← all publishers

cyberstrikeus

@cyberstrikeus source repo

7171 published skills · page 60 of 72

  1. Cis Oke V170 4 4 1 · cyberstrikeus
    Prefer using secrets as files over secrets as environment variables (Automated)
    0
    installs
  2. Cis Oke V170 4 4 2 · cyberstrikeus
    Consider external secret storage (Manual)
    0
    installs
  3. Cis Oke V170 4 5 1 · cyberstrikeus
    Create administrative boundaries between resources using namespaces (Manual)
    0
    installs
  4. Cis Oke V170 4 5 2 · cyberstrikeus
    Apply Security Context to Your Pods and Containers (Manual)
    0
    installs
  5. Cis Oke V170 4 5 3 · cyberstrikeus
    The default namespace should not be used (Automated)
    0
    installs
  6. Cis Oke V170 5 1 1 · cyberstrikeus
    Oracle Cloud Security Penetration and Vulnerability Testing (Manual)
    0
    installs
  7. Cis Oke V170 5 1 2 · cyberstrikeus
    Minimize user access control to Container Engine for Kubernetes (Manual)
    0
    installs
  8. Cis Oke V170 5 1 3 · cyberstrikeus
    Minimize cluster access to read-only (Manual)
    0
    installs
  9. Cis Oke V170 5 1 4 · cyberstrikeus
    Minimize Container Registries to only those approved (Manual)
    0
    installs
  10. Cis Oke V170 5 2 1 · cyberstrikeus
    Prefer using dedicated Service Accounts (Automated)
    0
    installs
  11. Cis Oke V170 5 3 1 · cyberstrikeus
    Encrypting Kubernetes Secrets at Rest in Etcd (Manual)
    0
    installs
  12. Cis Oke V170 5 4 1 · cyberstrikeus
    Restrict Access to the Control Plane Endpoint (Automated)
    0
    installs
  13. Cis Oke V170 5 4 2 · cyberstrikeus
    Ensure clusters created with Private Endpoint Enabled and Public Access Disabled (Automated)
    0
    installs
  14. Cis Oke V170 5 4 3 · cyberstrikeus
    Ensure clusters are created with Private Nodes (Automated)
    0
    installs
  15. Cis Oke V170 5 4 4 · cyberstrikeus
    Ensure Network Policy is Enabled and set as appropriate (Automated)
    0
    installs
  16. Cis Oke V170 5 4 5 · cyberstrikeus
    Encrypt traffic to HTTPS load balancers with TLS certificates (Manual)
    0
    installs
  17. Cis Oke V170 5 5 1 · cyberstrikeus
    Access Control and Container Engine for Kubernetes (Manual)
    0
    installs
  18. Cis Oke V180 2 1 1 · cyberstrikeus
    Client certificate authentication should not be used for users (Manual)
    0
    installs
  19. Cis Oke V180 2 2 1 · cyberstrikeus
    Ensure access to OCI Audit service Log for OKE (Manual)
    0
    installs
  20. Cis Oke V180 3 1 1 · cyberstrikeus
    Ensure that the kubelet-config.json file permissions are set to 644 or more restrictive (Automated)
    0
    installs
  21. Cis Oke V180 3 1 2 · cyberstrikeus
    Ensure that the kubelet-config.json file ownership is set to root:root (Automated)
    0
    installs
  22. Cis Oke V180 3 1 3 · cyberstrikeus
    Ensure that the kubelet configuration file has permissions set to 644 or more restrictive (Automated)
    0
    installs
  23. Cis Oke V180 3 1 4 · cyberstrikeus
    Ensure that the kubelet configuration file ownership is set to root:root (Automated)
    0
    installs
  24. Cis Oke V180 3 2 1 · cyberstrikeus
    Ensure that the --anonymous-auth argument is set to false (Automated)
    0
    installs
  25. Cis Oke V180 3 2 2 · cyberstrikeus
    Ensure that the --authorization-mode argument is not set to AlwaysAllow (Automated)
    0
    installs
  26. Cis Oke V180 3 2 3 · cyberstrikeus
    Ensure that the --client-ca-file argument is set as appropriate (Automated)
    0
    installs
  27. Cis Oke V180 3 2 4 · cyberstrikeus
    Ensure that the --read-only-port argument is set to 0 (Manual)
    0
    installs
  28. Cis Oke V180 3 2 5 · cyberstrikeus
    Ensure that the --streaming-connection-idle-timeout argument is not set to 0 (Automated)
    0
    installs
  29. Cis Oke V180 3 2 6 · cyberstrikeus
    Ensure that the --make-iptables-util-chains argument is set to true (Automated)
    0
    installs
  30. Cis Oke V180 3 2 7 · cyberstrikeus
    Ensure that the --event-qps argument is set to 0 or a level which ensures appropriate event capture (Automated)
    0
    installs
  31. Cis Oke V180 3 2 8 · cyberstrikeus
    Ensure that the --tls-cert-file and --tls-private-key-file arguments are set as appropriate (Automated)
    0
    installs
  32. Cis Oke V180 3 2 9 · cyberstrikeus
    Ensure that the --rotate-certificates argument is not set to false (Automated)
    0
    installs
  33. Cis Oke V180 4 1 1 · cyberstrikeus
    Ensure that the cluster-admin role is only used where required (Manual)
    0
    installs
  34. Cis Oke V180 4 1 2 · cyberstrikeus
    Minimize access to secrets (Manual)
    0
    installs
  35. Cis Oke V180 4 1 3 · cyberstrikeus
    Minimize wildcard use in Roles and ClusterRoles (Manual)
    0
    installs
  36. Cis Oke V180 4 1 4 · cyberstrikeus
    Minimize access to create pods (Manual)
    0
    installs
  37. Cis Oke V180 4 1 5 · cyberstrikeus
    Ensure that default service accounts are not actively used (Automated)
    0
    installs
  38. Cis Oke V180 4 1 6 · cyberstrikeus
    Ensure that Service Account Tokens are only mounted where necessary (Automated)
    0
    installs
  39. Cis Oke V180 4 2 1 · cyberstrikeus
    Minimize the admission of privileged containers (Automated)
    0
    installs
  40. Cis Oke V180 4 2 2 · cyberstrikeus
    Minimize the admission of containers wishing to share the host process ID namespace (Automated)
    0
    installs
  41. Cis Oke V180 4 2 3 · cyberstrikeus
    Minimize the admission of containers wishing to share the host IPC namespace (Automated)
    0
    installs
  42. Cis Oke V180 4 2 4 · cyberstrikeus
    Minimize the admission of containers wishing to share the host network namespace (Automated)
    0
    installs
  43. Cis Oke V180 4 2 5 · cyberstrikeus
    Minimize the admission of containers with allowPrivilegeEscalation (Automated)
    0
    installs
  44. Cis Oke V180 4 3 1 · cyberstrikeus
    Ensure latest CNI version is used (Automated)
    0
    installs
  45. Cis Oke V180 4 3 2 · cyberstrikeus
    Ensure that all Namespaces have Network Policies defined (Manual)
    0
    installs
  46. Cis Oke V180 4 4 1 · cyberstrikeus
    Prefer using secrets as files over secrets as environment variables (Automated)
    0
    installs
  47. Cis Oke V180 4 4 2 · cyberstrikeus
    Consider external secret storage (Manual)
    0
    installs
  48. Cis Oke V180 4 5 1 · cyberstrikeus
    Create administrative boundaries between resources using namespaces (Manual)
    0
    installs
  49. Cis Oke V180 4 5 2 · cyberstrikeus
    Apply Security Context to Your Pods and Containers (Manual)
    0
    installs
  50. Cis Oke V180 4 5 3 · cyberstrikeus
    The default namespace should not be used (Automated)
    0
    installs
  51. Cis Oke V180 5 1 1 · cyberstrikeus
    Oracle Cloud Security Penetration and Vulnerability Testing (Manual)
    0
    installs
  52. Cis Oke V180 5 1 2 · cyberstrikeus
    Minimize user access control to Container Engine for Kubernetes (Manual)
    0
    installs
  53. Cis Oke V180 5 1 3 · cyberstrikeus
    Minimize cluster access to read-only (Manual)
    0
    installs
  54. Cis Oke V180 5 1 4 · cyberstrikeus
    Minimize Container Registries to only those approved (Manual)
    0
    installs
  55. Cis Oke V180 5 2 1 · cyberstrikeus
    Prefer using dedicated Service Accounts (Automated)
    0
    installs
  56. Cis Oke V180 5 3 1 · cyberstrikeus
    Encrypting Kubernetes Secrets at Rest in Etcd (Manual)
    0
    installs
  57. Cis Oke V180 5 4 1 · cyberstrikeus
    Restrict Access to the Control Plane Endpoint (Automated)
    0
    installs
  58. Cis Oke V180 5 4 2 · cyberstrikeus
    Ensure clusters are created with Private Endpoint Enabled and Public Access Disabled (Automated)
    0
    installs
  59. Cis Oke V180 5 4 3 · cyberstrikeus
    Ensure clusters are created with Private Nodes (Automated)
    0
    installs
  60. Cis Oke V180 5 4 4 · cyberstrikeus
    Ensure Network Policy is Enabled and set as appropriate (Manual)
    0
    installs
  61. Cis Oke V180 5 4 5 · cyberstrikeus
    Encrypt traffic to HTTPS load balancers with TLS certificates (Manual)
    0
    installs
  62. Cis Oke V180 5 5 1 · cyberstrikeus
    Access Control and Container Engine for Kubernetes (Manual)
    0
    installs
  63. Cis Nginx V300 4 1 10 · cyberstrikeus
    Ensure the upstream traffic server certificate is trusted (Manual)
    0
    installs
  64. Cis Nginx V300 4 1 11 · cyberstrikeus
    Ensure Secure Session Resumption is Enabled (Manual)
    0
    installs
  65. Cis Nginx V300 4 1 12 · cyberstrikeus
    Ensure HTTP/3.0 is used (Manual)
    0
    installs
  66. T0800 Activate Firmware Update Mode · cyberstrikeus
    Adversaries may activate firmware update mode on devices to prevent expected response functions from engaging in reaction to an emergency or process malfunction.
    0
    installs
  67. T1637 001 Domain Generation Algorithms · cyberstrikeus
    Adversaries may use Domain Generation Algorithms (DGAs) to procedurally generate domain names for uses such as command and control communication or malicious application distribution.
    0
    installs
  68. Cryptographic Protection 03 13 11 Cryptographic Protection · cyberstrikeus
    Cryptographic Protection
    0
    installs
  69. Time Stamps 03 03 07 Time Stamps · cyberstrikeus
    Use internal system clocks to generate time stamps for audit records.
    0
    installs
  70. Least Functionality 03 04 06 Least Functionality · cyberstrikeus
    Configure the system to provide only mission-essential capabilities.
    0
    installs
  71. Device Identification And Authentication 03 05 02 Device Ide · cyberstrikeus
    Device Identification and Authentication
    0
    installs
  72. Physical Access Authorizations 03 10 01 Physical Access Auth · cyberstrikeus
    Develop, approve, and maintain a list of individuals with authorized access to the facility where the system resides.
    0
    installs
  73. Sp 800 171 03 14 04 031404 · cyberstrikeus
    03.14.04
    0
    installs
  74. Sp 800 171 03 14 05 031405 · cyberstrikeus
    03.14.05
    0
    installs
  75. Sp 800 171 03 14 07 031407 · cyberstrikeus
    03.14.07
    0
    installs
  76. Design Software To Meet Security Requirements And Mitigate S · cyberstrikeus
    Identify and evaluate the security requirements for the software;
    0
    installs
  77. Test Executable Code To Identify Vulnerabilities And Verify · cyberstrikeus
    Help identify vulnerabilities so that they can be corrected before the software is released in order to prevent exploitation.
    0
    installs
  78. Analyze Vulnerabilities To Identify Their Root Causes Rv 3 A · cyberstrikeus
    Help reduce the frequency of vulnerabilities in the future.
    0
    installs
  79. Au 5 Response To Audit Logging Process Failures · cyberstrikeus
    Alert [organization-defined] within [organization-defined] in the event of an audit logging process failure;
    0
    installs
  80. Au 7 Audit Record Reduction And Report Generation · cyberstrikeus
    Provide and implement an audit record reduction and report generation capability that: Supports on-demand audit record review, analysis, and reporting
    0
    installs
  81. Ca 5 Plan Of Action And Milestones · cyberstrikeus
    Develop a plan of action and milestones for the system to document the planned remediation actions of the organization to correct weaknesses or def...
    0
    installs
  82. Cm 2 2 Automation Support For Accuracy And Currency · cyberstrikeus
    Maintain the currency, completeness, accuracy, and availability of the baseline configuration of the system using [organization-defined].
    0
    installs
  83. Cm 8 1 Updates During Installation And Removal · cyberstrikeus
    Update the inventory of system components as part of component installations, removals, and system updates.
    0
    installs
  84. Ia 10 Adaptive Authentication · cyberstrikeus
    Require individuals accessing the system to employ [organization-defined] under specific [organization-defined].
    0
    installs
  85. Ia 12 5 Address Confirmation · cyberstrikeus
    Require that a [organization-defined] be delivered through an out-of-band channel to verify the users address (physical or digital) of record.
    0
    installs
  86. Ia 5 Authenticator Management · cyberstrikeus
    Manage system authenticators by: Verifying, as part of the initial authenticator distribution, the identity of the individual, group, role, service, o
    0
    installs
  87. Ia 8 2 Acceptance Of External Authenticators · cyberstrikeus
    Accept only external authenticators that are NIST-compliant;
    0
    installs
  88. Pe 17 Alternate Work Site · cyberstrikeus
    Determine and document the [organization-defined] allowed for use by employees;
    0
    installs
  89. Pe 19 Information Leakage · cyberstrikeus
    Protect the system from information leakage due to electromagnetic signals emanations.
    0
    installs
  90. Pe 3 3 Continuous Guards · cyberstrikeus
    Employ guards to control [organization-defined] to the facility where the system resides 24 hours per day, 7 days per week.
    0
    installs
  91. Pe 3 5 Tamper Protection · cyberstrikeus
    Employ [organization-defined] to [organization-defined] physical tampering or alteration of [organization-defined] within the system.
    0
    installs
  92. Pe 3 7 Physical Barriers · cyberstrikeus
    Limit access using physical barriers.
    0
    installs
  93. Pe 9 1 Redundant Cabling · cyberstrikeus
    Employ redundant power cabling paths that are physically separated by [organization-defined].
    0
    installs
  94. Pt 5 1 Just In Time Notice · cyberstrikeus
    Present notice of personally identifiable information processing to individuals at a time and location where the individual provides personally identi
    0
    installs
  95. Sa 11 9 Interactive Application Security Testing · cyberstrikeus
    Require the developer of the system, system component, or system service to employ interactive application security testing tools to identify flaws an
    0
    installs
  96. Sa 11 6 Attack Surface Reviews · cyberstrikeus
    Require the developer of the system, system component, or system service to perform attack surface reviews.
    0
    installs
  97. Sa 12 4 Diversity Of Suppliers · cyberstrikeus
    Diversity of Suppliers
    0
    installs
  98. Sa 15 6 Continuous Improvement · cyberstrikeus
    Require the developer of the system, system component, or system service to implement an explicit process to continuously improve the development proc
    0
    installs
  99. Sa 20 Customized Development Of Critical Components · cyberstrikeus
    Reimplement or custom develop the following critical system components: [organization-defined].
    0
    installs
  100. Sa 22 1 Alternative Sources For Continued Support · cyberstrikeus
    Alternative Sources for Continued Support
    0
    installs