Item Search

NameAudit NamePluginCategory
1.1.1 Ensure that the API server pod specification file permissions are set to 600 or more restrictiveCIS Red Hat OpenShift Container Platform v1.9.0 L1OpenShift

ACCESS CONTROL, MEDIA PROTECTION

1.1.3 Ensure that the controller manager pod specification file permissions are set to 600 or more restrictiveCIS Red Hat OpenShift Container Platform v1.9.0 L1OpenShift

ACCESS CONTROL, MEDIA PROTECTION

1.1.7 Ensure that the etcd pod specification file permissions are set to 600 or more restrictiveCIS Red Hat OpenShift Container Platform v1.9.0 L1OpenShift

ACCESS CONTROL, MEDIA PROTECTION

1.1.8 Ensure that the etcd pod specification file ownership is set to root:rootCIS Red Hat OpenShift Container Platform v1.9.0 L1OpenShift

ACCESS CONTROL

1.1.11 Ensure that the etcd data directory permissions are set to 700 or more restrictiveCIS Red Hat OpenShift Container Platform v1.9.0 L1OpenShift

ACCESS CONTROL, MEDIA PROTECTION

1.1.12 Ensure that the etcd data directory ownership is set to root:rootCIS Red Hat OpenShift Container Platform v1.9.0 L1OpenShift

ACCESS CONTROL

1.1.13 Ensure that the kubeconfig file permissions are set to 600 or more restrictiveCIS Red Hat OpenShift Container Platform v1.9.0 L1OpenShift

ACCESS CONTROL, MEDIA PROTECTION

1.1.21 Ensure that the OpenShift PKI key file permissions are set to 600CIS Red Hat OpenShift Container Platform v1.9.0 L1OpenShift

ACCESS CONTROL, MEDIA PROTECTION

1.2.1 Ensure that anonymous requests are authorizedCIS Red Hat OpenShift Container Platform v1.9.0 L1OpenShift

ACCESS CONTROL, MEDIA PROTECTION

1.2.4 Verify that the kubelet certificate authority is set as appropriateCIS Red Hat OpenShift Container Platform v1.9.0 L1OpenShift

SYSTEM AND SERVICES ACQUISITION

1.2.6 Verify that RBAC is enabledCIS Red Hat OpenShift Container Platform v1.9.0 L1OpenShift

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

1.2.7 Ensure that the APIPriorityAndFairness feature gate is enabledCIS Red Hat OpenShift Container Platform v1.9.0 L1OpenShift

ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION

1.2.8 Ensure that the admission control plugin AlwaysAdmit is not setCIS Red Hat OpenShift Container Platform v1.9.0 L1OpenShift

ACCESS CONTROL, MEDIA PROTECTION

1.2.9 Ensure that the admission control plugin AlwaysPullImages is not setCIS Red Hat OpenShift Container Platform v1.9.0 L1OpenShift

ACCESS CONTROL, MEDIA PROTECTION

1.2.10 Ensure that the admission control plugin ServiceAccount is setCIS Red Hat OpenShift Container Platform v1.9.0 L1OpenShift

ACCESS CONTROL, MEDIA PROTECTION

1.2.12 Ensure that the admission control plugin SecurityContextConstraint is setCIS Red Hat OpenShift Container Platform v1.9.0 L1OpenShift

SYSTEM AND SERVICES ACQUISITION

1.2.15 Ensure that the --insecure-port argument is set to 0CIS Red Hat OpenShift Container Platform v1.9.0 L1OpenShift

SYSTEM AND SERVICES ACQUISITION

1.2.20 Ensure that the maximumRetainedFiles argument is set to 10 or as appropriateCIS Red Hat OpenShift Container Platform v1.9.0 L1OpenShift

AUDIT AND ACCOUNTABILITY

1.2.21 Configure Kubernetes API Server Maximum Audit Log SizeCIS Red Hat OpenShift Container Platform v1.9.0 L1OpenShift

AUDIT AND ACCOUNTABILITY

1.2.25 Ensure that the --etcd-certfile and --etcd-keyfile arguments are set as appropriateCIS Red Hat OpenShift Container Platform v1.9.0 L1OpenShift

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

1.2.26 Ensure that the --tls-cert-file and --tls-private-key-file arguments are set as appropriateCIS Red Hat OpenShift Container Platform v1.9.0 L1OpenShift

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

1.2.27 Ensure that the --client-ca-file argument is set as appropriateCIS Red Hat OpenShift Container Platform v1.9.0 L1OpenShift

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

1.2.29 Ensure that encryption providers are appropriately configuredCIS Red Hat OpenShift Container Platform v1.9.0 L1OpenShift

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

1.3.3 Ensure that the --service-account-private-key-file argument is set as appropriateCIS Red Hat OpenShift Container Platform v1.9.0 L1OpenShift

IDENTIFICATION AND AUTHENTICATION

1.4.1 Ensure that the healthz endpoints for the scheduler are protected by RBACCIS Red Hat OpenShift Container Platform v1.9.0 L1OpenShift

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

2.1 Ensure that the --cert-file and --key-file arguments are set as appropriateCIS Red Hat OpenShift Container Platform v1.9.0 L1OpenShift

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

2.7 Ensure that a unique Certificate Authority is used for etcdCIS Red Hat OpenShift Container Platform v1.9.0 L2 OpenShiftOpenShift

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

3.1.1 Client certificate authentication should not be used for usersCIS Red Hat OpenShift Container Platform v1.9.0 L2 OpenShiftOpenShift

CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

3.2.2 Ensure that the audit policy covers key security concernsCIS Red Hat OpenShift Container Platform v1.9.0 L2 OpenShiftOpenShift

AUDIT AND ACCOUNTABILITY

4.1.2 Ensure that the kubelet service file ownership is set to root:rootCIS Red Hat OpenShift Container Platform v1.9.0 L1OpenShift

ACCESS CONTROL

4.1.5 Ensure that the --kubeconfig kubelet.conf file permissions are set to 644 or more restrictiveCIS Red Hat OpenShift Container Platform v1.9.0 L1OpenShift

ACCESS CONTROL, MEDIA PROTECTION

4.1.6 Ensure that the --kubeconfig kubelet.conf file ownership is set to root:rootCIS Red Hat OpenShift Container Platform v1.9.0 L1OpenShift

ACCESS CONTROL

4.1.7 Ensure that the certificate authorities file permissions are set to 644 or more restrictiveCIS Red Hat OpenShift Container Platform v1.9.0 L1OpenShift

ACCESS CONTROL, MEDIA PROTECTION

4.2.1 Activate Garbage collection in OpenShift Container Platform 4, as appropriateCIS Red Hat OpenShift Container Platform v1.9.0 L1OpenShift

SYSTEM AND INFORMATION INTEGRITY

4.2.8 Ensure that the kubeAPIQPS [--event-qps] argument is set to a level which ensures appropriate event captureCIS Red Hat OpenShift Container Platform v1.9.0 L2 OpenShiftOpenShift

AUDIT AND ACCOUNTABILITY

4.2.10 Ensure that the --rotate-certificates argument is not set to falseCIS Red Hat OpenShift Container Platform v1.9.0 L2 OpenShiftOpenShift

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

4.2.11 Verify that the RotateKubeletServerCertificate argument is set to trueCIS Red Hat OpenShift Container Platform v1.9.0 L2 OpenShiftOpenShift

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

4.2.12 Ensure that the Kubelet only makes use of Strong Cryptographic CiphersCIS Red Hat OpenShift Container Platform v1.9.0 L1OpenShift

IDENTIFICATION AND AUTHENTICATION

5.1.6 Ensure that Service Account Tokens are only mounted where necessaryCIS Red Hat OpenShift Container Platform v1.9.0 L1OpenShift

CONFIGURATION MANAGEMENT

5.2.2 Minimize the admission of containers wishing to share the host process ID namespaceCIS Red Hat OpenShift Container Platform v1.9.0 L1OpenShift

ACCESS CONTROL

5.2.6 Minimize the admission of root containersCIS Red Hat OpenShift Container Platform v1.9.0 L2 OpenShiftOpenShift

ACCESS CONTROL, SYSTEM AND INFORMATION INTEGRITY

5.2.9 Minimize the admission of containers with capabilities assignedCIS Red Hat OpenShift Container Platform v1.9.0 L2 OpenShiftOpenShift

CONFIGURATION MANAGEMENT

5.2.10 Minimize access to privileged Security Context ConstraintsCIS Red Hat OpenShift Container Platform v1.9.0 L2 OpenShiftOpenShift

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

5.3.2 Ensure that all Namespaces have Network Policies definedCIS Red Hat OpenShift Container Platform v1.9.0 L2 OpenShiftOpenShift

SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

5.4.1 Prefer using secrets as files over secrets as environment variablesCIS Red Hat OpenShift Container Platform v1.9.0 L2 OpenShiftOpenShift

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

5.4.2 Consider external secret storageCIS Red Hat OpenShift Container Platform v1.9.0 L2 OpenShiftOpenShift

SYSTEM AND COMMUNICATIONS PROTECTION

5.5.1 Configure Image Provenance using image controller configuration parametersCIS Red Hat OpenShift Container Platform v1.9.0 L2 OpenShiftOpenShift

CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

5.7.2 Ensure that the seccomp profile is set to docker/default in your pod definitionsCIS Red Hat OpenShift Container Platform v1.9.0 L2 OpenShiftOpenShift

CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

5.7.3 Apply Security Context to Your Pods and ContainersCIS Red Hat OpenShift Container Platform v1.9.0 L2 OpenShiftOpenShift

RISK ASSESSMENT, SYSTEM AND INFORMATION INTEGRITY

5.7.4 The default namespace should not be usedCIS Red Hat OpenShift Container Platform v1.9.0 L2 OpenShiftOpenShift

SYSTEM AND COMMUNICATIONS PROTECTION