| 1.1 Ensure packages are obtained from authorized repositories | CIS PostgreSQL 11 OS v1.0.0 | Unix | CONFIGURATION MANAGEMENT |
| 1.2.1 Ensure the container host has been Hardened | CIS Docker v1.8.0 L1 OS Linux | Unix | CONFIGURATION MANAGEMENT |
| 1.2.2 Use https for kubelet connections | CIS Red Hat OpenShift Container Platform v1.9.0 L1 | OpenShift | ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION |
| 1.2.13 Ensure that the admission control plugin NodeRestriction is set | CIS Red Hat OpenShift Container Platform v1.9.0 L1 | OpenShift | SYSTEM AND SERVICES ACQUISITION |
| 1.2.14 Ensure that the --insecure-bind-address argument is not set | CIS Red Hat OpenShift Container Platform v1.9.0 L1 | OpenShift | SYSTEM AND SERVICES ACQUISITION |
| 1.2.22 Ensure that the --request-timeout argument is set | CIS Red Hat OpenShift Container Platform v1.9.0 L1 | OpenShift | CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION |
| 1.2.24 Ensure that the --service-account-key-file argument is set as appropriate | CIS Red Hat OpenShift Container Platform v1.9.0 L1 | OpenShift | IDENTIFICATION AND AUTHENTICATION |
| 1.2.28 Ensure that the --etcd-cafile argument is set as appropriate | CIS Red Hat OpenShift Container Platform v1.9.0 L1 | OpenShift | ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION |
| 1.3.4 Ensure that the --root-ca-file argument is set as appropriate | CIS Red Hat OpenShift Container Platform v1.9.0 L1 | OpenShift | SYSTEM AND COMMUNICATIONS PROTECTION |
| 1.5.1.1 Ensure message of the day is configured properly | CIS Google Container-Optimized OS v1.2.0 L2 Server | Unix | CONFIGURATION MANAGEMENT |
| 2.5 Ensure that the --peer-client-cert-auth argument is set to true | CIS Red Hat OpenShift Container Platform v1.9.0 L1 | OpenShift | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY |
| 2.30 (L1) Ensure 'Enable Renderer App Container' Is Enabled | CIS Google Chrome L1 v3.0.0 | Windows | SYSTEM AND INFORMATION INTEGRITY |
| 2.70 (L1) Ensure 'Enable Renderer App Container' Is Enabled | CIS Google Chrome Group Policy v1.1.0 L1 | Windows | SYSTEM AND INFORMATION INTEGRITY |
| 4.1 Create CIS Audit Class | CIS Solaris 11.2 L1 v1.1.0 | Unix | ACCESS CONTROL |
| 4.1.3 If proxy kube proxy configuration file exists ensure permissions are set to 644 or more restrictive | CIS Red Hat OpenShift Container Platform v1.9.0 L1 | OpenShift | ACCESS CONTROL, MEDIA PROTECTION |
| 4.1.4 If proxy kubeconfig file exists ensure ownership is set to root:root | CIS Red Hat OpenShift Container Platform v1.9.0 L1 | OpenShift | ACCESS CONTROL |
| 4.1.10 Ensure that the kubelet configuration file ownership is set to root:root | CIS Red Hat OpenShift Container Platform v1.9.0 L1 | OpenShift | ACCESS CONTROL |
| 4.2.5 Verify that the read only port is not used or is set to 0 | CIS Red Hat OpenShift Container Platform v1.9.0 L1 | OpenShift | CONFIGURATION MANAGEMENT |
| 4.2.6 Ensure that the --streaming-connection-idle-timeout argument is not set to 0 | CIS Red Hat OpenShift Container Platform v1.9.0 L1 | OpenShift | CONFIGURATION MANAGEMENT |
| 4.3 Do not install unnecessary packages in the container | CIS Docker 1.6 v1.0.0 L1 Docker | Unix | CONFIGURATION MANAGEMENT |
| 4.3 Do not install unnecessary packages in the container | CIS Docker 1.12.0 v1.0.0 L1 Docker | Unix | CONFIGURATION MANAGEMENT |
| 4.3 Do not install unnecessary packages in the container | CIS Docker 1.13.0 v1.0.0 L1 Docker | Unix | CONFIGURATION MANAGEMENT |
| 4.3 Do not install unnecessary packages in the container | CIS Docker 1.11.0 v1.0.0 L1 Docker | Unix | CONFIGURATION MANAGEMENT |
| 4.3 Ensure unnecessary packages are not installed in the container | CIS Docker Community Edition v1.1.0 L1 Docker | Unix | CONFIGURATION MANAGEMENT |
| 5.1.1 Enable Artifact Analysis scanning for Artifact Registry container images | CIS Google Kubernetes Engine GKE Autopilot v2.0.0 L2 | GCP | RISK ASSESSMENT |
| 5.1.1 Enable Artifact Analysis scanning for Artifact Registry container images | CIS Google Kubernetes Engine GKE v2.0.0 L2 | GCP | RISK ASSESSMENT |
| 5.2.3 Minimize the admission of containers wishing to share the host IPC namespace | CIS Red Hat OpenShift Container Platform v1.9.0 L1 | OpenShift | SYSTEM AND COMMUNICATIONS PROTECTION |
| 5.2.8 Minimize the admission of containers with added capabilities | CIS Red Hat OpenShift Container Platform v1.9.0 L1 | OpenShift | CONFIGURATION MANAGEMENT |
| 6.4 Backup container data | CIS Docker 1.6 v1.0.0 L1 Docker | Unix | |
| 6.5 Avoid container sprawl | CIS Docker 1.13.0 v1.0.0 L1 Linux | Unix | SYSTEM AND INFORMATION INTEGRITY |
| CIS_Google_Container-Optimized_OS_v1.2.0_L1_Server.audit from CIS Google Container-Optimized OS Benchmark v1.2.0 | CIS Google Container-Optimized OS v1.2.0 L1 Server | Unix | |
| CIS_Google_Container-Optimized_OS_v1.2.0_L2_Server.audit from CIS Google Container-Optimized OS Benchmark v1.2.0 | CIS Google Container-Optimized OS v1.2.0 L2 Server | Unix | |
| CIS_Microsoft_SQL_Server_2019_v1.6.0_L1_AWS_RDS_Windows.audit from CIS Microsoft SQL Server 2019 v1.6.0 | CIS Microsoft SQL Server 2019 v1.6.0 L1 AWS RDS Windows | Windows | |
| CIS_Microsoft_SQL_Server_2019_v1.6.0_L1_Database_Engine_Windows.audit from CIS Microsoft SQL Server 2019 v1.6.0 | CIS Microsoft SQL Server 2019 v1.6.0 L1 Database Engine Windows | Windows | |
| CIS_Ubuntu_18.04_LXD_Container_v1.0.0_L1.audit from CIS Ubuntu Linux 18.04 LXD Container Benchmark | CIS Ubuntu Linux 18.04 LXD Container L1 v1.0.0 | Unix | |
| CIS_Ubuntu_18.04_LXD_Container_v1.0.0_L2.audit from CIS Ubuntu Linux 18.04 LXD Container Benchmark | CIS Ubuntu Linux 18.04 LXD Container L2 v1.0.0 | Unix | |
| CNTR-K8-000160 - The Kubernetes Scheduler must use TLS 1.2, at a minimum, to protect the confidentiality of sensitive data during electronic dissemination. | DISA Kubernetes STIG v2r6 | Unix | ACCESS CONTROL |
| CNTR-K8-000180 - The Kubernetes etcd must use TLS to protect the confidentiality of sensitive data during electronic dissemination. | DISA Kubernetes STIG v2r6 | Unix | ACCESS CONTROL |
| CNTR-K8-000190 - The Kubernetes etcd must use TLS to protect the confidentiality of sensitive data during electronic dissemination. | DISA Kubernetes STIG v2r6 | Unix | ACCESS CONTROL |
| CNTR-K8-002720 - Kubernetes must contain the latest updates as authorized by IAVMs, CTOs, DTMs, and STIGs. | DISA Kubernetes STIG v2r6 | Unix | SYSTEM AND INFORMATION INTEGRITY |
| DKER-EE-001800 - The insecure registry capability in the Docker Engine - Enterprise component of Docker Enterprise must be disabled. | DISA STIG Docker Enterprise 2.x Linux/Unix v2r2 | Unix | CONFIGURATION MANAGEMENT |
| DKER-EE-001810 - On Linux, a non-AUFS storage driver in the Docker Engine - Enterprise component of Docker Enterprise must be used. | DISA STIG Docker Enterprise 2.x Linux/Unix v2r2 | Unix | CONFIGURATION MANAGEMENT |
| DKER-EE-001830 - The userland proxy capability in the Docker Engine - Enterprise component of Docker Enterprise must be disabled. | DISA STIG Docker Enterprise 2.x Linux/Unix v2r2 | Unix | CONFIGURATION MANAGEMENT |
| DKER-EE-001840 - Experimental features in the Docker Engine - Enterprise component of Docker Enterprise must be disabled. | DISA STIG Docker Enterprise 2.x Linux/Unix v2r2 | Unix | CONFIGURATION MANAGEMENT |
| DKER-EE-001870 - The Docker Enterprise self-signed certificates in Universal Control Plane (UCP) must be replaced with DoD trusted, signed certificates. | DISA STIG Docker Enterprise 2.x Linux/Unix UCP v2r2 | Unix | CONFIGURATION MANAGEMENT |
| DKER-EE-001880 - The Docker Enterprise self-signed certificates in Docker Trusted Registry (DTR) must be replaced with DoD trusted, signed certificates. | DISA STIG Docker Enterprise 2.x Linux/Unix DTR v2r2 | Unix | CONFIGURATION MANAGEMENT |
| DKER-EE-001890 - The option in Universal Control Plane (UCP) allowing users and administrators to schedule containers on all nodes, including UCP managers and Docker Trusted Registry (DTR) nodes must be disabled in Docker Enterprise. | DISA STIG Docker Enterprise 2.x Linux/Unix UCP v2r2 | Unix | CONFIGURATION MANAGEMENT |
| DKER-EE-001900 - The Create repository on push option in Docker Trusted Registry (DTR) must be disabled in Docker Enterprise. | DISA STIG Docker Enterprise 2.x Linux/Unix DTR v2r2 | Unix | CONFIGURATION MANAGEMENT |
| DKER-EE-001910 - Periodic data usage and analytics reporting in Universal Control Plane (UCP) must be disabled in Docker Enterprise. | DISA STIG Docker Enterprise 2.x Linux/Unix UCP v2r2 | Unix | CONFIGURATION MANAGEMENT |
| DKER-EE-001920 - Periodic data usage and analytics reporting in Docker Trusted Registry (DTR) must be disabled in Docker Enterprise. | DISA STIG Docker Enterprise 2.x Linux/Unix DTR v2r2 | Unix | CONFIGURATION MANAGEMENT |