Item Search

NameAudit NamePluginCategory
1.262 ALMA-09-033350CIS Cloud Linux AlmaLinux OS 9 STIG v1.0.0 CAT IIUnix

IDENTIFICATION AND AUTHENTICATION

5.4.9 Ensure multifactor authentication for access to privileged accountsCIS Amazon Linux 2 STIG v2.0.1 STIGUnix

IDENTIFICATION AND AUTHENTICATION

CNTR-K8-000160 - The Kubernetes Scheduler must use TLS 1.2, at a minimum, to protect the confidentiality of sensitive data during electronic dissemination.DISA Kubernetes STIG v2r6Unix

ACCESS CONTROL

CNTR-K8-000170 - The Kubernetes API Server must use TLS 1.2, at a minimum, to protect the confidentiality of sensitive data during electronic dissemination.DISA Kubernetes STIG v2r6Unix

ACCESS CONTROL

CNTR-K8-000310 - The Kubernetes Controller Manager must have secure binding.DISA Kubernetes STIG v2r6Unix

ACCESS CONTROL

CNTR-K8-000350 - The Kubernetes API server must have the secure port set.DISA Kubernetes STIG v2r6Unix

ACCESS CONTROL

CNTR-K8-000360 - The Kubernetes API server must have anonymous authentication disabled.DISA Kubernetes STIG v2r6Unix

ACCESS CONTROL

CNTR-K8-000380 - The Kubernetes kubelet must enable explicit authorization.DISA Kubernetes STIG v2r6Unix

ACCESS CONTROL

CNTR-K8-000400 - Kubernetes Worker Nodes must not have sshd service running.DISA Kubernetes STIG v2r6Unix

ACCESS CONTROL

CNTR-K8-000430 - Kubernetes Kubectl cp command must give expected access and results.DISA Kubernetes STIG v2r6Unix

ACCESS CONTROL

CNTR-K8-000860 - The Kubernetes manifests must be owned by root.DISA Kubernetes STIG v2r6Unix

CONFIGURATION MANAGEMENT

CNTR-K8-000910 - Kubernetes Controller Manager must disable profiling.DISA Kubernetes STIG v2r6Unix

CONFIGURATION MANAGEMENT

CNTR-K8-000940 - The Kubernetes Controllers must enforce ports, protocols, and services (PPS) that adhere to the Ports, Protocols, and Services Management Category Assurance List (PPSM CAL).DISA Kubernetes STIG v2r6Unix

CONFIGURATION MANAGEMENT

CNTR-K8-001162 - Kubernetes Secrets must be encrypted at rest.DISA Kubernetes STIG v2r6Unix

ACCESS CONTROL

CNTR-K8-001163 - Kubernetes must limit Secret access on a need-to-know basis.DISA Kubernetes STIG v2r6Unix

SYSTEM AND COMMUNICATIONS PROTECTION

CNTR-K8-001300 - Kubernetes Kubelet must not disable timeouts.DISA Kubernetes STIG v2r6Unix

SYSTEM AND COMMUNICATIONS PROTECTION

CNTR-K8-001400 - The Kubernetes API server must use approved cipher suites.DISA Kubernetes STIG v2r6Unix

SYSTEM AND COMMUNICATIONS PROTECTION

CNTR-K8-001430 - Kubernetes Controller Manager must have the SSL Certificate Authority set.DISA Kubernetes STIG v2r6Unix

SYSTEM AND COMMUNICATIONS PROTECTION

CNTR-K8-001440 - Kubernetes API Server must have a certificate for communication.DISA Kubernetes STIG v2r6Unix

SYSTEM AND COMMUNICATIONS PROTECTION

CNTR-K8-001460 - Kubernetes Kubelet must enable tlsPrivateKeyFile for client authentication to secure service.DISA Kubernetes STIG v2r6Unix

SYSTEM AND COMMUNICATIONS PROTECTION

CNTR-K8-001470 - Kubernetes Kubelet must enable tlsCertFile for client authentication to secure service.DISA Kubernetes STIG v2r6Unix

SYSTEM AND COMMUNICATIONS PROTECTION

CNTR-K8-001480 - Kubernetes etcd must enable client authentication to secure service.DISA Kubernetes STIG v2r6Unix

SYSTEM AND COMMUNICATIONS PROTECTION

CNTR-K8-001500 - Kubernetes etcd must have a certificate for communication.DISA Kubernetes STIG v2r6Unix

SYSTEM AND COMMUNICATIONS PROTECTION

CNTR-K8-001530 - Kubernetes etcd must have a key file for secure communication.DISA Kubernetes STIG v2r6Unix

SYSTEM AND COMMUNICATIONS PROTECTION

CNTR-K8-001540 - Kubernetes etcd must have peer-cert-file set for secure communication.DISA Kubernetes STIG v2r6Unix

SYSTEM AND COMMUNICATIONS PROTECTION

CNTR-K8-001550 - Kubernetes etcd must have a peer-key-file set for secure communication.DISA Kubernetes STIG v2r6Unix

SYSTEM AND COMMUNICATIONS PROTECTION

CNTR-K8-001620 - Kubernetes Kubelet must enable kernel protection.DISA Kubernetes STIG v2r6Unix

SYSTEM AND COMMUNICATIONS PROTECTION

CNTR-K8-002010 - Kubernetes must have a pod security policy set.DISA Kubernetes STIG v2r6Unix

ACCESS CONTROL

CNTR-K8-002600 - Kubernetes API Server must configure timeouts to limit attack surface.DISA Kubernetes STIG v2r6Unix

SYSTEM AND COMMUNICATIONS PROTECTION

CNTR-K8-002630 - Kubernetes API Server must disable token authentication to protect information in transit.DISA Kubernetes STIG v2r6Unix

SYSTEM AND COMMUNICATIONS PROTECTION

CNTR-K8-002640 - Kubernetes endpoints must use approved organizational certificate and key pair to protect information in transit.DISA Kubernetes STIG v2r6Unix

SYSTEM AND COMMUNICATIONS PROTECTION

CNTR-K8-003110 - The Kubernetes component manifests must be owned by root.DISA Kubernetes STIG v2r6Unix

CONFIGURATION MANAGEMENT

CNTR-K8-003120 - The Kubernetes component etcd must be owned by etcd.DISA Kubernetes STIG v2r6Unix

CONFIGURATION MANAGEMENT

CNTR-K8-003130 - The Kubernetes conf files must be owned by root.DISA Kubernetes STIG v2r6Unix

CONFIGURATION MANAGEMENT

CNTR-K8-003140 - The Kubernetes Kube Proxy kubeconfig must have file permissions set to 644 or more restrictive.DISA Kubernetes STIG v2r6Unix

CONFIGURATION MANAGEMENT

CNTR-K8-003160 - The Kubernetes Kubelet certificate authority file must have file permissions set to 644 or more restrictive.DISA Kubernetes STIG v2r6Unix

CONFIGURATION MANAGEMENT

CNTR-K8-003170 - The Kubernetes Kubelet certificate authority must be owned by root.DISA Kubernetes STIG v2r6Unix

CONFIGURATION MANAGEMENT

CNTR-K8-003200 - The Kubernetes kubelet KubeConfig file must be owned by root.DISA Kubernetes STIG v2r6Unix

CONFIGURATION MANAGEMENT

CNTR-K8-003210 - The Kubernetes kubeadm.conf must be owned by root.DISA Kubernetes STIG v2r6Unix

CONFIGURATION MANAGEMENT

CNTR-K8-003220 - The Kubernetes kubeadm.conf must have file permissions set to 644 or more restrictive.DISA Kubernetes STIG v2r6Unix

CONFIGURATION MANAGEMENT

CNTR-K8-003240 - The Kubernetes kubelet config must be owned by root.DISA Kubernetes STIG v2r6Unix

CONFIGURATION MANAGEMENT

CNTR-K8-003270 - The Kubernetes admin kubeconfig must have file permissions set to 644 or more restrictive.DISA Kubernetes STIG v2r6Unix

CONFIGURATION MANAGEMENT

CNTR-K8-003280 - Kubernetes API Server audit logs must be enabled.DISA Kubernetes STIG v2r6Unix

CONFIGURATION MANAGEMENT

CNTR-K8-003300 - The Kubernetes API Server must be set to audit log maximum backup.DISA Kubernetes STIG v2r6Unix

CONFIGURATION MANAGEMENT

CNTR-K8-003320 - The Kubernetes API Server audit log path must be set.DISA Kubernetes STIG v2r6Unix

CONFIGURATION MANAGEMENT

CNTR-K8-003330 - The Kubernetes PKI CRT must have file permissions set to 644 or more restrictive.DISA Kubernetes STIG v2r6Unix

CONFIGURATION MANAGEMENT

CNTR-K8-003340 - The Kubernetes PKI keys must have file permissions set to 600 or more restrictive.DISA Kubernetes STIG v2r6Unix

CONFIGURATION MANAGEMENT

RHEL-07-041001 - The Red Hat Enterprise Linux operating system must have the required packages for multifactor authentication installed.DISA Red Hat Enterprise Linux 7 STIG v3r15Unix

IDENTIFICATION AND AUTHENTICATION

RHEL-07-041003 - The Red Hat Enterprise Linux operating system must implement certificate status checking for PKI authentication.DISA Red Hat Enterprise Linux 7 STIG v3r15Unix

IDENTIFICATION AND AUTHENTICATION

SLES-12-030500 - The SUSE operating system must have the packages required for multifactor authentication to be installed.DISA SLES 12 STIG v3r5Unix

IDENTIFICATION AND AUTHENTICATION