Item Search

NameAudit NamePluginCategory
1.1 Ensure packages are obtained from authorized repositoriesCIS PostgreSQL 11 OS v1.0.0Unix

CONFIGURATION MANAGEMENT

1.2.1 Ensure the container host has been HardenedCIS Docker v1.8.0 L1 OS LinuxUnix

CONFIGURATION MANAGEMENT

1.2.2 Use https for kubelet connectionsCIS Red Hat OpenShift Container Platform v1.9.0 L1OpenShift

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

1.2.13 Ensure that the admission control plugin NodeRestriction is setCIS Red Hat OpenShift Container Platform v1.9.0 L1OpenShift

SYSTEM AND SERVICES ACQUISITION

1.2.14 Ensure that the --insecure-bind-address argument is not setCIS Red Hat OpenShift Container Platform v1.9.0 L1OpenShift

SYSTEM AND SERVICES ACQUISITION

1.2.22 Ensure that the --request-timeout argument is setCIS Red Hat OpenShift Container Platform v1.9.0 L1OpenShift

CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

1.2.24 Ensure that the --service-account-key-file argument is set as appropriateCIS Red Hat OpenShift Container Platform v1.9.0 L1OpenShift

IDENTIFICATION AND AUTHENTICATION

1.2.28 Ensure that the --etcd-cafile argument is set as appropriateCIS Red Hat OpenShift Container Platform v1.9.0 L1OpenShift

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

1.3.4 Ensure that the --root-ca-file argument is set as appropriateCIS Red Hat OpenShift Container Platform v1.9.0 L1OpenShift

SYSTEM AND COMMUNICATIONS PROTECTION

1.5.1.1 Ensure message of the day is configured properlyCIS Google Container-Optimized OS v1.2.0 L2 ServerUnix

CONFIGURATION MANAGEMENT

2.5 Ensure that the --peer-client-cert-auth argument is set to trueCIS Red Hat OpenShift Container Platform v1.9.0 L1OpenShift

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

2.30 (L1) Ensure 'Enable Renderer App Container' Is EnabledCIS Google Chrome L1 v3.0.0Windows

SYSTEM AND INFORMATION INTEGRITY

2.70 (L1) Ensure 'Enable Renderer App Container' Is EnabledCIS Google Chrome Group Policy v1.1.0 L1Windows

SYSTEM AND INFORMATION INTEGRITY

4.1 Create CIS Audit ClassCIS Solaris 11.2 L1 v1.1.0Unix

ACCESS CONTROL

4.1.3 If proxy kube proxy configuration file exists ensure permissions are set to 644 or more restrictiveCIS Red Hat OpenShift Container Platform v1.9.0 L1OpenShift

ACCESS CONTROL, MEDIA PROTECTION

4.1.4 If proxy kubeconfig file exists ensure ownership is set to root:rootCIS Red Hat OpenShift Container Platform v1.9.0 L1OpenShift

ACCESS CONTROL

4.1.10 Ensure that the kubelet configuration file ownership is set to root:rootCIS Red Hat OpenShift Container Platform v1.9.0 L1OpenShift

ACCESS CONTROL

4.2.5 Verify that the read only port is not used or is set to 0CIS Red Hat OpenShift Container Platform v1.9.0 L1OpenShift

CONFIGURATION MANAGEMENT

4.2.6 Ensure that the --streaming-connection-idle-timeout argument is not set to 0CIS Red Hat OpenShift Container Platform v1.9.0 L1OpenShift

CONFIGURATION MANAGEMENT

4.3 Do not install unnecessary packages in the containerCIS Docker 1.6 v1.0.0 L1 DockerUnix

CONFIGURATION MANAGEMENT

4.3 Do not install unnecessary packages in the containerCIS Docker 1.12.0 v1.0.0 L1 DockerUnix

CONFIGURATION MANAGEMENT

4.3 Do not install unnecessary packages in the containerCIS Docker 1.13.0 v1.0.0 L1 DockerUnix

CONFIGURATION MANAGEMENT

4.3 Do not install unnecessary packages in the containerCIS Docker 1.11.0 v1.0.0 L1 DockerUnix

CONFIGURATION MANAGEMENT

4.3 Ensure unnecessary packages are not installed in the containerCIS Docker Community Edition v1.1.0 L1 DockerUnix

CONFIGURATION MANAGEMENT

5.1.1 Enable Artifact Analysis scanning for Artifact Registry container imagesCIS Google Kubernetes Engine GKE Autopilot v2.0.0 L2GCP

RISK ASSESSMENT

5.1.1 Enable Artifact Analysis scanning for Artifact Registry container imagesCIS Google Kubernetes Engine GKE v2.0.0 L2GCP

RISK ASSESSMENT

5.2.3 Minimize the admission of containers wishing to share the host IPC namespaceCIS Red Hat OpenShift Container Platform v1.9.0 L1OpenShift

SYSTEM AND COMMUNICATIONS PROTECTION

5.2.8 Minimize the admission of containers with added capabilitiesCIS Red Hat OpenShift Container Platform v1.9.0 L1OpenShift

CONFIGURATION MANAGEMENT

6.4 Backup container dataCIS Docker 1.6 v1.0.0 L1 DockerUnix
6.5 Avoid container sprawlCIS Docker 1.13.0 v1.0.0 L1 LinuxUnix

SYSTEM AND INFORMATION INTEGRITY

CIS_Google_Container-Optimized_OS_v1.2.0_L1_Server.audit from CIS Google Container-Optimized OS Benchmark v1.2.0CIS Google Container-Optimized OS v1.2.0 L1 ServerUnix
CIS_Google_Container-Optimized_OS_v1.2.0_L2_Server.audit from CIS Google Container-Optimized OS Benchmark v1.2.0CIS Google Container-Optimized OS v1.2.0 L2 ServerUnix
CIS_Microsoft_SQL_Server_2019_v1.6.0_L1_AWS_RDS_Windows.audit from CIS Microsoft SQL Server 2019 v1.6.0CIS Microsoft SQL Server 2019 v1.6.0 L1 AWS RDS WindowsWindows
CIS_Microsoft_SQL_Server_2019_v1.6.0_L1_Database_Engine_Windows.audit from CIS Microsoft SQL Server 2019 v1.6.0CIS Microsoft SQL Server 2019 v1.6.0 L1 Database Engine WindowsWindows
CIS_Ubuntu_18.04_LXD_Container_v1.0.0_L1.audit from CIS Ubuntu Linux 18.04 LXD Container BenchmarkCIS Ubuntu Linux 18.04 LXD Container L1 v1.0.0Unix
CIS_Ubuntu_18.04_LXD_Container_v1.0.0_L2.audit from CIS Ubuntu Linux 18.04 LXD Container BenchmarkCIS Ubuntu Linux 18.04 LXD Container L2 v1.0.0Unix
CNTR-K8-000160 - The Kubernetes Scheduler must use TLS 1.2, at a minimum, to protect the confidentiality of sensitive data during electronic dissemination.DISA Kubernetes STIG v2r6Unix

ACCESS CONTROL

CNTR-K8-000180 - The Kubernetes etcd must use TLS to protect the confidentiality of sensitive data during electronic dissemination.DISA Kubernetes STIG v2r6Unix

ACCESS CONTROL

CNTR-K8-000190 - The Kubernetes etcd must use TLS to protect the confidentiality of sensitive data during electronic dissemination.DISA Kubernetes STIG v2r6Unix

ACCESS CONTROL

CNTR-K8-002720 - Kubernetes must contain the latest updates as authorized by IAVMs, CTOs, DTMs, and STIGs.DISA Kubernetes STIG v2r6Unix

SYSTEM AND INFORMATION INTEGRITY

DKER-EE-001800 - The insecure registry capability in the Docker Engine - Enterprise component of Docker Enterprise must be disabled.DISA STIG Docker Enterprise 2.x Linux/Unix v2r2Unix

CONFIGURATION MANAGEMENT

DKER-EE-001810 - On Linux, a non-AUFS storage driver in the Docker Engine - Enterprise component of Docker Enterprise must be used.DISA STIG Docker Enterprise 2.x Linux/Unix v2r2Unix

CONFIGURATION MANAGEMENT

DKER-EE-001830 - The userland proxy capability in the Docker Engine - Enterprise component of Docker Enterprise must be disabled.DISA STIG Docker Enterprise 2.x Linux/Unix v2r2Unix

CONFIGURATION MANAGEMENT

DKER-EE-001840 - Experimental features in the Docker Engine - Enterprise component of Docker Enterprise must be disabled.DISA STIG Docker Enterprise 2.x Linux/Unix v2r2Unix

CONFIGURATION MANAGEMENT

DKER-EE-001870 - The Docker Enterprise self-signed certificates in Universal Control Plane (UCP) must be replaced with DoD trusted, signed certificates.DISA STIG Docker Enterprise 2.x Linux/Unix UCP v2r2Unix

CONFIGURATION MANAGEMENT

DKER-EE-001880 - The Docker Enterprise self-signed certificates in Docker Trusted Registry (DTR) must be replaced with DoD trusted, signed certificates.DISA STIG Docker Enterprise 2.x Linux/Unix DTR v2r2Unix

CONFIGURATION MANAGEMENT

DKER-EE-001890 - The option in Universal Control Plane (UCP) allowing users and administrators to schedule containers on all nodes, including UCP managers and Docker Trusted Registry (DTR) nodes must be disabled in Docker Enterprise.DISA STIG Docker Enterprise 2.x Linux/Unix UCP v2r2Unix

CONFIGURATION MANAGEMENT

DKER-EE-001900 - The Create repository on push option in Docker Trusted Registry (DTR) must be disabled in Docker Enterprise.DISA STIG Docker Enterprise 2.x Linux/Unix DTR v2r2Unix

CONFIGURATION MANAGEMENT

DKER-EE-001910 - Periodic data usage and analytics reporting in Universal Control Plane (UCP) must be disabled in Docker Enterprise.DISA STIG Docker Enterprise 2.x Linux/Unix UCP v2r2Unix

CONFIGURATION MANAGEMENT

DKER-EE-001920 - Periodic data usage and analytics reporting in Docker Trusted Registry (DTR) must be disabled in Docker Enterprise.DISA STIG Docker Enterprise 2.x Linux/Unix DTR v2r2Unix

CONFIGURATION MANAGEMENT