Item Search

NameAudit NamePluginCategory
1.1.8 Ensure that the etcd pod specification file ownership is set to root:rootCIS Kubernetes v2.0.1 L1 Master NodeUnix

ACCESS CONTROL

1.1.8 Ensure that the etcd pod specification file ownership is set to root:rootCIS Kubernetes v1.23 Benchmark v1.0.1 L1 MasterUnix

ACCESS CONTROL

1.1.8 Ensure that the etcd pod specification file ownership is set to root:rootCIS Kubernetes v1.20 Benchmark v1.0.1 L1 MasterUnix

ACCESS CONTROL

1.1.8 Ensure that the etcd pod specification file ownership is set to root:rootCIS Kubernetes v1.24 Benchmark v1.0.0 L1 MasterUnix

ACCESS CONTROL

1.1.13 Ensure that the default administrative credential file permissions are set to 600CIS Kubernetes v2.0.1 L1 Master NodeUnix

ACCESS CONTROL, MEDIA PROTECTION

1.1.14 Ensure that the --audit-log-path argument is set as appropriateCIS Kubernetes 1.8 Benchmark v1.2.0 L1Unix

AUDIT AND ACCOUNTABILITY

1.1.15 Ensure that the --audit-log-path argument is set as appropriateCIS Kubernetes 1.13 Benchmark v1.4.1 L1Unix

AUDIT AND ACCOUNTABILITY

1.1.15 Ensure that the --audit-log-path argument is set as appropriateCIS Kubernetes 1.11 Benchmark v1.3.0 L1Unix

AUDIT AND ACCOUNTABILITY

1.1.16 Ensure that the --audit-log-path argument is set as appropriateCIS Kubernetes 1.7.0 Benchmark v1.1.0 L1Unix

AUDIT AND ACCOUNTABILITY

1.1.37 Ensure that the AdvancedAuditing argument is not set to false - AdvancedAuditingCIS Kubernetes 1.13 Benchmark v1.4.1 L1Unix

AUDIT AND ACCOUNTABILITY

1.1.37 Ensure that the AdvancedAuditing argument is not set to false - AdvancedAuditingCIS Kubernetes 1.11 Benchmark v1.3.0 L1Unix

AUDIT AND ACCOUNTABILITY

1.1.37 Ensure that the AdvancedAuditing argument is not set to false - AUDIT_POLICY_FILECIS Kubernetes 1.13 Benchmark v1.4.1 L1Unix

AUDIT AND ACCOUNTABILITY

1.2.18 Ensure that the --audit-log-path argument is setCIS Kubernetes v1.24 Benchmark v1.0.0 L1 MasterUnix

AUDIT AND ACCOUNTABILITY

1.2.18 Ensure that the --audit-log-path argument is setCIS Kubernetes v1.23 Benchmark v1.0.1 L1 MasterUnix

AUDIT AND ACCOUNTABILITY

1.2.21 Ensure that the --audit-log-path argument is setCIS Kubernetes v1.20 Benchmark v1.0.1 L1 MasterUnix

AUDIT AND ACCOUNTABILITY

1.4.7 Ensure that the etcd pod specification file permissions are set to 644 or more restrictiveCIS Kubernetes 1.8 Benchmark v1.2.0 L1Unix

CONFIGURATION MANAGEMENT

1.4.7 Ensure that the etcd pod specification file permissions are set to 644 or more restrictiveCIS Kubernetes 1.13 Benchmark v1.4.1 L1Unix

CONFIGURATION MANAGEMENT

1.4.8 Ensure that the etcd pod specification file ownership is set to root:rootCIS Kubernetes 1.11 Benchmark v1.3.0 L1Unix

CONFIGURATION MANAGEMENT

1.4.8 Ensure that the etcd pod specification file ownership is set to root:rootCIS Kubernetes 1.13 Benchmark v1.4.1 L1Unix

CONFIGURATION MANAGEMENT

1.4.8 Ensure that the etcd pod specification file ownership is set to root:rootCIS Kubernetes 1.8 Benchmark v1.2.0 L1Unix

CONFIGURATION MANAGEMENT

1.6.2 Create administrative boundaries between resources using namespacesCIS Kubernetes 1.13 Benchmark v1.4.1 L1Unix

ACCESS CONTROL

3.1.10 Ensure that the --audit-log-path argument is set as appropriateCIS Kubernetes 1.7.0 Benchmark v1.1.0 L1Unix

AUDIT AND ACCOUNTABILITY

3.1.10 Ensure that the --audit-log-path argument is set as appropriateCIS Kubernetes 1.8 Benchmark v1.2.0 L1Unix

AUDIT AND ACCOUNTABILITY

4.1.4 Ensure that default service accounts are not actively usedCIS Google Kubernetes Engine GKE v1.9.0 L1 GCPGCP

ACCESS CONTROL

4.4.1 Consider external secret storageCIS Google Kubernetes Engine GKE Autopilot v1.3.0 L2GCP

SYSTEM AND COMMUNICATIONS PROTECTION

4.4.2 Consider external secret storageCIS Google Kubernetes Engine GKE v1.9.0 L2 GCPGCP

SYSTEM AND COMMUNICATIONS PROTECTION

4.6.1 Create administrative boundaries between resources using namespacesCIS Google Kubernetes Engine GKE v1.9.0 L1 GCPGCP

SYSTEM AND COMMUNICATIONS PROTECTION

4.6.1 Create administrative boundaries between resources using namespacesCIS Google Kubernetes Engine GKE Autopilot v1.3.0 L1GCP

SYSTEM AND COMMUNICATIONS PROTECTION

5.1.2 Minimize access to secretsCIS Kubernetes v1.23 Benchmark v1.0.1 L1 MasterUnix

ACCESS CONTROL

5.1.5 Ensure that default service accounts are not actively used.CIS Kubernetes v2.0.1 L1 Master NodeUnix

ACCESS CONTROL

5.2.1 Ensure GKE clusters are not running using the Compute Engine default service accountCIS Google Kubernetes Engine GKE Autopilot v1.3.0 L2GCP

IDENTIFICATION AND AUTHENTICATION

5.4.2 Consider external secret storageCIS Kubernetes v1.23 Benchmark v1.0.1 L2 MasterUnix

SYSTEM AND COMMUNICATIONS PROTECTION

5.4.2 Consider external secret storageCIS Kubernetes v1.20 Benchmark v1.0.1 L2 MasterUnix

SYSTEM AND COMMUNICATIONS PROTECTION

5.4.2 Consider external secret storageCIS Red Hat OpenShift Container Platform v1.9.0 L2 OpenShiftOpenShift

SYSTEM AND COMMUNICATIONS PROTECTION

5.4.2 Consider external secret storageCIS Kubernetes v2.0.1 L2 Master NodeUnix

SYSTEM AND COMMUNICATIONS PROTECTION

5.4.2 Consider external secret storageCIS Kubernetes v1.24 Benchmark v1.0.0 L2 MasterUnix

SYSTEM AND COMMUNICATIONS PROTECTION

5.5.2 Ensure Node Auto-Repair is Enabled for GKE NodesCIS Google Kubernetes Engine GKE v1.9.0 L2 GCPGCP

RISK ASSESSMENT

5.6.1 Create administrative boundaries between resources using namespacesCIS Kubernetes v2.0.1 L1 Master NodeUnix

SYSTEM AND COMMUNICATIONS PROTECTION

5.7.1 Create administrative boundaries between resources using namespacesCIS Red Hat OpenShift Container Platform v1.9.0 L1OpenShift

SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

5.7.1 Create administrative boundaries between resources using namespacesCIS Kubernetes v1.23 Benchmark v1.0.1 L1 MasterUnix

SYSTEM AND COMMUNICATIONS PROTECTION

CNTR-K8-001540 - Kubernetes etcd must have peer-cert-file set for secure communication.DISA Kubernetes STIG v2r6Unix

SYSTEM AND COMMUNICATIONS PROTECTION

CNTR-K8-001550 - Kubernetes etcd must have a peer-key-file set for secure communication.DISA Kubernetes STIG v2r6Unix

SYSTEM AND COMMUNICATIONS PROTECTION

CNTR-K8-002640 - Kubernetes endpoints must use approved organizational certificate and key pair to protect information in transit.DISA Kubernetes STIG v2r6Unix

SYSTEM AND COMMUNICATIONS PROTECTION

CNTR-K8-003210 - The Kubernetes kubeadm.conf must be owned by root.DISA Kubernetes STIG v2r6Unix

CONFIGURATION MANAGEMENT

CNTR-K8-003220 - The Kubernetes kubeadm.conf must have file permissions set to 644 or more restrictive.DISA Kubernetes STIG v2r6Unix

CONFIGURATION MANAGEMENT

CNTR-K8-003330 - The Kubernetes PKI CRT must have file permissions set to 644 or more restrictive.DISA Kubernetes STIG v2r6Unix

CONFIGURATION MANAGEMENT

CNTR-K8-003340 - The Kubernetes PKI keys must have file permissions set to 600 or more restrictive.DISA Kubernetes STIG v2r6Unix

CONFIGURATION MANAGEMENT

DISA_STIG_JRE_8_Windows_v2r1.audit for DISA Oracle Java Runtime Environment (JRE) Version 8 for Windows v2r1 STIGDISA STIG Oracle JRE 8 Windows v2r1Windows
DISA_STIG_McAfee_VirusScan_8.8_Managed_Client_v6r1.audit from DISA McAfee VirusScan 8.8 Managed Client Security Technical implementation Guide v6r1 STIGDISA McAfee VirusScan 8.8 Managed Client STIG v6r1Windows
DISA_STIG_VMware_vSphere_8.0_vCenter_Appliance_ESX_Agent_Manager_EAM_v2r2.audit from DISA VMware vSphere 8.0 vCenter Appliance ESX Agent Manager EAM STIG v2r2DISA VMware vSphere 8.0 vCenter Appliance ESX Agent Manager EAM STIG v2r2Unix