Item Search

NameAudit NamePluginCategory
1.1.2 Ensure that the API server pod specification file ownership is set to root:rootCIS Red Hat OpenShift Container Platform v1.9.0 L1OpenShift

ACCESS CONTROL

1.1.4 Ensure that the controller manager pod specification file ownership is set to root:rootCIS Red Hat OpenShift Container Platform v1.9.0 L1OpenShift

ACCESS CONTROL

1.1.5 Ensure that the scheduler pod specification file permissions are set to 600 or more restrictiveCIS Red Hat OpenShift Container Platform v1.9.0 L1OpenShift

ACCESS CONTROL, MEDIA PROTECTION

1.1.6 Ensure that the scheduler pod specification file ownership is set to root:rootCIS Red Hat OpenShift Container Platform v1.9.0 L1OpenShift

ACCESS CONTROL

1.1.9 Ensure that the Container Network Interface file permissions are set to 600 or more restrictiveCIS Red Hat OpenShift Container Platform v1.9.0 L1OpenShift

ACCESS CONTROL, MEDIA PROTECTION

1.1.10 Ensure that the Container Network Interface file ownership is set to root:rootCIS Red Hat OpenShift Container Platform v1.9.0 L1OpenShift

ACCESS CONTROL

1.1.14 Ensure that the kubeconfig file ownership is set to root:rootCIS Red Hat OpenShift Container Platform v1.9.0 L1OpenShift

ACCESS CONTROL

1.1.15 Ensure that the Scheduler kubeconfig file permissions are set to 600 or more restrictiveCIS Red Hat OpenShift Container Platform v1.9.0 L1OpenShift

ACCESS CONTROL, MEDIA PROTECTION

1.1.16 Ensure that the Scheduler kubeconfig file ownership is set to root:rootCIS Red Hat OpenShift Container Platform v1.9.0 L1OpenShift

ACCESS CONTROL

1.1.17 Ensure that the Controller Manager kubeconfig file permissions are set to 600 or more restrictiveCIS Red Hat OpenShift Container Platform v1.9.0 L1OpenShift

ACCESS CONTROL, MEDIA PROTECTION

1.1.18 Ensure that the Controller Manager kubeconfig file ownership is set to root:rootCIS Red Hat OpenShift Container Platform v1.9.0 L1OpenShift

ACCESS CONTROL

1.1.19 Ensure that the OpenShift PKI directory and file ownership is set to root:rootCIS Red Hat OpenShift Container Platform v1.9.0 L1OpenShift

ACCESS CONTROL

1.1.20 Ensure that the OpenShift PKI certificate file permissions are set to 600 or more restrictiveCIS Red Hat OpenShift Container Platform v1.9.0 L1OpenShift

ACCESS CONTROL, MEDIA PROTECTION

1.2.3 Ensure that the kubelet uses certificates to authenticateCIS Red Hat OpenShift Container Platform v1.9.0 L1OpenShift

SYSTEM AND SERVICES ACQUISITION

1.2.5 Ensure that the --authorization-mode argument is not set to AlwaysAllowCIS Red Hat OpenShift Container Platform v1.9.0 L1OpenShift

ACCESS CONTROL, MEDIA PROTECTION

1.2.11 Ensure that the admission control plugin NamespaceLifecycle is setCIS Red Hat OpenShift Container Platform v1.9.0 L1OpenShift

CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

1.2.16 Ensure that the --secure-port argument is not set to 0CIS Red Hat OpenShift Container Platform v1.9.0 L1OpenShift

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

1.2.17 Ensure that the healthz endpoint is protected by RBACCIS Red Hat OpenShift Container Platform v1.9.0 L1OpenShift

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

1.2.18 Ensure that the --audit-log-path argument is setCIS Red Hat OpenShift Container Platform v1.9.0 L1OpenShift

AUDIT AND ACCOUNTABILITY

1.2.19 Ensure that the audit logs are forwarded off the cluster for retentionCIS Red Hat OpenShift Container Platform v1.9.0 L1OpenShift

AUDIT AND ACCOUNTABILITY

1.2.23 Ensure that the --service-account-lookup argument is set to trueCIS Red Hat OpenShift Container Platform v1.9.0 L1OpenShift

ACCESS CONTROL, MEDIA PROTECTION

1.2.30 Ensure that the API Server only makes use of Strong Cryptographic CiphersCIS Red Hat OpenShift Container Platform v1.9.0 L1OpenShift

CONFIGURATION MANAGEMENT

1.2.31 Ensure unsupported configuration overrides are not usedCIS Red Hat OpenShift Container Platform v1.9.0 L1OpenShift

SYSTEM AND SERVICES ACQUISITION

1.3.1 Ensure that controller manager healthz endpoints are protected by RBACCIS Red Hat OpenShift Container Platform v1.9.0 L1OpenShift

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

1.3.2 Ensure that the --use-service-account-credentials argument is set to trueCIS Red Hat OpenShift Container Platform v1.9.0 L1OpenShift

IDENTIFICATION AND AUTHENTICATION

1.4.2 Verify that the scheduler API service is protected by RBACCIS Red Hat OpenShift Container Platform v1.9.0 L1OpenShift

SYSTEM AND COMMUNICATIONS PROTECTION

2.2 Ensure that the --client-cert-auth argument is set to trueCIS Red Hat OpenShift Container Platform v1.9.0 L1OpenShift

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

2.3 Ensure that the --auto-tls argument is not set to trueCIS Red Hat OpenShift Container Platform v1.9.0 L1OpenShift

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

2.4 Ensure that the --peer-cert-file and --peer-key-file arguments are set as appropriateCIS Red Hat OpenShift Container Platform v1.9.0 L1OpenShift

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

2.6 Ensure that the --peer-auto-tls argument is not set to trueCIS Red Hat OpenShift Container Platform v1.9.0 L1OpenShift

IDENTIFICATION AND AUTHENTICATION

3.2.1 Ensure that a minimal audit policy is createdCIS Red Hat OpenShift Container Platform v1.9.0 L1OpenShift

AUDIT AND ACCOUNTABILITY

4.1.1 Ensure that the kubelet service file permissions are set to 644 or more restrictiveCIS Red Hat OpenShift Container Platform v1.9.0 L1OpenShift

ACCESS CONTROL, MEDIA PROTECTION

4.1.8 Ensure that the client certificate authorities file ownership is set to root:rootCIS Red Hat OpenShift Container Platform v1.9.0 L1OpenShift

ACCESS CONTROL

4.1.9 Ensure that the kubelet --config configuration file has permissions set to 600 or more restrictiveCIS Red Hat OpenShift Container Platform v1.9.0 L1OpenShift

ACCESS CONTROL

4.2.2 Ensure that the --anonymous-auth argument is set to falseCIS Red Hat OpenShift Container Platform v1.9.0 L1OpenShift

ACCESS CONTROL, MEDIA PROTECTION

4.2.3 Ensure that the --authorization-mode argument is not set to AlwaysAllowCIS Red Hat OpenShift Container Platform v1.9.0 L1OpenShift

ACCESS CONTROL, MEDIA PROTECTION

4.2.4 Ensure that the --client-ca-file argument is set as appropriateCIS Red Hat OpenShift Container Platform v1.9.0 L1OpenShift

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

4.2.7 Ensure that the --make-iptables-util-chains argument is set to trueCIS Red Hat OpenShift Container Platform v1.9.0 L1OpenShift

SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

4.2.9 Ensure that the --tls-cert-file and --tls-private-key-file arguments are set as appropriateCIS Red Hat OpenShift Container Platform v1.9.0 L1OpenShift

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

5.1.1 Ensure that the cluster-admin role is only used where requiredCIS Red Hat OpenShift Container Platform v1.9.0 L1OpenShift

ACCESS CONTROL

5.1.2 Minimize access to secretsCIS Red Hat OpenShift Container Platform v1.9.0 L1OpenShift

SYSTEM AND COMMUNICATIONS PROTECTION

5.1.3 Minimize wildcard use in Roles and ClusterRolesCIS Red Hat OpenShift Container Platform v1.9.0 L1OpenShift

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

5.1.4 Minimize access to create podsCIS Red Hat OpenShift Container Platform v1.9.0 L1OpenShift

CONFIGURATION MANAGEMENT, SYSTEM AND INFORMATION INTEGRITY

5.1.5 Ensure that default service accounts are not actively used.CIS Red Hat OpenShift Container Platform v1.9.0 L1OpenShift

ACCESS CONTROL

5.2.1 Minimize the admission of privileged containersCIS Red Hat OpenShift Container Platform v1.9.0 L1OpenShift

ACCESS CONTROL, SYSTEM AND INFORMATION INTEGRITY

5.2.4 Minimize the admission of containers wishing to share the host network namespaceCIS Red Hat OpenShift Container Platform v1.9.0 L1OpenShift

SYSTEM AND COMMUNICATIONS PROTECTION

5.2.5 Minimize the admission of containers with allowPrivilegeEscalationCIS Red Hat OpenShift Container Platform v1.9.0 L1OpenShift

ACCESS CONTROL, SYSTEM AND INFORMATION INTEGRITY

5.2.7 Minimize the admission of containers with the NET_RAW capabilityCIS Red Hat OpenShift Container Platform v1.9.0 L1OpenShift

CONFIGURATION MANAGEMENT

5.3.1 Ensure that the CNI in use supports Network PoliciesCIS Red Hat OpenShift Container Platform v1.9.0 L1OpenShift

SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

5.7.1 Create administrative boundaries between resources using namespacesCIS Red Hat OpenShift Container Platform v1.9.0 L1OpenShift

SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION