| 1.1.2 Ensure that the --basic-auth-file argument is not set | CIS Kubernetes 1.11 Benchmark v1.3.0 L1 | Unix | IDENTIFICATION AND AUTHENTICATION |
| 1.1.7 Ensure that the --insecure-port argument is set to 0 | CIS Kubernetes 1.7.0 Benchmark v1.1.0 L1 | Unix | CONFIGURATION MANAGEMENT |
| 1.1.21 Ensure that the --token-auth-file parameter is not set | CIS Kubernetes 1.7.0 Benchmark v1.1.0 L1 | Unix | IDENTIFICATION AND AUTHENTICATION |
| 1.1.24 Ensure that the admission control plugin PodSecurityPolicy is set | CIS Kubernetes 1.11 Benchmark v1.3.0 L1 | Unix | ACCESS CONTROL |
| 1.1.28 Ensure that the admission control policy is set to ServiceAccount | CIS Kubernetes 1.7.0 Benchmark v1.1.0 L1 | Unix | ACCESS CONTROL |
| 1.3.4 Ensure that the --service-account-private-key-file argument is set as appropriate | CIS Kubernetes v2.0.1 L1 Master Node | Unix | IDENTIFICATION AND AUTHENTICATION |
| 1.4.10 Ensure that the Container Network Interface file ownership is set to root:root | CIS Kubernetes 1.13 Benchmark v1.4.1 L1 | Unix | CONFIGURATION MANAGEMENT |
| 2.1.1 Ensure that the --allow-privileged argument is set to false | CIS Kubernetes 1.11 Benchmark v1.3.0 L1 | Unix | ACCESS CONTROL |
| 2.1.2 Ensure that the --authorization-mode argument is not set to AlwaysAllow | CIS Kubernetes 1.13 Benchmark v1.4.1 L1 | Unix | ACCESS CONTROL |
| 2.1.3 Ensure that the --client-ca-file argument is set as appropriate | CIS Kubernetes 1.13 Benchmark v1.4.1 L1 | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| 2.1.8 Ensure that the --make-iptables-util-chains argument is set to true | CIS Kubernetes 1.7.0 Benchmark v1.1.0 L1 | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| 2.1.15 Ensure that the RotateKubeletServerCertificate argument is set to true | CIS Kubernetes 1.8 Benchmark v1.2.0 L1 | Unix | IDENTIFICATION AND AUTHENTICATION |
| 2.2.3 Ensure that the kubelet service file permissions are set to 644 or more restrictive | CIS Kubernetes 1.8 Benchmark v1.2.0 L1 | Unix | CONFIGURATION MANAGEMENT |
| 2.2.5 Ensure that the proxy kubeconfig file permissions are set to 644 or more restrictive | CIS Kubernetes 1.8 Benchmark v1.2.0 L1 | Unix | CONFIGURATION MANAGEMENT |
| 2.2.5 Ensure that the proxy kubeconfig file permissions are set to 644 or more restrictive | CIS Kubernetes 1.13 Benchmark v1.4.1 L1 | Unix | CONFIGURATION MANAGEMENT |
| 2.2.6 Ensure that the proxy kubeconfig file ownership is set to root:root | CIS Kubernetes 1.11 Benchmark v1.3.0 L1 | Unix | CONFIGURATION MANAGEMENT |
| 2.2.6 Ensure that the proxy kubeconfig file ownership is set to root:root | CIS Kubernetes 1.13 Benchmark v1.4.1 L1 | Unix | CONFIGURATION MANAGEMENT |
| 2.2.7 Ensure that the certificate authorities file permissions are set to 644 or more restrictive | CIS Kubernetes 1.13 Benchmark v1.4.1 L1 | Unix | ACCESS CONTROL |
| 3.1.1 Ensure that the --anonymous-auth argument is set to false | CIS Kubernetes 1.8 Benchmark v1.2.0 L1 | Unix | IDENTIFICATION AND AUTHENTICATION |
| 3.1.2 Ensure that the --basic-auth-file argument is not set | CIS Kubernetes 1.8 Benchmark v1.2.0 L1 | Unix | IDENTIFICATION AND AUTHENTICATION |
| 3.1.5 Ensure that the --insecure-port argument is set to 0 | CIS Kubernetes 1.8 Benchmark v1.2.0 L1 | Unix | CONFIGURATION MANAGEMENT |
| 3.1.8 Ensure that the admission control policy is not set to AlwaysAdmit | CIS Kubernetes 1.7.0 Benchmark v1.1.0 L1 | Unix | ACCESS CONTROL |
| 3.1.16 Ensure that the --service-account-lookup argument is set to true | CIS Kubernetes 1.8 Benchmark v1.2.0 L1 | Unix | IDENTIFICATION AND AUTHENTICATION |
| 3.1.17 Ensure that the --service-account-key-file argument is set as appropriate | CIS Kubernetes 1.7.0 Benchmark v1.1.0 L1 | Unix | IDENTIFICATION AND AUTHENTICATION |
| 3.2.1 Ensure that the --profiling argument is set to false | CIS Kubernetes 1.7.0 Benchmark v1.1.0 L1 | Unix | CONFIGURATION MANAGEMENT |
| 4.1.1 Ensure that the kubelet service file permissions are set to 600 or more restrictive | CIS Kubernetes v2.0.1 L1 Master Node | Unix | ACCESS CONTROL, MEDIA PROTECTION |
| 4.1.2 Ensure that the kubelet service file ownership is set to root:root | CIS Kubernetes v2.0.1 L1 Worker Node | Unix | ACCESS CONTROL |
| 4.1.8 Ensure that the client certificate authorities file ownership is set to root:root | CIS Kubernetes v2.0.1 L1 Worker Node | Unix | ACCESS CONTROL |
| 4.1.9 If the kubelet config.yaml configuration file is being used validate permissions set to 600 or more restrictive | CIS Kubernetes v2.0.1 L1 Worker Node | Unix | ACCESS CONTROL, MEDIA PROTECTION |
| 4.2.1 Ensure that the --anonymous-auth argument is set to false | CIS Kubernetes v2.0.1 L1 Worker Node | Unix | ACCESS CONTROL, MEDIA PROTECTION |
| 4.2.6 Ensure that the --make-iptables-util-chains argument is set to true | CIS Kubernetes v2.0.1 L1 Worker Node | Unix | CONFIGURATION MANAGEMENT |
| 4.2.8 Ensure that the eventRecordQPS argument is set to a level which ensures appropriate event capture | CIS Kubernetes v2.0.1 L2 Worker Node | Unix | AUDIT AND ACCOUNTABILITY |
| 4.2.9 Ensure that the --tls-cert-file and --tls-private-key-file arguments are set as appropriate | CIS Kubernetes v2.0.1 L1 Worker Node | Unix | ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION |
| 4.3.1 Ensure that all Namespaces have Network Policies defined | CIS Google Kubernetes Engine GKE Autopilot v1.3.0 L2 | GCP | SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION |
| 4.3.1 Ensure that the kube-proxy metrics service is bound to localhost | CIS Kubernetes v2.0.1 L1 Worker Node | Unix | ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION |
| 5.1.6 Ensure that Service Account Tokens are only mounted where necessary | CIS Kubernetes v2.0.1 L1 Master Node | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| 5.1.7 Avoid use of system:masters group | CIS Kubernetes v2.0.1 L1 Master Node | Unix | ACCESS CONTROL |
| 5.1.10 Minimize access to the proxy sub-resource of nodes | CIS Kubernetes v2.0.1 L1 Master Node | Unix | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY |
| 5.2.3 Minimize the admission of containers wishing to share the host process ID namespace | CIS Kubernetes v2.0.1 L1 Master Node | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| 5.2.4 Minimize the admission of containers wishing to share the host IPC namespace | CIS Kubernetes v2.0.1 L1 Master Node | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| 5.2.5 Minimize the admission of containers wishing to share the host network namespace | CIS Kubernetes v2.0.1 L1 Master Node | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| 5.2.6 Minimize the admission of containers with allowPrivilegeEscalation | CIS Kubernetes v2.0.1 L1 Master Node | Unix | ACCESS CONTROL |
| 5.2.7 Minimize the admission of root containers | CIS Kubernetes v2.0.1 L2 Master Node | Unix | ACCESS CONTROL |
| 5.2.8 Minimize the admission of containers with the NET_RAW capability | CIS Kubernetes v2.0.1 L1 Master Node | Unix | CONFIGURATION MANAGEMENT |
| 5.2.9 Minimize the admission of containers with capabilities assigned | CIS Kubernetes v2.0.1 L2 Master Node | Unix | CONFIGURATION MANAGEMENT |
| 5.2.12 Minimize the admission of containers which use HostPorts | CIS Kubernetes v2.0.1 L1 Master Node | Unix | CONFIGURATION MANAGEMENT, SYSTEM AND INFORMATION INTEGRITY |
| 5.3.2 Ensure that all Namespaces have Network Policies defined | CIS Kubernetes v2.0.1 L2 Master Node | Unix | SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION |
| TCAT-AS-001670 - RECYCLE_FACADES must be set to true. | DISA STIG Apache Tomcat Application Server 9 v3r4 Middleware | Unix | CONFIGURATION MANAGEMENT |
| WN12-SO-000045 - The system must be configured to use Safe DLL Search Mode. | DISA Windows Server 2012 and 2012 R2 DC STIG v3r7 | Windows | CONFIGURATION MANAGEMENT |
| WN12-SO-000045 - The system must be configured to use Safe DLL Search Mode. | DISA Windows Server 2012 and 2012 R2 MS STIG v3r7 | Windows | CONFIGURATION MANAGEMENT |