Item Search

NameAudit NamePluginCategory
1.1.2 Ensure that the --basic-auth-file argument is not setCIS Kubernetes 1.11 Benchmark v1.3.0 L1Unix

IDENTIFICATION AND AUTHENTICATION

1.1.7 Ensure that the --insecure-port argument is set to 0CIS Kubernetes 1.7.0 Benchmark v1.1.0 L1Unix

CONFIGURATION MANAGEMENT

1.1.21 Ensure that the --token-auth-file parameter is not setCIS Kubernetes 1.7.0 Benchmark v1.1.0 L1Unix

IDENTIFICATION AND AUTHENTICATION

1.1.24 Ensure that the admission control plugin PodSecurityPolicy is setCIS Kubernetes 1.11 Benchmark v1.3.0 L1Unix

ACCESS CONTROL

1.1.28 Ensure that the admission control policy is set to ServiceAccountCIS Kubernetes 1.7.0 Benchmark v1.1.0 L1Unix

ACCESS CONTROL

1.3.4 Ensure that the --service-account-private-key-file argument is set as appropriateCIS Kubernetes v2.0.1 L1 Master NodeUnix

IDENTIFICATION AND AUTHENTICATION

1.4.10 Ensure that the Container Network Interface file ownership is set to root:rootCIS Kubernetes 1.13 Benchmark v1.4.1 L1Unix

CONFIGURATION MANAGEMENT

2.1.1 Ensure that the --allow-privileged argument is set to falseCIS Kubernetes 1.11 Benchmark v1.3.0 L1Unix

ACCESS CONTROL

2.1.2 Ensure that the --authorization-mode argument is not set to AlwaysAllowCIS Kubernetes 1.13 Benchmark v1.4.1 L1Unix

ACCESS CONTROL

2.1.3 Ensure that the --client-ca-file argument is set as appropriateCIS Kubernetes 1.13 Benchmark v1.4.1 L1Unix

SYSTEM AND COMMUNICATIONS PROTECTION

2.1.8 Ensure that the --make-iptables-util-chains argument is set to trueCIS Kubernetes 1.7.0 Benchmark v1.1.0 L1Unix

SYSTEM AND COMMUNICATIONS PROTECTION

2.1.15 Ensure that the RotateKubeletServerCertificate argument is set to trueCIS Kubernetes 1.8 Benchmark v1.2.0 L1Unix

IDENTIFICATION AND AUTHENTICATION

2.2.3 Ensure that the kubelet service file permissions are set to 644 or more restrictiveCIS Kubernetes 1.8 Benchmark v1.2.0 L1Unix

CONFIGURATION MANAGEMENT

2.2.5 Ensure that the proxy kubeconfig file permissions are set to 644 or more restrictiveCIS Kubernetes 1.8 Benchmark v1.2.0 L1Unix

CONFIGURATION MANAGEMENT

2.2.5 Ensure that the proxy kubeconfig file permissions are set to 644 or more restrictiveCIS Kubernetes 1.13 Benchmark v1.4.1 L1Unix

CONFIGURATION MANAGEMENT

2.2.6 Ensure that the proxy kubeconfig file ownership is set to root:rootCIS Kubernetes 1.11 Benchmark v1.3.0 L1Unix

CONFIGURATION MANAGEMENT

2.2.6 Ensure that the proxy kubeconfig file ownership is set to root:rootCIS Kubernetes 1.13 Benchmark v1.4.1 L1Unix

CONFIGURATION MANAGEMENT

2.2.7 Ensure that the certificate authorities file permissions are set to 644 or more restrictiveCIS Kubernetes 1.13 Benchmark v1.4.1 L1Unix

ACCESS CONTROL

3.1.1 Ensure that the --anonymous-auth argument is set to falseCIS Kubernetes 1.8 Benchmark v1.2.0 L1Unix

IDENTIFICATION AND AUTHENTICATION

3.1.2 Ensure that the --basic-auth-file argument is not setCIS Kubernetes 1.8 Benchmark v1.2.0 L1Unix

IDENTIFICATION AND AUTHENTICATION

3.1.5 Ensure that the --insecure-port argument is set to 0CIS Kubernetes 1.8 Benchmark v1.2.0 L1Unix

CONFIGURATION MANAGEMENT

3.1.8 Ensure that the admission control policy is not set to AlwaysAdmitCIS Kubernetes 1.7.0 Benchmark v1.1.0 L1Unix

ACCESS CONTROL

3.1.16 Ensure that the --service-account-lookup argument is set to trueCIS Kubernetes 1.8 Benchmark v1.2.0 L1Unix

IDENTIFICATION AND AUTHENTICATION

3.1.17 Ensure that the --service-account-key-file argument is set as appropriateCIS Kubernetes 1.7.0 Benchmark v1.1.0 L1Unix

IDENTIFICATION AND AUTHENTICATION

3.2.1 Ensure that the --profiling argument is set to falseCIS Kubernetes 1.7.0 Benchmark v1.1.0 L1Unix

CONFIGURATION MANAGEMENT

4.1.1 Ensure that the kubelet service file permissions are set to 600 or more restrictiveCIS Kubernetes v2.0.1 L1 Master NodeUnix

ACCESS CONTROL, MEDIA PROTECTION

4.1.2 Ensure that the kubelet service file ownership is set to root:rootCIS Kubernetes v2.0.1 L1 Worker NodeUnix

ACCESS CONTROL

4.1.8 Ensure that the client certificate authorities file ownership is set to root:rootCIS Kubernetes v2.0.1 L1 Worker NodeUnix

ACCESS CONTROL

4.1.9 If the kubelet config.yaml configuration file is being used validate permissions set to 600 or more restrictiveCIS Kubernetes v2.0.1 L1 Worker NodeUnix

ACCESS CONTROL, MEDIA PROTECTION

4.2.1 Ensure that the --anonymous-auth argument is set to falseCIS Kubernetes v2.0.1 L1 Worker NodeUnix

ACCESS CONTROL, MEDIA PROTECTION

4.2.6 Ensure that the --make-iptables-util-chains argument is set to trueCIS Kubernetes v2.0.1 L1 Worker NodeUnix

CONFIGURATION MANAGEMENT

4.2.8 Ensure that the eventRecordQPS argument is set to a level which ensures appropriate event captureCIS Kubernetes v2.0.1 L2 Worker NodeUnix

AUDIT AND ACCOUNTABILITY

4.2.9 Ensure that the --tls-cert-file and --tls-private-key-file arguments are set as appropriateCIS Kubernetes v2.0.1 L1 Worker NodeUnix

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

4.3.1 Ensure that all Namespaces have Network Policies definedCIS Google Kubernetes Engine GKE Autopilot v1.3.0 L2GCP

SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

4.3.1 Ensure that the kube-proxy metrics service is bound to localhostCIS Kubernetes v2.0.1 L1 Worker NodeUnix

ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION

5.1.6 Ensure that Service Account Tokens are only mounted where necessaryCIS Kubernetes v2.0.1 L1 Master NodeUnix

SYSTEM AND COMMUNICATIONS PROTECTION

5.1.7 Avoid use of system:masters groupCIS Kubernetes v2.0.1 L1 Master NodeUnix

ACCESS CONTROL

5.1.10 Minimize access to the proxy sub-resource of nodesCIS Kubernetes v2.0.1 L1 Master NodeUnix

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

5.2.3 Minimize the admission of containers wishing to share the host process ID namespaceCIS Kubernetes v2.0.1 L1 Master NodeUnix

SYSTEM AND COMMUNICATIONS PROTECTION

5.2.4 Minimize the admission of containers wishing to share the host IPC namespaceCIS Kubernetes v2.0.1 L1 Master NodeUnix

SYSTEM AND COMMUNICATIONS PROTECTION

5.2.5 Minimize the admission of containers wishing to share the host network namespaceCIS Kubernetes v2.0.1 L1 Master NodeUnix

SYSTEM AND COMMUNICATIONS PROTECTION

5.2.6 Minimize the admission of containers with allowPrivilegeEscalationCIS Kubernetes v2.0.1 L1 Master NodeUnix

ACCESS CONTROL

5.2.7 Minimize the admission of root containersCIS Kubernetes v2.0.1 L2 Master NodeUnix

ACCESS CONTROL

5.2.8 Minimize the admission of containers with the NET_RAW capabilityCIS Kubernetes v2.0.1 L1 Master NodeUnix

CONFIGURATION MANAGEMENT

5.2.9 Minimize the admission of containers with capabilities assignedCIS Kubernetes v2.0.1 L2 Master NodeUnix

CONFIGURATION MANAGEMENT

5.2.12 Minimize the admission of containers which use HostPortsCIS Kubernetes v2.0.1 L1 Master NodeUnix

CONFIGURATION MANAGEMENT, SYSTEM AND INFORMATION INTEGRITY

5.3.2 Ensure that all Namespaces have Network Policies definedCIS Kubernetes v2.0.1 L2 Master NodeUnix

SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

TCAT-AS-001670 - RECYCLE_FACADES must be set to true.DISA STIG Apache Tomcat Application Server 9 v3r4 MiddlewareUnix

CONFIGURATION MANAGEMENT

WN12-SO-000045 - The system must be configured to use Safe DLL Search Mode.DISA Windows Server 2012 and 2012 R2 DC STIG v3r7Windows

CONFIGURATION MANAGEMENT

WN12-SO-000045 - The system must be configured to use Safe DLL Search Mode.DISA Windows Server 2012 and 2012 R2 MS STIG v3r7Windows

CONFIGURATION MANAGEMENT