Item Search

NameAudit NamePluginCategory
1.1.1 Ensure that the API server pod specification file permissions are set to 600 or more restrictiveCIS Kubernetes v1.24 Benchmark v1.0.0 L1 MasterUnix

ACCESS CONTROL, MEDIA PROTECTION

1.1.9 Ensure that the --profiling argument is set to falseCIS Kubernetes 1.7.0 Benchmark v1.1.0 L1Unix

CONFIGURATION MANAGEMENT

1.1.19 Ensure that the --audit-log-maxsize argument is set to 100 or as appropriateCIS Kubernetes 1.7.0 Benchmark v1.1.0 L1Unix

AUDIT AND ACCOUNTABILITY

1.1.23 Ensure that the --service-account-lookup argument is set to trueCIS Kubernetes 1.13 Benchmark v1.4.1 L1Unix

IDENTIFICATION AND AUTHENTICATION

1.2.11 Ensure that the admission control plugin AlwaysPullImages is setCIS Kubernetes v1.20 Benchmark v1.0.1 L1 MasterUnix

ACCESS CONTROL, MEDIA PROTECTION

1.2.20 Ensure that the --audit-log-maxbackup argument is set to 10 or as appropriateCIS Kubernetes v1.23 Benchmark v1.0.1 L1 MasterUnix

AUDIT AND ACCOUNTABILITY

1.3.5 Ensure that the --root-ca-file argument is set as appropriateCIS Kubernetes 1.8 Benchmark v1.2.0 L1Unix

IDENTIFICATION AND AUTHENTICATION

1.3.5 Ensure that the --root-ca-file argument is set as appropriateCIS Kubernetes 1.11 Benchmark v1.3.0 L1Unix

IDENTIFICATION AND AUTHENTICATION

1.7.6 Do not admit root containersCIS Kubernetes 1.11 Benchmark v1.3.0 L2Unix

CONFIGURATION MANAGEMENT

2.4 Ensure that the --peer-cert-file and --peer-key-file arguments are set as appropriate - certCIS Kubernetes v1.23 Benchmark v1.0.1 L1 MasterUnix

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

2.4 Ensure that the --peer-cert-file and --peer-key-file arguments are set as appropriate - certCIS Kubernetes v1.24 Benchmark v1.0.0 L1 MasterUnix

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

3.1.18 Ensure that the --etcd-certfile and --etcd-keyfile arguments are set as appropriate - etcd-keyfileCIS Kubernetes 1.8 Benchmark v1.2.0 L1Unix

IDENTIFICATION AND AUTHENTICATION

3.1.19 Ensure that the --tls-cert-file and --tls-private-key-file arguments are set as appropriate - tls-cert-fileCIS Kubernetes 1.8 Benchmark v1.2.0 L1Unix

IDENTIFICATION AND AUTHENTICATION

4.1.6 Ensure that the --kubeconfig kubelet.conf file ownership is set to root:rootCIS Red Hat OpenShift Container Platform v1.9.0 L1OpenShift

ACCESS CONTROL

4.6.3 Apply Security Context to Pods and ContainersCIS Google Kubernetes Engine GKE Autopilot v1.3.0 L2GCP

CONFIGURATION MANAGEMENT

4.6.3 Apply Security Context to Pods and ContainersCIS Google Kubernetes Engine GKE v1.9.0 L2 GCPGCP

CONFIGURATION MANAGEMENT

5.5.1.2 Ensure minimum days between password changes is configured - /etc/login.defsCIS Red Hat Enterprise Linux 7 STIG v2.0.0 L1 ServerUnix

CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

5.5.1.2 Ensure minimum days between password changes is configured - /etc/shadowCIS Red Hat Enterprise Linux 7 STIG v2.0.0 L1 ServerUnix

CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

5.6.3 Apply Security Context to Your Pods and ContainersCIS Kubernetes v2.0.1 L2 Master NodeUnix

CONFIGURATION MANAGEMENT

5.6.3 Ensure Control Plane Authorized Networks is EnabledCIS Google Kubernetes Engine GKE v1.9.0 L2 GCPGCP

ACCESS CONTROL, MEDIA PROTECTION

GOOG-14-002800 - Google Android 14 must be configured to enable audit logging.AirWatch - DISA Google Android 14 COPE STIG v2r5MDM

AUDIT AND ACCOUNTABILITY

GOOG-14-006100 - Google Android 14 must be configured to not allow passwords that include more than four repeating or sequential characters - NumbersAirWatch - DISA Google Android 14 COPE STIG v2r5MDM

IDENTIFICATION AND AUTHENTICATION

GOOG-14-006500 - Google Android 14 must be configured to enforce an application installation policy by specifying one or more authorized application repositories, including [selection: DOD-approved commercial app repository, MDM server, mobile application store].AirWatch - DISA Google Android 14 COPE STIG v2r5MDM

CONFIGURATION MANAGEMENT

GOOG-14-006500 - Google Android 14 must be configured to enforce an application installation policy by specifying one or more authorized application repositories, including [selection: DOD-approved commercial app repository, MDM server, mobile application store].MobileIron - DISA Google Android 14 COPE STIG v2r5MDM

CONFIGURATION MANAGEMENT

GOOG-14-006600 - Google Android 14 must be configured to enforce an application installation policy by specifying an application allowlist that restricts applications by the following characteristics: [selection: list of digital signatures, cryptographic hash values, names, application version].MobileIron - DISA Google Android 14 COPE STIG v2r5MDM

CONFIGURATION MANAGEMENT

GOOG-14-007200 - Google Android 14 must be configured to disable trust agents - NOTE: This requirement is not applicable (NA) for specific biometric authentication factors included in the product's Common Criteria evaluation.MobileIron - DISA Google Android 14 COPE STIG v2r5MDM

IDENTIFICATION AND AUTHENTICATION

GOOG-14-007700 - Google Android 14 must be configured to display the DOD advisory warning message at startup or each time the user unlocks the device.MobileIron - DISA Google Android 14 COPE STIG v2r5MDM

ACCESS CONTROL

GOOG-14-007800 - Google Android 14 must be configured to generate audit records for the following auditable events: Detected integrity violations.AirWatch - DISA Google Android 14 COPE STIG v2r5MDM

AUDIT AND ACCOUNTABILITY

GOOG-14-008400 - Google Android 14 must be configured to disable USB mass storage mode.AirWatch - DISA Google Android 14 COPE STIG v2r5MDM

SYSTEM AND COMMUNICATIONS PROTECTION

GOOG-14-008500 - Google Android 14 must be configured to not allow backup of [all applications, configuration data] to locally connected systems.MobileIron - DISA Google Android 14 COPE STIG v2r5MDM

SYSTEM AND COMMUNICATIONS PROTECTION

GOOG-14-008600 - Google Android 14 must be configured to not allow backup of [all applications, configuration data] to remote systems.MobileIron - DISA Google Android 14 COPE STIG v2r5MDM

SYSTEM AND COMMUNICATIONS PROTECTION

GOOG-14-009000 - Google Android 14 must be configured to disable multiuser modes.MobileIron - DISA Google Android 14 COPE STIG v2r5MDM

ACCESS CONTROL, CONFIGURATION MANAGEMENT

GOOG-14-009400 - Google Android 14 must be configured to disable all Bluetooth profiles except for HSP (Headset Profile), HFP (Hands-Free Profile), SPP (Serial Port Profile), A2DP (Advanced Audio Distribution Profile), AVRCP (Audio/Video Remote Control Profile), and PBAP (Phone Book Access Profile) - SPP.MobileIron - DISA Google Android 14 COBO STIG v2r5MDM

CONFIGURATION MANAGEMENT

GOOG-14-009400 - Google Android 14 must be configured to disable all Bluetooth profiles except for HSP (Headset Profile), HFP (Hands-Free Profile), SPP (Serial Port Profile), A2DP (Advanced Audio Distribution Profile), AVRCP (Audio/Video Remote Control Profile), and PBAP (Phone Book Access Profile) - SPP.MobileIron - DISA Google Android 14 COPE STIG v2r5MDM

CONFIGURATION MANAGEMENT

GOOG-14-009500 - Google Android 14 must be configured to disable ad hoc wireless client-to-client connection capability.AirWatch - DISA Google Android 14 COPE STIG v2r5MDM

SYSTEM AND COMMUNICATIONS PROTECTION

GOOG-14-009900 - Google Android 14 must be configured to enforce that Wi-Fi Sharing is disabled.AirWatch - DISA Google Android 14 COPE STIG v2r5MDM

CONFIGURATION MANAGEMENT

GOOG-14-010200 - The Google Android 14 work profile must be configured to enforce the system application disable list.AirWatch - DISA Google Android 14 COPE STIG v2r5MDM

CONFIGURATION MANAGEMENT

GOOG-14-010200 - The Google Android 14 work profile must be configured to enforce the system application disable list.MobileIron - DISA Google Android 14 COPE STIG v2r5MDM

CONFIGURATION MANAGEMENT

GOOG-14-010500 - The Google Android 14 work profile must be configured to disable the autofill services.AirWatch - DISA Google Android 14 COPE STIG v2r5MDM

CONFIGURATION MANAGEMENT

GOOG-14-010800 - Android 14 devices must have the latest available Google Android 14 operating system installed.MobileIron - DISA Google Android 14 COBO STIG v2r5MDM

CONFIGURATION MANAGEMENT

GOOG-14-012200 - Google Android 14 must be configured to disable all data signaling over [assignment: list of externally accessible hardware ports (for example, USB)] - for example, USB].MobileIron - DISA Google Android 14 COBO STIG v2r5MDM

ACCESS CONTROL

GOOG-14-012400 - Google Android 14 must allow only the administrator (MDM) to perform the following management function: Disable Phone Hub - MDM to perform the following management function: Disable Phone Hub.AirWatch - DISA Google Android 14 COPE STIG v2r5MDM

SYSTEM AND COMMUNICATIONS PROTECTION

GOOG-14-012400 - Google Android 14 must allow only the administrator (MDM) to perform the following management function: Disable Phone Hub - MDM to perform the following management function: Disable Phone Hub.MobileIron - DISA Google Android 14 COPE STIG v2r5MDM

SYSTEM AND COMMUNICATIONS PROTECTION

GOOG-14-013000 - Google Android 14 must disable the user's ability to wipe the device.MobileIron - DISA Google Android 14 COPE STIG v2r5MDM

CONFIGURATION MANAGEMENT

GOOG-14-013200 - Google Android 14 must disable wireless printing.MobileIron - DISA Google Android 14 COBO STIG v2r5MDM

CONFIGURATION MANAGEMENT

GOOG-14-013500 - Google Android 14 must implement the management setting: disable Camera.AirWatch - DISA Google Android 14 COPE STIG v2r5MDM

CONFIGURATION MANAGEMENT

GOOG-14-013500 - Google Android 14 must implement the management setting: disable Camera.MobileIron - DISA Google Android 14 COPE STIG v2r5MDM

CONFIGURATION MANAGEMENT

GOOG-14-013600 - The Google Android device must be configured to disable Wi-Fi Aware for Work Profile apps.MobileIron - DISA Google Android 14 COBO STIG v2r5MDM

CONFIGURATION MANAGEMENT

GOOG-14-013600 - The Google Android device must be configured to disable Wi-Fi Aware for Work Profile apps.MobileIron - DISA Google Android 14 COPE STIG v2r5MDM

CONFIGURATION MANAGEMENT

SHPT-00-000760 - SharePoint must implement security functions as largely independent modules to avoid unnecessary interactions between modules - Internet & Extranet assigned to diff App PoolsDISA STIG SharePoint 2010 v1r9Windows

SYSTEM AND COMMUNICATIONS PROTECTION