| 1.1.8 Ensure that the etcd pod specification file ownership is set to root:root | CIS Kubernetes v2.0.1 L1 Master Node | Unix | ACCESS CONTROL |
| 1.1.8 Ensure that the etcd pod specification file ownership is set to root:root | CIS Kubernetes v1.23 Benchmark v1.0.1 L1 Master | Unix | ACCESS CONTROL |
| 1.1.8 Ensure that the etcd pod specification file ownership is set to root:root | CIS Kubernetes v1.20 Benchmark v1.0.1 L1 Master | Unix | ACCESS CONTROL |
| 1.1.8 Ensure that the etcd pod specification file ownership is set to root:root | CIS Kubernetes v1.24 Benchmark v1.0.0 L1 Master | Unix | ACCESS CONTROL |
| 1.1.13 Ensure that the default administrative credential file permissions are set to 600 | CIS Kubernetes v2.0.1 L1 Master Node | Unix | ACCESS CONTROL, MEDIA PROTECTION |
| 1.1.14 Ensure that the --audit-log-path argument is set as appropriate | CIS Kubernetes 1.8 Benchmark v1.2.0 L1 | Unix | AUDIT AND ACCOUNTABILITY |
| 1.1.15 Ensure that the --audit-log-path argument is set as appropriate | CIS Kubernetes 1.13 Benchmark v1.4.1 L1 | Unix | AUDIT AND ACCOUNTABILITY |
| 1.1.15 Ensure that the --audit-log-path argument is set as appropriate | CIS Kubernetes 1.11 Benchmark v1.3.0 L1 | Unix | AUDIT AND ACCOUNTABILITY |
| 1.1.16 Ensure that the --audit-log-path argument is set as appropriate | CIS Kubernetes 1.7.0 Benchmark v1.1.0 L1 | Unix | AUDIT AND ACCOUNTABILITY |
| 1.1.37 Ensure that the AdvancedAuditing argument is not set to false - AdvancedAuditing | CIS Kubernetes 1.13 Benchmark v1.4.1 L1 | Unix | AUDIT AND ACCOUNTABILITY |
| 1.1.37 Ensure that the AdvancedAuditing argument is not set to false - AdvancedAuditing | CIS Kubernetes 1.11 Benchmark v1.3.0 L1 | Unix | AUDIT AND ACCOUNTABILITY |
| 1.1.37 Ensure that the AdvancedAuditing argument is not set to false - AUDIT_POLICY_FILE | CIS Kubernetes 1.13 Benchmark v1.4.1 L1 | Unix | AUDIT AND ACCOUNTABILITY |
| 1.2.18 Ensure that the --audit-log-path argument is set | CIS Kubernetes v1.24 Benchmark v1.0.0 L1 Master | Unix | AUDIT AND ACCOUNTABILITY |
| 1.2.18 Ensure that the --audit-log-path argument is set | CIS Kubernetes v1.23 Benchmark v1.0.1 L1 Master | Unix | AUDIT AND ACCOUNTABILITY |
| 1.2.21 Ensure that the --audit-log-path argument is set | CIS Kubernetes v1.20 Benchmark v1.0.1 L1 Master | Unix | AUDIT AND ACCOUNTABILITY |
| 1.4.7 Ensure that the etcd pod specification file permissions are set to 644 or more restrictive | CIS Kubernetes 1.8 Benchmark v1.2.0 L1 | Unix | CONFIGURATION MANAGEMENT |
| 1.4.7 Ensure that the etcd pod specification file permissions are set to 644 or more restrictive | CIS Kubernetes 1.13 Benchmark v1.4.1 L1 | Unix | CONFIGURATION MANAGEMENT |
| 1.4.8 Ensure that the etcd pod specification file ownership is set to root:root | CIS Kubernetes 1.11 Benchmark v1.3.0 L1 | Unix | CONFIGURATION MANAGEMENT |
| 1.4.8 Ensure that the etcd pod specification file ownership is set to root:root | CIS Kubernetes 1.13 Benchmark v1.4.1 L1 | Unix | CONFIGURATION MANAGEMENT |
| 1.4.8 Ensure that the etcd pod specification file ownership is set to root:root | CIS Kubernetes 1.8 Benchmark v1.2.0 L1 | Unix | CONFIGURATION MANAGEMENT |
| 1.6.2 Create administrative boundaries between resources using namespaces | CIS Kubernetes 1.13 Benchmark v1.4.1 L1 | Unix | ACCESS CONTROL |
| 3.1.10 Ensure that the --audit-log-path argument is set as appropriate | CIS Kubernetes 1.7.0 Benchmark v1.1.0 L1 | Unix | AUDIT AND ACCOUNTABILITY |
| 3.1.10 Ensure that the --audit-log-path argument is set as appropriate | CIS Kubernetes 1.8 Benchmark v1.2.0 L1 | Unix | AUDIT AND ACCOUNTABILITY |
| 4.1.4 Ensure that default service accounts are not actively used | CIS Google Kubernetes Engine GKE v1.9.0 L1 GCP | GCP | ACCESS CONTROL |
| 4.4.1 Consider external secret storage | CIS Google Kubernetes Engine GKE Autopilot v1.3.0 L2 | GCP | SYSTEM AND COMMUNICATIONS PROTECTION |
| 4.4.2 Consider external secret storage | CIS Google Kubernetes Engine GKE v1.9.0 L2 GCP | GCP | SYSTEM AND COMMUNICATIONS PROTECTION |
| 4.6.1 Create administrative boundaries between resources using namespaces | CIS Google Kubernetes Engine GKE v1.9.0 L1 GCP | GCP | SYSTEM AND COMMUNICATIONS PROTECTION |
| 4.6.1 Create administrative boundaries between resources using namespaces | CIS Google Kubernetes Engine GKE Autopilot v1.3.0 L1 | GCP | SYSTEM AND COMMUNICATIONS PROTECTION |
| 5.1.2 Minimize access to secrets | CIS Kubernetes v1.23 Benchmark v1.0.1 L1 Master | Unix | ACCESS CONTROL |
| 5.1.5 Ensure that default service accounts are not actively used. | CIS Kubernetes v2.0.1 L1 Master Node | Unix | ACCESS CONTROL |
| 5.2.1 Ensure GKE clusters are not running using the Compute Engine default service account | CIS Google Kubernetes Engine GKE Autopilot v1.3.0 L2 | GCP | IDENTIFICATION AND AUTHENTICATION |
| 5.4.2 Consider external secret storage | CIS Kubernetes v1.23 Benchmark v1.0.1 L2 Master | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| 5.4.2 Consider external secret storage | CIS Kubernetes v1.20 Benchmark v1.0.1 L2 Master | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| 5.4.2 Consider external secret storage | CIS Red Hat OpenShift Container Platform v1.9.0 L2 OpenShift | OpenShift | SYSTEM AND COMMUNICATIONS PROTECTION |
| 5.4.2 Consider external secret storage | CIS Kubernetes v2.0.1 L2 Master Node | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| 5.4.2 Consider external secret storage | CIS Kubernetes v1.24 Benchmark v1.0.0 L2 Master | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| 5.5.2 Ensure Node Auto-Repair is Enabled for GKE Nodes | CIS Google Kubernetes Engine GKE v1.9.0 L2 GCP | GCP | RISK ASSESSMENT |
| 5.6.1 Create administrative boundaries between resources using namespaces | CIS Kubernetes v2.0.1 L1 Master Node | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| 5.7.1 Create administrative boundaries between resources using namespaces | CIS Red Hat OpenShift Container Platform v1.9.0 L1 | OpenShift | SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION |
| 5.7.1 Create administrative boundaries between resources using namespaces | CIS Kubernetes v1.23 Benchmark v1.0.1 L1 Master | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| CNTR-K8-001540 - Kubernetes etcd must have peer-cert-file set for secure communication. | DISA Kubernetes STIG v2r6 | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| CNTR-K8-001550 - Kubernetes etcd must have a peer-key-file set for secure communication. | DISA Kubernetes STIG v2r6 | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| CNTR-K8-002640 - Kubernetes endpoints must use approved organizational certificate and key pair to protect information in transit. | DISA Kubernetes STIG v2r6 | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| CNTR-K8-003210 - The Kubernetes kubeadm.conf must be owned by root. | DISA Kubernetes STIG v2r6 | Unix | CONFIGURATION MANAGEMENT |
| CNTR-K8-003220 - The Kubernetes kubeadm.conf must have file permissions set to 644 or more restrictive. | DISA Kubernetes STIG v2r6 | Unix | CONFIGURATION MANAGEMENT |
| CNTR-K8-003330 - The Kubernetes PKI CRT must have file permissions set to 644 or more restrictive. | DISA Kubernetes STIG v2r6 | Unix | CONFIGURATION MANAGEMENT |
| CNTR-K8-003340 - The Kubernetes PKI keys must have file permissions set to 600 or more restrictive. | DISA Kubernetes STIG v2r6 | Unix | CONFIGURATION MANAGEMENT |
| DISA_STIG_JRE_8_Windows_v2r1.audit for DISA Oracle Java Runtime Environment (JRE) Version 8 for Windows v2r1 STIG | DISA STIG Oracle JRE 8 Windows v2r1 | Windows | |
| DISA_STIG_McAfee_VirusScan_8.8_Managed_Client_v6r1.audit from DISA McAfee VirusScan 8.8 Managed Client Security Technical implementation Guide v6r1 STIG | DISA McAfee VirusScan 8.8 Managed Client STIG v6r1 | Windows | |
| DISA_STIG_VMware_vSphere_8.0_vCenter_Appliance_ESX_Agent_Manager_EAM_v2r2.audit from DISA VMware vSphere 8.0 vCenter Appliance ESX Agent Manager EAM STIG v2r2 | DISA VMware vSphere 8.0 vCenter Appliance ESX Agent Manager EAM STIG v2r2 | Unix | |