Item Search

NameAudit NamePluginCategory
1.1.3 Ensure that the controller manager pod specification file permissions are set to 600 or more restrictiveCIS Kubernetes v1.20 Benchmark v1.0.1 L1 MasterUnix

ACCESS CONTROL, MEDIA PROTECTION

1.1.14 Ensure that the admission control policy is set to SecurityContextDenyCIS Kubernetes 1.7.0 Benchmark v1.1.0 L1Unix

ACCESS CONTROL

1.1.17 Ensure that the --audit-log-maxage argument is set to 30 or as appropriateCIS Kubernetes 1.7.0 Benchmark v1.1.0 L1Unix

AUDIT AND ACCOUNTABILITY

1.1.18 Ensure that the --audit-log-maxsize argument is set to 100 or as appropriateCIS Kubernetes 1.11 Benchmark v1.3.0 L1Unix

AUDIT AND ACCOUNTABILITY

1.1.18 Ensure that the --authorization-mode argument is not set to AlwaysAllowCIS Kubernetes 1.8 Benchmark v1.2.0 L1Unix

ACCESS CONTROL

1.2.1 Ensure that the --profiling argument is set to falseCIS Kubernetes 1.7.0 Benchmark v1.1.0 L1Unix

CONFIGURATION MANAGEMENT

1.2.6 Ensure that the --authorization-mode argument is not set to AlwaysAllowCIS Kubernetes v2.0.1 L1 Master NodeUnix

ACCESS CONTROL, MEDIA PROTECTION

1.2.6 Ensure that the --authorization-mode argument is not set to AlwaysAllowCIS Kubernetes v1.20 Benchmark v1.0.1 L1 MasterUnix

ACCESS CONTROL, MEDIA PROTECTION

1.2.7 Ensure that the --authorization-mode argument includes NodeCIS Kubernetes v1.24 Benchmark v1.0.0 L1 MasterUnix

ACCESS CONTROL, MEDIA PROTECTION

1.2.8 Ensure that the --authorization-mode argument includes RBACCIS Kubernetes v1.20 Benchmark v1.0.1 L1 MasterUnix

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

1.2.8 Ensure that the --authorization-mode argument includes RBACCIS Kubernetes v1.23 Benchmark v1.0.1 L1 MasterUnix

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

1.2.19 Ensure that the --audit-log-maxage argument is set to 30 or as appropriateCIS Kubernetes v1.24 Benchmark v1.0.0 L1 MasterUnix

AUDIT AND ACCOUNTABILITY

1.2.19 Ensure that the --audit-log-maxsize argument is set to 100 or as appropriateCIS Kubernetes v2.0.1 L1 Master NodeUnix

AUDIT AND ACCOUNTABILITY

1.2.20 Ensure that the --audit-log-maxbackup argument is set to 10 or as appropriateCIS Kubernetes v1.24 Benchmark v1.0.0 L1 MasterUnix

AUDIT AND ACCOUNTABILITY

1.2.23 Ensure that the --audit-log-maxbackup argument is set to 10 or as appropriateCIS Kubernetes v1.20 Benchmark v1.0.1 L1 MasterUnix

AUDIT AND ACCOUNTABILITY

1.3.3 Ensure that the --use-service-account-credentials argument is set to trueCIS Kubernetes v1.20 Benchmark v1.0.1 L1 MasterUnix

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, IDENTIFICATION AND AUTHENTICATION

1.3.6 Apply Security Context to Your Pods and ContainersCIS Kubernetes 1.7.0 Benchmark v1.1.0 L2Unix
1.3.6 Apply Security Context to Your Pods and ContainersCIS Kubernetes 1.8 Benchmark v1.2.0 L2Unix
1.3.7 Ensure that the --bind-address argument is set to 127.0.0.1CIS Kubernetes v1.20 Benchmark v1.0.1 L1 MasterUnix

ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION

1.4.8 Ensure that the etcd.conf file ownership is set to root:rootCIS Kubernetes 1.7.0 Benchmark v1.1.0 L1Unix

CONFIGURATION MANAGEMENT

1.6.6 Apply Security Context to Your Pods and ContainersCIS Kubernetes 1.7.0 Benchmark v1.1.0 L2Unix
2.1.6 Ensure that the --streaming-connection-idle-timeout argument is not set to 0CIS Kubernetes 1.7.0 Benchmark v1.1.0 L1Unix

SYSTEM AND COMMUNICATIONS PROTECTION

2.1.14 Ensure that the RotateKubeletClientCertificate argument is set to trueCIS Kubernetes 1.7.0 Benchmark v1.1.0 L1Unix

IDENTIFICATION AND AUTHENTICATION

2.4 Ensure that the --peer-cert-file and --peer-key-file arguments are set as appropriateCIS Red Hat OpenShift Container Platform v1.9.0 L1OpenShift

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

2.4 Ensure that the --peer-cert-file and --peer-key-file arguments are set as appropriate - certCIS Kubernetes v1.20 Benchmark v1.0.1 L1 MasterUnix

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

2.4 Ensure that the --peer-cert-file and --peer-key-file arguments are set as appropriate - keyCIS Kubernetes v1.24 Benchmark v1.0.0 L1 MasterUnix

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

3.1.18 Ensure that the --etcd-certfile and --etcd-keyfile arguments are set as appropriate - etcd-certfileCIS Kubernetes 1.7.0 Benchmark v1.1.0 L1Unix

IDENTIFICATION AND AUTHENTICATION

3.1.18 Ensure that the --etcd-certfile and --etcd-keyfile arguments are set as appropriate - etcd-certfileCIS Kubernetes 1.8 Benchmark v1.2.0 L1Unix

IDENTIFICATION AND AUTHENTICATION

3.1.18 Ensure that the --etcd-certfile and --etcd-keyfile arguments are set as appropriate - etcd-keyfileCIS Kubernetes 1.7.0 Benchmark v1.1.0 L1Unix

IDENTIFICATION AND AUTHENTICATION

3.2.1 Ensure that a minimal audit policy is createdCIS Kubernetes v1.23 Benchmark v1.0.1 L1 MasterUnix

AUDIT AND ACCOUNTABILITY

3.2.1 Ensure that a minimal audit policy is createdCIS Kubernetes v1.24 Benchmark v1.0.0 L1 MasterUnix

AUDIT AND ACCOUNTABILITY

3.2.1 Ensure that a minimal audit policy is createdCIS Kubernetes v1.20 Benchmark v1.0.1 L1 MasterUnix

AUDIT AND ACCOUNTABILITY

4.1.9 Avoid non-default bindings to system:unauthenticatedCIS Google Kubernetes Engine GKE Autopilot v1.3.0 L1GCP

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION

5.7.3 Apply Security Context to Your Pods and ContainersCIS Red Hat OpenShift Container Platform v1.9.0 L2 OpenShiftOpenShift

RISK ASSESSMENT, SYSTEM AND INFORMATION INTEGRITY

5.7.3 Apply Security Context to Your Pods and ContainersCIS Kubernetes v1.20 Benchmark v1.0.1 L2 MasterUnix

CONFIGURATION MANAGEMENT

GOOG-14-006100 - Google Android 14 must be configured to not allow passwords that include more than four repeating or sequential characters - AlphanumericMobileIron - DISA Google Android 14 COPE STIG v2r5MDM

IDENTIFICATION AND AUTHENTICATION

GOOG-14-006400 - Google Android 14 must be configured to not allow more than 10 consecutive failed authentication attempts.MobileIron - DISA Google Android 14 COPE STIG v2r5MDM

ACCESS CONTROL

GOOG-14-006700 - Google Android 14 allowlist must be configured to not include applications with the following characteristics:MobileIron - DISA Google Android 14 COPE STIG v2r5MDM

CONFIGURATION MANAGEMENT, IDENTIFICATION AND AUTHENTICATION

GOOG-14-006800 - Google Android 14 must be configured to not display the following (work profile) notifications when the device is locked: [selection:MobileIron - DISA Google Android 14 COPE STIG v2r5MDM

ACCESS CONTROL

GOOG-14-007800 - Google Android 14 must be configured to generate audit records for the following auditable events: Detected integrity violations.MobileIron - DISA Google Android 14 COPE STIG v2r5MDM

AUDIT AND ACCOUNTABILITY

GOOG-14-009400 - Google Android 14 must be configured to disable all Bluetooth profiles except for HSP (Headset Profile), HFP (Hands-Free Profile), SPP (Serial Port Profile), A2DP (Advanced Audio Distribution Profile), AVRCP (Audio/Video Remote Control Profile), and PBAP (Phone Book Access Profile) - SPP.AirWatch - DISA Google Android 14 COPE STIG v2r5MDM

CONFIGURATION MANAGEMENT

GOOG-14-010000 - Google Android 14 must have the DOD root and intermediate PKI certificates installed.AirWatch - DISA Google Android 14 COPE STIG v2r5MDM

CONFIGURATION MANAGEMENT

GOOG-14-010000 - Google Android 14 must have the DOD root and intermediate PKI certificates installed.MobileIron - DISA Google Android 14 COPE STIG v2r5MDM

CONFIGURATION MANAGEMENT

GOOG-14-010300 - Google Android 14 must be provisioned as a fully managed device and configured to create a work profile.MobileIron - DISA Google Android 14 COPE STIG v2r5MDM

CONFIGURATION MANAGEMENT

GOOG-14-010400 - The Google Android 14 work profile must be configured to disable automatic completion of workspace internet browser text input.AirWatch - DISA Google Android 14 COPE STIG v2r5MDM

CONFIGURATION MANAGEMENT

GOOG-14-010600 - Google Android 14 must be configured to disallow configuration of date and time.AirWatch - DISA Google Android 14 COPE STIG v2r5MDM

CONFIGURATION MANAGEMENT

GOOG-14-010900 - Android 14 devices must be configured to disable the use of third-party keyboards.MobileIron - DISA Google Android 14 COPE STIG v2r5MDM

CONFIGURATION MANAGEMENT

GOOG-14-013200 - Google Android 14 must disable wireless printing.MobileIron - DISA Google Android 14 COPE STIG v2r5MDM

CONFIGURATION MANAGEMENT

GOOG-14-013300 - Google Android 14 must disable screen capture.AirWatch - DISA Google Android 14 COPE STIG v2r5MDM

CONFIGURATION MANAGEMENT

GOOG-14-013400 - Google Android 14 devices must have a Mobile Threat Detection (MTD) app installed.MobileIron - DISA Google Android 14 COPE STIG v2r5MDM

CONFIGURATION MANAGEMENT