| 1.1.2 Ensure that the API server pod specification file ownership is set to root:root | CIS Red Hat OpenShift Container Platform v1.9.0 L1 | OpenShift | ACCESS CONTROL |
| 1.1.4 Ensure that the controller manager pod specification file ownership is set to root:root | CIS Red Hat OpenShift Container Platform v1.9.0 L1 | OpenShift | ACCESS CONTROL |
| 1.1.5 Ensure that the scheduler pod specification file permissions are set to 600 or more restrictive | CIS Red Hat OpenShift Container Platform v1.9.0 L1 | OpenShift | ACCESS CONTROL, MEDIA PROTECTION |
| 1.1.6 Ensure that the scheduler pod specification file ownership is set to root:root | CIS Red Hat OpenShift Container Platform v1.9.0 L1 | OpenShift | ACCESS CONTROL |
| 1.1.9 Ensure that the Container Network Interface file permissions are set to 600 or more restrictive | CIS Red Hat OpenShift Container Platform v1.9.0 L1 | OpenShift | ACCESS CONTROL, MEDIA PROTECTION |
| 1.1.10 Ensure that the Container Network Interface file ownership is set to root:root | CIS Red Hat OpenShift Container Platform v1.9.0 L1 | OpenShift | ACCESS CONTROL |
| 1.1.14 Ensure that the kubeconfig file ownership is set to root:root | CIS Red Hat OpenShift Container Platform v1.9.0 L1 | OpenShift | ACCESS CONTROL |
| 1.1.15 Ensure that the Scheduler kubeconfig file permissions are set to 600 or more restrictive | CIS Red Hat OpenShift Container Platform v1.9.0 L1 | OpenShift | ACCESS CONTROL, MEDIA PROTECTION |
| 1.1.16 Ensure that the Scheduler kubeconfig file ownership is set to root:root | CIS Red Hat OpenShift Container Platform v1.9.0 L1 | OpenShift | ACCESS CONTROL |
| 1.1.17 Ensure that the Controller Manager kubeconfig file permissions are set to 600 or more restrictive | CIS Red Hat OpenShift Container Platform v1.9.0 L1 | OpenShift | ACCESS CONTROL, MEDIA PROTECTION |
| 1.1.18 Ensure that the Controller Manager kubeconfig file ownership is set to root:root | CIS Red Hat OpenShift Container Platform v1.9.0 L1 | OpenShift | ACCESS CONTROL |
| 1.1.19 Ensure that the OpenShift PKI directory and file ownership is set to root:root | CIS Red Hat OpenShift Container Platform v1.9.0 L1 | OpenShift | ACCESS CONTROL |
| 1.1.20 Ensure that the OpenShift PKI certificate file permissions are set to 600 or more restrictive | CIS Red Hat OpenShift Container Platform v1.9.0 L1 | OpenShift | ACCESS CONTROL, MEDIA PROTECTION |
| 1.2.3 Ensure that the kubelet uses certificates to authenticate | CIS Red Hat OpenShift Container Platform v1.9.0 L1 | OpenShift | SYSTEM AND SERVICES ACQUISITION |
| 1.2.5 Ensure that the --authorization-mode argument is not set to AlwaysAllow | CIS Red Hat OpenShift Container Platform v1.9.0 L1 | OpenShift | ACCESS CONTROL, MEDIA PROTECTION |
| 1.2.11 Ensure that the admission control plugin NamespaceLifecycle is set | CIS Red Hat OpenShift Container Platform v1.9.0 L1 | OpenShift | CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION |
| 1.2.16 Ensure that the --secure-port argument is not set to 0 | CIS Red Hat OpenShift Container Platform v1.9.0 L1 | OpenShift | ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION |
| 1.2.17 Ensure that the healthz endpoint is protected by RBAC | CIS Red Hat OpenShift Container Platform v1.9.0 L1 | OpenShift | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY |
| 1.2.18 Ensure that the --audit-log-path argument is set | CIS Red Hat OpenShift Container Platform v1.9.0 L1 | OpenShift | AUDIT AND ACCOUNTABILITY |
| 1.2.19 Ensure that the audit logs are forwarded off the cluster for retention | CIS Red Hat OpenShift Container Platform v1.9.0 L1 | OpenShift | AUDIT AND ACCOUNTABILITY |
| 1.2.23 Ensure that the --service-account-lookup argument is set to true | CIS Red Hat OpenShift Container Platform v1.9.0 L1 | OpenShift | ACCESS CONTROL, MEDIA PROTECTION |
| 1.2.30 Ensure that the API Server only makes use of Strong Cryptographic Ciphers | CIS Red Hat OpenShift Container Platform v1.9.0 L1 | OpenShift | CONFIGURATION MANAGEMENT |
| 1.2.31 Ensure unsupported configuration overrides are not used | CIS Red Hat OpenShift Container Platform v1.9.0 L1 | OpenShift | SYSTEM AND SERVICES ACQUISITION |
| 1.3.1 Ensure that controller manager healthz endpoints are protected by RBAC | CIS Red Hat OpenShift Container Platform v1.9.0 L1 | OpenShift | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY |
| 1.3.2 Ensure that the --use-service-account-credentials argument is set to true | CIS Red Hat OpenShift Container Platform v1.9.0 L1 | OpenShift | IDENTIFICATION AND AUTHENTICATION |
| 1.4.2 Verify that the scheduler API service is protected by RBAC | CIS Red Hat OpenShift Container Platform v1.9.0 L1 | OpenShift | SYSTEM AND COMMUNICATIONS PROTECTION |
| 2.2 Ensure that the --client-cert-auth argument is set to true | CIS Red Hat OpenShift Container Platform v1.9.0 L1 | OpenShift | IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION |
| 2.3 Ensure that the --auto-tls argument is not set to true | CIS Red Hat OpenShift Container Platform v1.9.0 L1 | OpenShift | ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION |
| 2.4 Ensure that the --peer-cert-file and --peer-key-file arguments are set as appropriate | CIS Red Hat OpenShift Container Platform v1.9.0 L1 | OpenShift | ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION |
| 2.6 Ensure that the --peer-auto-tls argument is not set to true | CIS Red Hat OpenShift Container Platform v1.9.0 L1 | OpenShift | IDENTIFICATION AND AUTHENTICATION |
| 3.2.1 Ensure that a minimal audit policy is created | CIS Red Hat OpenShift Container Platform v1.9.0 L1 | OpenShift | AUDIT AND ACCOUNTABILITY |
| 4.1.1 Ensure that the kubelet service file permissions are set to 644 or more restrictive | CIS Red Hat OpenShift Container Platform v1.9.0 L1 | OpenShift | ACCESS CONTROL, MEDIA PROTECTION |
| 4.1.8 Ensure that the client certificate authorities file ownership is set to root:root | CIS Red Hat OpenShift Container Platform v1.9.0 L1 | OpenShift | ACCESS CONTROL |
| 4.1.9 Ensure that the kubelet --config configuration file has permissions set to 600 or more restrictive | CIS Red Hat OpenShift Container Platform v1.9.0 L1 | OpenShift | ACCESS CONTROL |
| 4.2.2 Ensure that the --anonymous-auth argument is set to false | CIS Red Hat OpenShift Container Platform v1.9.0 L1 | OpenShift | ACCESS CONTROL, MEDIA PROTECTION |
| 4.2.3 Ensure that the --authorization-mode argument is not set to AlwaysAllow | CIS Red Hat OpenShift Container Platform v1.9.0 L1 | OpenShift | ACCESS CONTROL, MEDIA PROTECTION |
| 4.2.4 Ensure that the --client-ca-file argument is set as appropriate | CIS Red Hat OpenShift Container Platform v1.9.0 L1 | OpenShift | IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION |
| 4.2.7 Ensure that the --make-iptables-util-chains argument is set to true | CIS Red Hat OpenShift Container Platform v1.9.0 L1 | OpenShift | SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION |
| 4.2.9 Ensure that the --tls-cert-file and --tls-private-key-file arguments are set as appropriate | CIS Red Hat OpenShift Container Platform v1.9.0 L1 | OpenShift | ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION |
| 5.1.1 Ensure that the cluster-admin role is only used where required | CIS Red Hat OpenShift Container Platform v1.9.0 L1 | OpenShift | ACCESS CONTROL |
| 5.1.2 Minimize access to secrets | CIS Red Hat OpenShift Container Platform v1.9.0 L1 | OpenShift | SYSTEM AND COMMUNICATIONS PROTECTION |
| 5.1.3 Minimize wildcard use in Roles and ClusterRoles | CIS Red Hat OpenShift Container Platform v1.9.0 L1 | OpenShift | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY |
| 5.1.4 Minimize access to create pods | CIS Red Hat OpenShift Container Platform v1.9.0 L1 | OpenShift | CONFIGURATION MANAGEMENT, SYSTEM AND INFORMATION INTEGRITY |
| 5.1.5 Ensure that default service accounts are not actively used. | CIS Red Hat OpenShift Container Platform v1.9.0 L1 | OpenShift | ACCESS CONTROL |
| 5.2.1 Minimize the admission of privileged containers | CIS Red Hat OpenShift Container Platform v1.9.0 L1 | OpenShift | ACCESS CONTROL, SYSTEM AND INFORMATION INTEGRITY |
| 5.2.4 Minimize the admission of containers wishing to share the host network namespace | CIS Red Hat OpenShift Container Platform v1.9.0 L1 | OpenShift | SYSTEM AND COMMUNICATIONS PROTECTION |
| 5.2.5 Minimize the admission of containers with allowPrivilegeEscalation | CIS Red Hat OpenShift Container Platform v1.9.0 L1 | OpenShift | ACCESS CONTROL, SYSTEM AND INFORMATION INTEGRITY |
| 5.2.7 Minimize the admission of containers with the NET_RAW capability | CIS Red Hat OpenShift Container Platform v1.9.0 L1 | OpenShift | CONFIGURATION MANAGEMENT |
| 5.3.1 Ensure that the CNI in use supports Network Policies | CIS Red Hat OpenShift Container Platform v1.9.0 L1 | OpenShift | SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION |
| 5.7.1 Create administrative boundaries between resources using namespaces | CIS Red Hat OpenShift Container Platform v1.9.0 L1 | OpenShift | SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION |