstrikeusHelp reduce the frequency of vulnerabilities in the future.
- ▌ Au 5 Response To Audit Logging Process Failures · cyberstrikeusAlert [organization-defined] within [organization-defined] in the event of an audit logging process failure;
- ▌ Au 7 Audit Record Reduction And Report Generation · cyberstrikeusProvide and implement an audit record reduction and report generation capability that: Supports on-demand audit record review, analysis, and reporting
- ▌ Ca 5 Plan Of Action And Milestones · cyberstrikeusDevelop a plan of action and milestones for the system to document the planned remediation actions of the organization to correct weaknesses or def...
- ▌ Cm 2 2 Automation Support For Accuracy And Currency · cyberstrikeusMaintain the currency, completeness, accuracy, and availability of the baseline configuration of the system using [organization-defined].
- ▌ Cm 8 1 Updates During Installation And Removal · cyberstrikeusUpdate the inventory of system components as part of component installations, removals, and system updates.
- ▌ Ia 10 Adaptive Authentication · cyberstrikeusRequire individuals accessing the system to employ [organization-defined] under specific [organization-defined].
- ▌ Ia 12 5 Address Confirmation · cyberstrikeusRequire that a [organization-defined] be delivered through an out-of-band channel to verify the users address (physical or digital) of record.
- ▌ Ia 5 Authenticator Management · cyberstrikeusManage system authenticators by: Verifying, as part of the initial authenticator distribution, the identity of the individual, group, role, service, o
- ▌ Ia 8 2 Acceptance Of External Authenticators · cyberstrikeusAccept only external authenticators that are NIST-compliant;
- ▌ Pe 17 Alternate Work Site · cyberstrikeusDetermine and document the [organization-defined] allowed for use by employees;
- ▌ Pe 19 Information Leakage · cyberstrikeusProtect the system from information leakage due to electromagnetic signals emanations.
- ▌ Pe 3 3 Continuous Guards · cyberstrikeusEmploy guards to control [organization-defined] to the facility where the system resides 24 hours per day, 7 days per week.
- ▌ Pe 3 5 Tamper Protection · cyberstrikeusEmploy [organization-defined] to [organization-defined] physical tampering or alteration of [organization-defined] within the system.
- ▌
- ▌ Pe 9 1 Redundant Cabling · cyberstrikeusEmploy redundant power cabling paths that are physically separated by [organization-defined].
- ▌ Pt 5 1 Just In Time Notice · cyberstrikeusPresent notice of personally identifiable information processing to individuals at a time and location where the individual provides personally identi
- ▌ Sa 11 9 Interactive Application Security Testing · cyberstrikeusRequire the developer of the system, system component, or system service to employ interactive application security testing tools to identify flaws an
- ▌ Sa 11 6 Attack Surface Reviews · cyberstrikeusRequire the developer of the system, system component, or system service to perform attack surface reviews.
- ▌
- ▌ Sa 15 6 Continuous Improvement · cyberstrikeusRequire the developer of the system, system component, or system service to implement an explicit process to continuously improve the development proc
- ▌ Sa 20 Customized Development Of Critical Components · cyberstrikeusReimplement or custom develop the following critical system components: [organization-defined].
- ▌ Sa 22 1 Alternative Sources For Continued Support · cyberstrikeusAlternative Sources for Continued Support