| 1.262 ALMA-09-033350 | CIS Cloud Linux AlmaLinux OS 9 STIG v1.0.0 CAT II | Unix | IDENTIFICATION AND AUTHENTICATION |
| 5.4.9 Ensure multifactor authentication for access to privileged accounts | CIS Amazon Linux 2 STIG v2.0.1 STIG | Unix | IDENTIFICATION AND AUTHENTICATION |
| CNTR-K8-000160 - The Kubernetes Scheduler must use TLS 1.2, at a minimum, to protect the confidentiality of sensitive data during electronic dissemination. | DISA Kubernetes STIG v2r6 | Unix | ACCESS CONTROL |
| CNTR-K8-000170 - The Kubernetes API Server must use TLS 1.2, at a minimum, to protect the confidentiality of sensitive data during electronic dissemination. | DISA Kubernetes STIG v2r6 | Unix | ACCESS CONTROL |
| CNTR-K8-000310 - The Kubernetes Controller Manager must have secure binding. | DISA Kubernetes STIG v2r6 | Unix | ACCESS CONTROL |
| CNTR-K8-000350 - The Kubernetes API server must have the secure port set. | DISA Kubernetes STIG v2r6 | Unix | ACCESS CONTROL |
| CNTR-K8-000360 - The Kubernetes API server must have anonymous authentication disabled. | DISA Kubernetes STIG v2r6 | Unix | ACCESS CONTROL |
| CNTR-K8-000380 - The Kubernetes kubelet must enable explicit authorization. | DISA Kubernetes STIG v2r6 | Unix | ACCESS CONTROL |
| CNTR-K8-000400 - Kubernetes Worker Nodes must not have sshd service running. | DISA Kubernetes STIG v2r6 | Unix | ACCESS CONTROL |
| CNTR-K8-000430 - Kubernetes Kubectl cp command must give expected access and results. | DISA Kubernetes STIG v2r6 | Unix | ACCESS CONTROL |
| CNTR-K8-000860 - The Kubernetes manifests must be owned by root. | DISA Kubernetes STIG v2r6 | Unix | CONFIGURATION MANAGEMENT |
| CNTR-K8-000910 - Kubernetes Controller Manager must disable profiling. | DISA Kubernetes STIG v2r6 | Unix | CONFIGURATION MANAGEMENT |
| CNTR-K8-000940 - The Kubernetes Controllers must enforce ports, protocols, and services (PPS) that adhere to the Ports, Protocols, and Services Management Category Assurance List (PPSM CAL). | DISA Kubernetes STIG v2r6 | Unix | CONFIGURATION MANAGEMENT |
| CNTR-K8-001162 - Kubernetes Secrets must be encrypted at rest. | DISA Kubernetes STIG v2r6 | Unix | ACCESS CONTROL |
| CNTR-K8-001163 - Kubernetes must limit Secret access on a need-to-know basis. | DISA Kubernetes STIG v2r6 | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| CNTR-K8-001300 - Kubernetes Kubelet must not disable timeouts. | DISA Kubernetes STIG v2r6 | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| CNTR-K8-001400 - The Kubernetes API server must use approved cipher suites. | DISA Kubernetes STIG v2r6 | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| CNTR-K8-001430 - Kubernetes Controller Manager must have the SSL Certificate Authority set. | DISA Kubernetes STIG v2r6 | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| CNTR-K8-001440 - Kubernetes API Server must have a certificate for communication. | DISA Kubernetes STIG v2r6 | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| CNTR-K8-001460 - Kubernetes Kubelet must enable tlsPrivateKeyFile for client authentication to secure service. | DISA Kubernetes STIG v2r6 | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| CNTR-K8-001470 - Kubernetes Kubelet must enable tlsCertFile for client authentication to secure service. | DISA Kubernetes STIG v2r6 | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| CNTR-K8-001480 - Kubernetes etcd must enable client authentication to secure service. | DISA Kubernetes STIG v2r6 | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| CNTR-K8-001500 - Kubernetes etcd must have a certificate for communication. | DISA Kubernetes STIG v2r6 | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| CNTR-K8-001530 - Kubernetes etcd must have a key file for secure communication. | DISA Kubernetes STIG v2r6 | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| CNTR-K8-001540 - Kubernetes etcd must have peer-cert-file set for secure communication. | DISA Kubernetes STIG v2r6 | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| CNTR-K8-001550 - Kubernetes etcd must have a peer-key-file set for secure communication. | DISA Kubernetes STIG v2r6 | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| CNTR-K8-001620 - Kubernetes Kubelet must enable kernel protection. | DISA Kubernetes STIG v2r6 | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| CNTR-K8-002010 - Kubernetes must have a pod security policy set. | DISA Kubernetes STIG v2r6 | Unix | ACCESS CONTROL |
| CNTR-K8-002600 - Kubernetes API Server must configure timeouts to limit attack surface. | DISA Kubernetes STIG v2r6 | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| CNTR-K8-002630 - Kubernetes API Server must disable token authentication to protect information in transit. | DISA Kubernetes STIG v2r6 | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| CNTR-K8-002640 - Kubernetes endpoints must use approved organizational certificate and key pair to protect information in transit. | DISA Kubernetes STIG v2r6 | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| CNTR-K8-003110 - The Kubernetes component manifests must be owned by root. | DISA Kubernetes STIG v2r6 | Unix | CONFIGURATION MANAGEMENT |
| CNTR-K8-003120 - The Kubernetes component etcd must be owned by etcd. | DISA Kubernetes STIG v2r6 | Unix | CONFIGURATION MANAGEMENT |
| CNTR-K8-003130 - The Kubernetes conf files must be owned by root. | DISA Kubernetes STIG v2r6 | Unix | CONFIGURATION MANAGEMENT |
| CNTR-K8-003140 - The Kubernetes Kube Proxy kubeconfig must have file permissions set to 644 or more restrictive. | DISA Kubernetes STIG v2r6 | Unix | CONFIGURATION MANAGEMENT |
| CNTR-K8-003160 - The Kubernetes Kubelet certificate authority file must have file permissions set to 644 or more restrictive. | DISA Kubernetes STIG v2r6 | Unix | CONFIGURATION MANAGEMENT |
| CNTR-K8-003170 - The Kubernetes Kubelet certificate authority must be owned by root. | DISA Kubernetes STIG v2r6 | Unix | CONFIGURATION MANAGEMENT |
| CNTR-K8-003200 - The Kubernetes kubelet KubeConfig file must be owned by root. | DISA Kubernetes STIG v2r6 | Unix | CONFIGURATION MANAGEMENT |
| CNTR-K8-003210 - The Kubernetes kubeadm.conf must be owned by root. | DISA Kubernetes STIG v2r6 | Unix | CONFIGURATION MANAGEMENT |
| CNTR-K8-003220 - The Kubernetes kubeadm.conf must have file permissions set to 644 or more restrictive. | DISA Kubernetes STIG v2r6 | Unix | CONFIGURATION MANAGEMENT |
| CNTR-K8-003240 - The Kubernetes kubelet config must be owned by root. | DISA Kubernetes STIG v2r6 | Unix | CONFIGURATION MANAGEMENT |
| CNTR-K8-003270 - The Kubernetes admin kubeconfig must have file permissions set to 644 or more restrictive. | DISA Kubernetes STIG v2r6 | Unix | CONFIGURATION MANAGEMENT |
| CNTR-K8-003280 - Kubernetes API Server audit logs must be enabled. | DISA Kubernetes STIG v2r6 | Unix | CONFIGURATION MANAGEMENT |
| CNTR-K8-003300 - The Kubernetes API Server must be set to audit log maximum backup. | DISA Kubernetes STIG v2r6 | Unix | CONFIGURATION MANAGEMENT |
| CNTR-K8-003320 - The Kubernetes API Server audit log path must be set. | DISA Kubernetes STIG v2r6 | Unix | CONFIGURATION MANAGEMENT |
| CNTR-K8-003330 - The Kubernetes PKI CRT must have file permissions set to 644 or more restrictive. | DISA Kubernetes STIG v2r6 | Unix | CONFIGURATION MANAGEMENT |
| CNTR-K8-003340 - The Kubernetes PKI keys must have file permissions set to 600 or more restrictive. | DISA Kubernetes STIG v2r6 | Unix | CONFIGURATION MANAGEMENT |
| RHEL-07-041001 - The Red Hat Enterprise Linux operating system must have the required packages for multifactor authentication installed. | DISA Red Hat Enterprise Linux 7 STIG v3r15 | Unix | IDENTIFICATION AND AUTHENTICATION |
| RHEL-07-041003 - The Red Hat Enterprise Linux operating system must implement certificate status checking for PKI authentication. | DISA Red Hat Enterprise Linux 7 STIG v3r15 | Unix | IDENTIFICATION AND AUTHENTICATION |
| SLES-12-030500 - The SUSE operating system must have the packages required for multifactor authentication to be installed. | DISA SLES 12 STIG v3r5 | Unix | IDENTIFICATION AND AUTHENTICATION |