Item Search

NameAudit NamePluginCategory
1.1.5 (L1) Ensure 'Password must meet complexity requirements' is set to 'Enabled'CIS Microsoft Windows Server 2016 v4.0.0 L1 MSWindows

IDENTIFICATION AND AUTHENTICATION

1.1.5 Ensure 'Password must meet complexity requirements' is set to 'Enabled'CIS Microsoft Windows Server 2025 v2.1.0 L1 DCWindows

IDENTIFICATION AND AUTHENTICATION

1.67 SOL-11.1-020560CIS Solaris 11 SPARC STIG v1.0.0 CAT IIUnix

CONFIGURATION MANAGEMENT

1.67 SOL-11.1-020560CIS Solaris 11 X86 STIG v1.0.0 CAT IIUnix

CONFIGURATION MANAGEMENT

BIND-9X-001910 - The BIND 9.x server implementation must be configured with a channel to send audit records to at least two remote syslogs.DISA BIND 9.x STIG v3r3Unix

AUDIT AND ACCOUNTABILITY

CNTR-K8-000150 - The Kubernetes Controller Manager must use TLS 1.2, at a minimum, to protect the confidentiality of sensitive data during electronic dissemination.DISA Kubernetes STIG v2r6Unix

ACCESS CONTROL

CNTR-K8-000160 - The Kubernetes Scheduler must use TLS 1.2, at a minimum, to protect the confidentiality of sensitive data during electronic dissemination.DISA Kubernetes STIG v2r6Unix

ACCESS CONTROL

CNTR-K8-000170 - The Kubernetes API Server must use TLS 1.2, at a minimum, to protect the confidentiality of sensitive data during electronic dissemination.DISA Kubernetes STIG v2r6Unix

ACCESS CONTROL

CNTR-K8-000180 - The Kubernetes etcd must use TLS to protect the confidentiality of sensitive data during electronic dissemination.DISA Kubernetes STIG v2r6Unix

ACCESS CONTROL

CNTR-K8-000220 - The Kubernetes Controller Manager must create unique service accounts for each work payload.DISA Kubernetes STIG v2r6Unix

ACCESS CONTROL

CNTR-K8-000270 - The Kubernetes API Server must enable Node,RBAC as the authorization mode.DISA Kubernetes STIG v2r6Unix

ACCESS CONTROL

CNTR-K8-000460 - Kubernetes DynamicKubeletConfig must not be enabled.DISA Kubernetes STIG v2r6Unix

ACCESS CONTROL

CNTR-K8-000470 - The Kubernetes API server must have Alpha APIs disabled.DISA Kubernetes STIG v2r6Unix

ACCESS CONTROL

CNTR-K8-000610 - The Kubernetes API Server must have an audit log path set.DISA Kubernetes STIG v2r6Unix

AUDIT AND ACCOUNTABILITY

CNTR-K8-000700 - Kubernetes API Server must generate audit records that identify what type of event has occurred, identify the source of the event, contain the event results, identify any users, and identify any containers associated with the event.DISA Kubernetes STIG v2r6Unix

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

CNTR-K8-000850 - Kubernetes Kubelet must deny hostname override.DISA Kubernetes STIG v2r6Unix

CONFIGURATION MANAGEMENT

CNTR-K8-000880 - The Kubernetes KubeletConfiguration file must be owned by root.DISA Kubernetes STIG v2r6Unix

CONFIGURATION MANAGEMENT

CNTR-K8-000890 - The Kubernetes KubeletConfiguration files must have file permissions set to 644 or more restrictive.DISA Kubernetes STIG v2r6Unix

CONFIGURATION MANAGEMENT

CNTR-K8-000900 - The Kubernetes manifest files must have least privileges.DISA Kubernetes STIG v2r6Unix

CONFIGURATION MANAGEMENT

CNTR-K8-000920 - The Kubernetes API Server must enforce ports, protocols, and services (PPS) that adhere to the Ports, Protocols, and Services Management Category Assurance List (PPSM CAL).DISA Kubernetes STIG v2r6Unix

CONFIGURATION MANAGEMENT

CNTR-K8-000930 - The Kubernetes Scheduler must enforce ports, protocols, and services (PPS) that adhere to the Ports, Protocols, and Services Management Category Assurance List (PPSM CAL).DISA Kubernetes STIG v2r6Unix

CONFIGURATION MANAGEMENT

CNTR-K8-000950 - The Kubernetes etcd must enforce ports, protocols, and services (PPS) that adhere to the Ports, Protocols, and Services Management Category Assurance List (PPSM CAL).DISA Kubernetes STIG v2r6Unix

CONFIGURATION MANAGEMENT

CNTR-K8-000960 - The Kubernetes cluster must use non-privileged host ports for user pods.DISA Kubernetes STIG v2r6Unix

CONFIGURATION MANAGEMENT

CNTR-K8-001161 - Sensitive information must be stored using Kubernetes Secrets or an external Secret store provider.DISA Kubernetes STIG v2r6Unix

IDENTIFICATION AND AUTHENTICATION

CNTR-K8-001360 - Kubernetes must separate user functionality.DISA Kubernetes STIG v2r6Unix

SYSTEM AND COMMUNICATIONS PROTECTION

CNTR-K8-001400 - The Kubernetes API server must use approved cipher suites.DISA Kubernetes STIG v2r6Unix

SYSTEM AND COMMUNICATIONS PROTECTION

CNTR-K8-001410 - Kubernetes API Server must have the SSL Certificate Authority set.DISA Kubernetes STIG v2r6Unix

SYSTEM AND COMMUNICATIONS PROTECTION

CNTR-K8-001450 - Kubernetes etcd must enable client authentication to secure service.DISA Kubernetes STIG v2r6Unix

SYSTEM AND COMMUNICATIONS PROTECTION

CNTR-K8-001460 - Kubernetes Kubelet must enable tlsPrivateKeyFile for client authentication to secure service.DISA Kubernetes STIG v2r6Unix

SYSTEM AND COMMUNICATIONS PROTECTION

CNTR-K8-001470 - Kubernetes Kubelet must enable tlsCertFile for client authentication to secure service.DISA Kubernetes STIG v2r6Unix

SYSTEM AND COMMUNICATIONS PROTECTION

CNTR-K8-001490 - Kubernetes etcd must have a key file for secure communication.DISA Kubernetes STIG v2r6Unix

SYSTEM AND COMMUNICATIONS PROTECTION

CNTR-K8-001500 - Kubernetes etcd must have a certificate for communication.DISA Kubernetes STIG v2r6Unix

SYSTEM AND COMMUNICATIONS PROTECTION

CNTR-K8-001520 - Kubernetes etcd must have a certificate for communication.DISA Kubernetes STIG v2r6Unix

SYSTEM AND COMMUNICATIONS PROTECTION

CNTR-K8-001540 - Kubernetes etcd must have peer-cert-file set for secure communication.DISA Kubernetes STIG v2r6Unix

SYSTEM AND COMMUNICATIONS PROTECTION

CNTR-K8-001550 - Kubernetes etcd must have a peer-key-file set for secure communication.DISA Kubernetes STIG v2r6Unix

SYSTEM AND COMMUNICATIONS PROTECTION

CNTR-K8-002010 - Kubernetes must have a pod security policy set.DISA Kubernetes STIG v2r6Unix

ACCESS CONTROL

CNTR-K8-002620 - Kubernetes API Server must disable basic authentication to protect information in transit.DISA Kubernetes STIG v2r6Unix

SYSTEM AND COMMUNICATIONS PROTECTION

CNTR-K8-002630 - Kubernetes API Server must disable token authentication to protect information in transit.DISA Kubernetes STIG v2r6Unix

SYSTEM AND COMMUNICATIONS PROTECTION

CNTR-K8-002640 - Kubernetes endpoints must use approved organizational certificate and key pair to protect information in transit.DISA Kubernetes STIG v2r6Unix

SYSTEM AND COMMUNICATIONS PROTECTION

CNTR-K8-003110 - The Kubernetes component manifests must be owned by root.DISA Kubernetes STIG v2r6Unix

CONFIGURATION MANAGEMENT

CNTR-K8-003120 - The Kubernetes component etcd must be owned by etcd.DISA Kubernetes STIG v2r6Unix

CONFIGURATION MANAGEMENT

CNTR-K8-003150 - The Kubernetes Kube Proxy kubeconfig must be owned by root.DISA Kubernetes STIG v2r6Unix

CONFIGURATION MANAGEMENT

CNTR-K8-003160 - The Kubernetes Kubelet certificate authority file must have file permissions set to 644 or more restrictive.DISA Kubernetes STIG v2r6Unix

CONFIGURATION MANAGEMENT

CNTR-K8-003190 - The Kubernetes kubelet KubeConfig must have file permissions set to 644 or more restrictive.DISA Kubernetes STIG v2r6Unix

CONFIGURATION MANAGEMENT

CNTR-K8-003200 - The Kubernetes kubelet KubeConfig file must be owned by root.DISA Kubernetes STIG v2r6Unix

CONFIGURATION MANAGEMENT

CNTR-K8-003230 - The Kubernetes kubelet config must have file permissions set to 644 or more restrictive.DISA Kubernetes STIG v2r6Unix

CONFIGURATION MANAGEMENT

CNTR-K8-003240 - The Kubernetes kubelet config must be owned by root.DISA Kubernetes STIG v2r6Unix

CONFIGURATION MANAGEMENT

CNTR-K8-003270 - The Kubernetes admin kubeconfig must have file permissions set to 644 or more restrictive.DISA Kubernetes STIG v2r6Unix

CONFIGURATION MANAGEMENT

SOL-11.1-020500 - Any X Windows host must write .Xauthority files.DISA Solaris 11 SPARC STIG v3r6Unix

CONFIGURATION MANAGEMENT

SOL-11.1-020500 - Any X Windows host must write .Xauthority files.DISA Solaris 11 X86 STIG v3r6Unix

CONFIGURATION MANAGEMENT