| 1.1.7 Ensure that the etcd pod specification file permissions are set to 600 or more restrictive | CIS Kubernetes v2.0.1 L1 Master Node | Unix | ACCESS CONTROL, MEDIA PROTECTION |
| 1.1.7 Ensure that the etcd pod specification file permissions are set to 600 or more restrictive | CIS Kubernetes v1.20 Benchmark v1.0.1 L1 Master | Unix | ACCESS CONTROL, MEDIA PROTECTION |
| 1.1.7 Ensure that the etcd pod specification file permissions are set to 600 or more restrictive | CIS Kubernetes v1.23 Benchmark v1.0.1 L1 Master | Unix | ACCESS CONTROL, MEDIA PROTECTION |
| 1.1.7 Ensure that the etcd pod specification file permissions are set to 600 or more restrictive | CIS Kubernetes v1.24 Benchmark v1.0.0 L1 Master | Unix | ACCESS CONTROL, MEDIA PROTECTION |
| 1.1.7 Ensure that the etcd pod specification file permissions are set to 600 or more restrictive | CIS Red Hat OpenShift Container Platform v1.9.0 L1 | OpenShift | ACCESS CONTROL, MEDIA PROTECTION |
| 1.1.8 Ensure that the etcd pod specification file ownership is set to root:root | CIS Red Hat OpenShift Container Platform v1.9.0 L1 | OpenShift | ACCESS CONTROL |
| 1.1.14 Ensure that the default administrative credential file ownership is set to root:root | CIS Kubernetes v2.0.1 L1 Master Node | Unix | ACCESS CONTROL |
| 1.1.20 Ensure that the Kubernetes PKI certificate file permissions are set to 600 or more restrictive | CIS Kubernetes v1.23 Benchmark v1.0.1 L1 Master | Unix | ACCESS CONTROL |
| 1.1.20 Ensure that the Kubernetes PKI certificate file permissions are set to 600 or more restrictive | CIS Kubernetes v1.24 Benchmark v1.0.0 L1 Master | Unix | ACCESS CONTROL |
| 1.1.20 Ensure that the Kubernetes PKI certificate file permissions are set to 644 or more restrictive | CIS Kubernetes v2.0.1 L1 Master Node | Unix | ACCESS CONTROL |
| 1.1.21 Ensure that the Kubernetes PKI key file permissions are set to 600 | CIS Kubernetes v1.24 Benchmark v1.0.0 L1 Master | Unix | ACCESS CONTROL, MEDIA PROTECTION |
| 1.1.21 Ensure that the Kubernetes PKI key file permissions are set to 600 | CIS Kubernetes v2.0.1 L1 Master Node | Unix | ACCESS CONTROL, MEDIA PROTECTION |
| 1.1.21 Ensure that the Kubernetes PKI key file permissions are set to 600 | CIS Kubernetes v1.23 Benchmark v1.0.1 L1 Master | Unix | ACCESS CONTROL, MEDIA PROTECTION |
| 1.1.21 Ensure that the Kubernetes PKI key file permissions are set to 600 | CIS Kubernetes v1.20 Benchmark v1.0.1 L1 Master | Unix | ACCESS CONTROL, MEDIA PROTECTION |
| 1.1.29 Ensure that the --client-ca-file argument is set as appropriate | CIS Kubernetes 1.8 Benchmark v1.2.0 L1 | Unix | IDENTIFICATION AND AUTHENTICATION |
| 1.1.37 Ensure that the AdvancedAuditing argument is not set to false - audit-policy-file | CIS Kubernetes 1.13 Benchmark v1.4.1 L1 | Unix | AUDIT AND ACCOUNTABILITY |
| 1.2.18 Ensure that the --audit-log-path argument is set | CIS Red Hat OpenShift Container Platform v1.9.0 L1 | OpenShift | AUDIT AND ACCOUNTABILITY |
| 1.2.25 Ensure that the --client-ca-file argument is set as appropriate | CIS Kubernetes v2.0.1 L1 Master Node | Unix | ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION |
| 1.4.7 Ensure that the etcd pod specification file permissions are set to 644 or more restrictive | CIS Kubernetes 1.11 Benchmark v1.3.0 L1 | Unix | CONFIGURATION MANAGEMENT |
| 1.4.21 Ensure that the Kubernetes PKI key file permissions are set to 600 | CIS Kubernetes 1.13 Benchmark v1.4.1 L1 | Unix | CONFIGURATION MANAGEMENT |
| 1.6.2 Create administrative boundaries between resources using namespaces | CIS Kubernetes 1.11 Benchmark v1.3.0 L1 | Unix | ACCESS CONTROL |
| 4.1.4 Ensure that default service accounts are not actively used | CIS Google Kubernetes Engine GKE Autopilot v1.3.0 L1 | GCP | ACCESS CONTROL |
| 4.6.4 The default namespace should not be used | CIS Google Kubernetes Engine GKE v1.9.0 L2 Unix | Unix | CONFIGURATION MANAGEMENT, CONTINGENCY PLANNING, PLANNING, PROGRAM MANAGEMENT, SYSTEM AND SERVICES ACQUISITION, SYSTEM AND COMMUNICATIONS PROTECTION |
| 5.2.1 Ensure GKE clusters are not running using the Compute Engine default service account | CIS Google Kubernetes Engine GKE v1.9.0 L1 GCP | GCP | IDENTIFICATION AND AUTHENTICATION |
| 5.5.3 Ensure Node Auto-Upgrade is Enabled for GKE Nodes | CIS Google Kubernetes Engine GKE v1.9.0 L2 GCP | GCP | RISK ASSESSMENT, SYSTEM AND INFORMATION INTEGRITY |
| 5.7.1 Create administrative boundaries between resources using namespaces | CIS Kubernetes v1.20 Benchmark v1.0.1 L1 Master | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| 5.7.1 Create administrative boundaries between resources using namespaces | CIS Kubernetes v1.24 Benchmark v1.0.0 L1 Master | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| CNTR-K8-000290 - User-managed resources must be created in dedicated namespaces. | DISA Kubernetes STIG v2r6 | Unix | CONFIGURATION MANAGEMENT |
| CNTR-K8-000330 - The Kubernetes Kubelet must have the "readOnlyPort" flag disabled. | DISA Kubernetes STIG v2r6 | Unix | ACCESS CONTROL |
| CNTR-K8-000370 - The Kubernetes Kubelet must have anonymous authentication disabled. | DISA Kubernetes STIG v2r6 | Unix | ACCESS CONTROL |
| CNTR-K8-000410 - Kubernetes Worker Nodes must not have the sshd service enabled. | DISA Kubernetes STIG v2r6 | Unix | ACCESS CONTROL |
| CNTR-K8-000440 - The Kubernetes kubelet staticPodPath must not enable static pods. | DISA Kubernetes STIG v2r6 | Unix | ACCESS CONTROL |
| CNTR-K8-000450 - Kubernetes DynamicAuditing must not be enabled. | DISA Kubernetes STIG v2r6 | Unix | ACCESS CONTROL |
| CNTR-K8-000700 - Kubernetes API Server must generate audit records that identify what type of event has occurred, identify the source of the event, contain the event results, identify any users, and identify any containers associated with the event. | DISA Kubernetes STIG v2r6 | Unix | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY |
| CNTR-K8-000850 - Kubernetes Kubelet must deny hostname override. | DISA Kubernetes STIG v2r6 | Unix | CONFIGURATION MANAGEMENT |
| CNTR-K8-000860 - The Kubernetes manifests must be owned by root. | DISA Kubernetes STIG v2r6 | Unix | CONFIGURATION MANAGEMENT |
| CNTR-K8-000880 - The Kubernetes KubeletConfiguration file must be owned by root. | DISA Kubernetes STIG v2r6 | Unix | CONFIGURATION MANAGEMENT |
| CNTR-K8-000940 - The Kubernetes Controllers must enforce ports, protocols, and services (PPS) that adhere to the Ports, Protocols, and Services Management Category Assurance List (PPSM CAL). | DISA Kubernetes STIG v2r6 | Unix | CONFIGURATION MANAGEMENT |
| CNTR-K8-001160 - Secrets in Kubernetes must not be stored as environment variables. | DISA Kubernetes STIG v2r6 | Unix | IDENTIFICATION AND AUTHENTICATION |
| CNTR-K8-001163 - Kubernetes must limit Secret access on a need-to-know basis. | DISA Kubernetes STIG v2r6 | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| CNTR-K8-001420 - Kubernetes Kubelet must have the SSL Certificate Authority set. | DISA Kubernetes STIG v2r6 | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| CNTR-K8-002000 - The Kubernetes API server must have the ValidatingAdmissionWebhook enabled. | DISA Kubernetes STIG v2r6 | Unix | ACCESS CONTROL |
| CNTR-K8-002001 - Kubernetes must enable PodSecurity admission controller on static pods and Kubelets. | DISA Kubernetes STIG v2r6 | Unix | ACCESS CONTROL |
| CNTR-K8-002700 - Kubernetes must remove old components after updated versions have been installed. | DISA Kubernetes STIG v2r6 | Unix | SYSTEM AND INFORMATION INTEGRITY |
| CNTR-K8-002720 - Kubernetes must contain the latest updates as authorized by IAVMs, CTOs, DTMs, and STIGs. | DISA Kubernetes STIG v2r6 | Unix | SYSTEM AND INFORMATION INTEGRITY |
| CNTR-K8-003160 - The Kubernetes Kubelet certificate authority file must have file permissions set to 644 or more restrictive. | DISA Kubernetes STIG v2r6 | Unix | CONFIGURATION MANAGEMENT |
| CNTR-K8-003180 - The Kubernetes component PKI must be owned by root. | DISA Kubernetes STIG v2r6 | Unix | CONFIGURATION MANAGEMENT |
| CNTR-K8-003260 - The Kubernetes etcd must have file permissions set to 644 or more restrictive. | DISA Kubernetes STIG v2r6 | Unix | CONFIGURATION MANAGEMENT |
| DISA_VMware_vSphere_8.0_vCenter_Appliance_Management_Interface_(VAMI)_STIG_v2r1.audit from DISA VMware vSphere 8.0 vCenter Appliance Management Interface (VAMI) STIG v2r1 | DISA VMware vSphere 8.0 vCenter Appliance Management Interface (VAMI) STIG v2r1 | Unix | |
| F5BI-AP-000231 - The F5 BIG-IP appliance must be configured to deny access when revocation data is unavailable using OCSP. | DISA F5 BIG-IP Access Policy Manager STIG v2r4 | F5 | IDENTIFICATION AND AUTHENTICATION |