Item Search

NameAudit NamePluginCategory
1.1.10 Ensure that the Container Network Interface file ownership is set to root:rootCIS Kubernetes v1.23 Benchmark v1.0.1 L1 MasterUnix

ACCESS CONTROL

1.16 WN10-00-000070CIS Microsoft Windows 10 STIG v1.0.0 CAT IWindows

ACCESS CONTROL

1.37 SOL-11.1-020050CIS Solaris 11 X86 STIG v1.0.0 CAT IIUnix

AUDIT AND ACCOUNTABILITY

1.39 SOL-11.1-020080CIS Solaris 11 SPARC STIG v1.0.0 CAT IIUnix

AUDIT AND ACCOUNTABILITY

1.103 WN10-CC-000030CIS Microsoft Windows 10 STIG v1.0.0 CAT IIIWindows

CONFIGURATION MANAGEMENT

4.1.3 If proxy kube proxy configuration file exists ensure permissions are set to 644 or more restrictiveCIS Red Hat OpenShift Container Platform v1.9.0 L1OpenShift

ACCESS CONTROL, MEDIA PROTECTION

4.1.7 Ensure that the certificate authorities file permissions are set to 600 or more restrictiveCIS Kubernetes v1.23 Benchmark v1.0.1 L1 WorkerUnix

ACCESS CONTROL, MEDIA PROTECTION

4.1.9 Ensure that the kubelet --config configuration file has permissions set to 600 or more restrictiveCIS Kubernetes v1.20 Benchmark v1.0.1 L1 WorkerUnix

ACCESS CONTROL, MEDIA PROTECTION

4.2.8 Ensure that the --hostname-override argument is not setCIS Kubernetes v1.23 Benchmark v1.0.1 L1 WorkerUnix

CONFIGURATION MANAGEMENT

4.2.9 Ensure that the eventRecordQPS argument is set to a level which ensures appropriate event captureCIS Kubernetes v1.24 Benchmark v1.0.0 L2 WorkerUnix

AUDIT AND ACCOUNTABILITY

4.2.12 Verify that the RotateKubeletServerCertificate argument is set to trueCIS Kubernetes v1.20 Benchmark v1.0.1 L1 WorkerUnix

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

4.4.1 Prefer using secrets as files over secrets as environment variablesCIS Google Kubernetes Engine GKE v2.0.0 L2GCP

SYSTEM AND COMMUNICATIONS PROTECTION

4.6.2 Require RuntimeDefault seccomp or approved custom profiles for workload podsCIS Google Kubernetes Engine GKE v2.0.0 L2GCP

CONFIGURATION MANAGEMENT

4.6.3 Require hardened security contexts for all workload Pods and containersCIS Google Kubernetes Engine GKE v2.0.0 L2GCP

CONFIGURATION MANAGEMENT

4.6.4 Avoid deploying workloads in the default namespaceCIS Google Kubernetes Engine GKE v2.0.0 L2GCP

CONFIGURATION MANAGEMENT, CONTINGENCY PLANNING, PLANNING, PROGRAM MANAGEMENT, SYSTEM AND SERVICES ACQUISITION, SYSTEM AND COMMUNICATIONS PROTECTION

5.1.1 Ensure that the cluster-admin role is only used where requiredCIS Kubernetes v1.20 Benchmark v1.0.1 L1 MasterUnix

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

5.1.2 Grant least privilege IAM access to Artifact Registry repositoriesCIS Google Kubernetes Engine GKE v2.0.0 L2GCP

ACCESS CONTROL, MEDIA PROTECTION

5.1.6 Ensure that Service Account Tokens are only mounted where necessary - podsCIS Kubernetes v1.24 Benchmark v1.0.0 L1 MasterUnix

SYSTEM AND COMMUNICATIONS PROTECTION

5.1.6 Ensure that Service Account Tokens are only mounted where necessary - serviceaccountsCIS Kubernetes v1.23 Benchmark v1.0.1 L1 MasterUnix

SYSTEM AND COMMUNICATIONS PROTECTION

5.2.2 Minimize the admission of privileged containersCIS Kubernetes v1.24 Benchmark v1.0.0 L1 MasterUnix

ACCESS CONTROL

5.2.3 Minimize the admission of containers wishing to share the host process ID namespaceCIS Kubernetes v1.23 Benchmark v1.0.1 L1 MasterUnix

SYSTEM AND COMMUNICATIONS PROTECTION

5.2.8 Minimize the admission of containers with added capabilitiesCIS Kubernetes v1.20 Benchmark v1.0.1 L1 MasterUnix

CONFIGURATION MANAGEMENT

5.2.8 Minimize the admission of containers with the NET_RAW capabilityCIS Kubernetes v1.23 Benchmark v1.0.1 L1 MasterUnix

CONFIGURATION MANAGEMENT

5.2.9 Minimize the admission of containers with added capabilitiesCIS Kubernetes v1.23 Benchmark v1.0.1 L1 MasterUnix

CONFIGURATION MANAGEMENT

5.5.2 Verify node auto-repair is enabled for GKE node poolsCIS Google Kubernetes Engine GKE v2.0.0 L2GCP

RISK ASSESSMENT

5.6.1 Enable VPC Flow Logs and Intranode VisibilityCIS Google Kubernetes Engine GKE v2.0.0 L2GCP

AUDIT AND ACCOUNTABILITY, SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND INFORMATION INTEGRITY

5.6.6 Apply least privilege firewall rules to GKE worker nodesCIS Google Kubernetes Engine GKE v2.0.0 L2GCP

SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

5.6.7 Use Google managed SSL certificates for GKE Ingress TLSCIS Google Kubernetes Engine GKE v2.0.0 L2GCP

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

5.10.2 Use GKE Sandbox for untrusted or high risk workloadsCIS Google Kubernetes Engine GKE v2.0.0 L2GCP

SYSTEM AND COMMUNICATIONS PROTECTION

BIND-9X-001500 - A BIND 9.x server implementation must be operating on a Current-Stable version as defined by ISC.DISA BIND 9.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

CIS_Kubernetes_v1.4.1_Level_1.audit from CIS Kubernetes Benchmark v1.4.1CIS Kubernetes 1.13 Benchmark v1.4.1 L1Unix

CONFIGURATION MANAGEMENT

CIS_Kubernetes_v1.20_v1.0.1_Level_2_Master.audit from CIS Kubernetes v1.20 Benchmark v1.0.1CIS Kubernetes v1.20 Benchmark v1.0.1 L2 MasterUnix

CONFIGURATION MANAGEMENT

CIS_Kubernetes_v1.23_v1.0.1_Level_1_Worker.audit from CIS Kubernetes v1.23 Benchmark v1.0.1CIS Kubernetes v1.23 Benchmark v1.0.1 L1 WorkerUnix

CONFIGURATION MANAGEMENT

CIS_Kubernetes_v1.24_v1.0.0_Level_1_Worker.audit from CIS Kubernetes v1.24 Benchmark v1.0.0CIS Kubernetes v1.24 Benchmark v1.0.0 L1 WorkerUnix

CONFIGURATION MANAGEMENT

CIS_Kubernetes_v1.24_v1.0.0_Level_2_Master.audit from CIS Kubernetes v1.24 Benchmark v1.0.0CIS Kubernetes v1.24 Benchmark v1.0.0 L2 MasterUnix

CONFIGURATION MANAGEMENT

DO6748-ORACLE11 - Case sensitivity for passwords should be enabled - 'sec_case_sensitive_logon = true'DISA STIG Oracle 11 Instance v9r1 DatabaseOracleDB
MYS8-00-002500 - The MySQL Database Server 8.0 must generate audit records when unsuccessful attempts to add privileges/permissions occur.DISA Oracle MySQL 8.0 v2r2 DBMySQLDB

AUDIT AND ACCOUNTABILITY

SOL-11.1-020080 - System packages must be configured with the vendor-provided files, permissions, and ownerships.DISA Solaris 11 SPARC STIG v3r6Unix

AUDIT AND ACCOUNTABILITY

VCPG-67-000022 - Rsyslog must be configured to monitor VMware Postgres logs - logDISA STIG VMware vSphere 6.7 PostgreSQL v1r2Unix

AUDIT AND ACCOUNTABILITY

WN10-00-000150 - Structured Exception Handling Overwrite Protection (SEHOP) must be enabled.DISA Microsoft Windows 10 STIG v3r6Windows

SYSTEM AND INFORMATION INTEGRITY

WN10-CC-000039 - Run as different user must be removed from context menus.DISA Microsoft Windows 10 STIG v3r6Windows

CONFIGURATION MANAGEMENT

WN12-SO-000038 - The system must be configured to prevent IP source routing.DISA Windows Server 2012 and 2012 R2 MS STIG v3r7Windows

CONFIGURATION MANAGEMENT

WN12-SO-000042 - IPSec Exemptions must be limited.DISA Windows Server 2012 and 2012 R2 MS STIG v3r7Windows

CONFIGURATION MANAGEMENT

WN12-SO-000043 - The system must be configured to ignore NetBIOS name release requests except from WINS servers.DISA Windows Server 2012 and 2012 R2 DC STIG v3r7Windows

SYSTEM AND COMMUNICATIONS PROTECTION

WN12-SO-000043 - The system must be configured to ignore NetBIOS name release requests except from WINS servers.DISA Windows Server 2012 and 2012 R2 MS STIG v3r7Windows

SYSTEM AND COMMUNICATIONS PROTECTION

WN12-SO-000048 - The system must limit how many times unacknowledged TCP data is retransmitted.DISA Windows Server 2012 and 2012 R2 DC STIG v3r7Windows

SYSTEM AND COMMUNICATIONS PROTECTION

WN12-SO-000049 - The system must generate an audit event when the audit log reaches a percentage of full threshold.DISA Windows Server 2012 and 2012 R2 DC STIG v3r7Windows

AUDIT AND ACCOUNTABILITY

WN22-CC-000050 - Windows Server 2022 must be configured to prevent Internet Control Message Protocol (ICMP) redirects from overriding Open Shortest Path First (OSPF)-generated routes.DISA Microsoft Windows Server 2022 STIG v2r10Windows

CONFIGURATION MANAGEMENT

WN22-MS-000020 - Windows Server 2022 local administrator accounts must have their privileged token filtered to prevent elevated privileges from being used over the network on domain-joined member servers.DISA Microsoft Windows Server 2022 STIG v2r8Windows

SYSTEM AND COMMUNICATIONS PROTECTION

WN25-00-000390 - Windows Server 2025 must have the Server Message Block (SMB) v1 protocol disabled on the SMB server.DISA Microsoft Windows Server 2025 STIG v1r1Windows

CONFIGURATION MANAGEMENT