| CNTR-K8-000150 - The Kubernetes Controller Manager must use TLS 1.2, at a minimum, to protect the confidentiality of sensitive data during electronic dissemination. | DISA Kubernetes STIG v2r6 | Unix | ACCESS CONTROL |
| CNTR-K8-000180 - The Kubernetes etcd must use TLS to protect the confidentiality of sensitive data during electronic dissemination. | DISA Kubernetes STIG v2r6 | Unix | ACCESS CONTROL |
| CNTR-K8-000190 - The Kubernetes etcd must use TLS to protect the confidentiality of sensitive data during electronic dissemination. | DISA Kubernetes STIG v2r6 | Unix | ACCESS CONTROL |
| CNTR-K8-000220 - The Kubernetes Controller Manager must create unique service accounts for each work payload. | DISA Kubernetes STIG v2r6 | Unix | ACCESS CONTROL |
| CNTR-K8-000270 - The Kubernetes API Server must enable Node,RBAC as the authorization mode. | DISA Kubernetes STIG v2r6 | Unix | ACCESS CONTROL |
| CNTR-K8-000290 - User-managed resources must be created in dedicated namespaces. | DISA Kubernetes STIG v2r6 | Unix | CONFIGURATION MANAGEMENT |
| CNTR-K8-000300 - The Kubernetes Scheduler must have secure binding. | DISA Kubernetes STIG v2r6 | Unix | ACCESS CONTROL |
| CNTR-K8-000330 - The Kubernetes Kubelet must have the "readOnlyPort" flag disabled. | DISA Kubernetes STIG v2r6 | Unix | ACCESS CONTROL |
| CNTR-K8-000370 - The Kubernetes Kubelet must have anonymous authentication disabled. | DISA Kubernetes STIG v2r6 | Unix | ACCESS CONTROL |
| CNTR-K8-000410 - Kubernetes Worker Nodes must not have the sshd service enabled. | DISA Kubernetes STIG v2r6 | Unix | ACCESS CONTROL |
| CNTR-K8-000420 - Kubernetes dashboard must not be enabled. | DISA Kubernetes STIG v2r6 | Unix | ACCESS CONTROL |
| CNTR-K8-000440 - The Kubernetes kubelet staticPodPath must not enable static pods. | DISA Kubernetes STIG v2r6 | Unix | ACCESS CONTROL |
| CNTR-K8-000450 - Kubernetes DynamicAuditing must not be enabled. | DISA Kubernetes STIG v2r6 | Unix | ACCESS CONTROL |
| CNTR-K8-000460 - Kubernetes DynamicKubeletConfig must not be enabled. | DISA Kubernetes STIG v2r6 | Unix | ACCESS CONTROL |
| CNTR-K8-000470 - The Kubernetes API server must have Alpha APIs disabled. | DISA Kubernetes STIG v2r6 | Unix | ACCESS CONTROL |
| CNTR-K8-000610 - The Kubernetes API Server must have an audit log path set. | DISA Kubernetes STIG v2r6 | Unix | AUDIT AND ACCOUNTABILITY |
| CNTR-K8-000700 - Kubernetes API Server must generate audit records that identify what type of event has occurred, identify the source of the event, contain the event results, identify any users, and identify any containers associated with the event. | DISA Kubernetes STIG v2r6 | Unix | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY |
| CNTR-K8-000850 - Kubernetes Kubelet must deny hostname override. | DISA Kubernetes STIG v2r6 | Unix | CONFIGURATION MANAGEMENT |
| CNTR-K8-000880 - The Kubernetes KubeletConfiguration file must be owned by root. | DISA Kubernetes STIG v2r6 | Unix | CONFIGURATION MANAGEMENT |
| CNTR-K8-000890 - The Kubernetes KubeletConfiguration files must have file permissions set to 644 or more restrictive. | DISA Kubernetes STIG v2r6 | Unix | CONFIGURATION MANAGEMENT |
| CNTR-K8-000900 - The Kubernetes manifest files must have least privileges. | DISA Kubernetes STIG v2r6 | Unix | CONFIGURATION MANAGEMENT |
| CNTR-K8-000920 - The Kubernetes API Server must enforce ports, protocols, and services (PPS) that adhere to the Ports, Protocols, and Services Management Category Assurance List (PPSM CAL). | DISA Kubernetes STIG v2r6 | Unix | CONFIGURATION MANAGEMENT |
| CNTR-K8-000930 - The Kubernetes Scheduler must enforce ports, protocols, and services (PPS) that adhere to the Ports, Protocols, and Services Management Category Assurance List (PPSM CAL). | DISA Kubernetes STIG v2r6 | Unix | CONFIGURATION MANAGEMENT |
| CNTR-K8-000950 - The Kubernetes etcd must enforce ports, protocols, and services (PPS) that adhere to the Ports, Protocols, and Services Management Category Assurance List (PPSM CAL). | DISA Kubernetes STIG v2r6 | Unix | CONFIGURATION MANAGEMENT |
| CNTR-K8-000960 - The Kubernetes cluster must use non-privileged host ports for user pods. | DISA Kubernetes STIG v2r6 | Unix | CONFIGURATION MANAGEMENT |
| CNTR-K8-001160 - Secrets in Kubernetes must not be stored as environment variables. | DISA Kubernetes STIG v2r6 | Unix | IDENTIFICATION AND AUTHENTICATION |
| CNTR-K8-001161 - Sensitive information must be stored using Kubernetes Secrets or an external Secret store provider. | DISA Kubernetes STIG v2r6 | Unix | IDENTIFICATION AND AUTHENTICATION |
| CNTR-K8-001360 - Kubernetes must separate user functionality. | DISA Kubernetes STIG v2r6 | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| CNTR-K8-001410 - Kubernetes API Server must have the SSL Certificate Authority set. | DISA Kubernetes STIG v2r6 | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| CNTR-K8-001420 - Kubernetes Kubelet must have the SSL Certificate Authority set. | DISA Kubernetes STIG v2r6 | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| CNTR-K8-001450 - Kubernetes etcd must enable client authentication to secure service. | DISA Kubernetes STIG v2r6 | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| CNTR-K8-001490 - Kubernetes etcd must have a key file for secure communication. | DISA Kubernetes STIG v2r6 | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| CNTR-K8-001510 - Kubernetes etcd must have the SSL Certificate Authority set. | DISA Kubernetes STIG v2r6 | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| CNTR-K8-001520 - Kubernetes etcd must have a certificate for communication. | DISA Kubernetes STIG v2r6 | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| CNTR-K8-002000 - The Kubernetes API server must have the ValidatingAdmissionWebhook enabled. | DISA Kubernetes STIG v2r6 | Unix | ACCESS CONTROL |
| CNTR-K8-002001 - Kubernetes must enable PodSecurity admission controller on static pods and Kubelets. | DISA Kubernetes STIG v2r6 | Unix | ACCESS CONTROL |
| CNTR-K8-002011 - Kubernetes must have a Pod Security Admission control file configured. | DISA Kubernetes STIG v2r6 | Unix | ACCESS CONTROL |
| CNTR-K8-002620 - Kubernetes API Server must disable basic authentication to protect information in transit. | DISA Kubernetes STIG v2r6 | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| CNTR-K8-002700 - Kubernetes must remove old components after updated versions have been installed. | DISA Kubernetes STIG v2r6 | Unix | SYSTEM AND INFORMATION INTEGRITY |
| CNTR-K8-002720 - Kubernetes must contain the latest updates as authorized by IAVMs, CTOs, DTMs, and STIGs. | DISA Kubernetes STIG v2r6 | Unix | SYSTEM AND INFORMATION INTEGRITY |
| CNTR-K8-003150 - The Kubernetes Kube Proxy kubeconfig must be owned by root. | DISA Kubernetes STIG v2r6 | Unix | CONFIGURATION MANAGEMENT |
| CNTR-K8-003180 - The Kubernetes component PKI must be owned by root. | DISA Kubernetes STIG v2r6 | Unix | CONFIGURATION MANAGEMENT |
| CNTR-K8-003190 - The Kubernetes kubelet KubeConfig must have file permissions set to 644 or more restrictive. | DISA Kubernetes STIG v2r6 | Unix | CONFIGURATION MANAGEMENT |
| CNTR-K8-003230 - The Kubernetes kubelet config must have file permissions set to 644 or more restrictive. | DISA Kubernetes STIG v2r6 | Unix | CONFIGURATION MANAGEMENT |
| CNTR-K8-003260 - The Kubernetes etcd must have file permissions set to 644 or more restrictive. | DISA Kubernetes STIG v2r6 | Unix | CONFIGURATION MANAGEMENT |
| CNTR-K8-003290 - The Kubernetes API Server must be set to audit log max size. | DISA Kubernetes STIG v2r6 | Unix | CONFIGURATION MANAGEMENT |
| CNTR-K8-003310 - The Kubernetes API Server audit log retention must be set. | DISA Kubernetes STIG v2r6 | Unix | CONFIGURATION MANAGEMENT |
| DTOO262 - Run in FIPS compliant mode must be enforced. | DISA STIG Microsoft Outlook 2013 v1r14 | Windows | IDENTIFICATION AND AUTHENTICATION |
| MOTS-11-010200 - Motorola Solutions Android 11 must be configured to disallow configuration of date and time. | AirWatch - DISA Motorola Solutions Android 11 COBO v1r3 | MDM | CONFIGURATION MANAGEMENT |
| MOTS-11-010200 - Motorola Solutions Android 11 must be configured to disallow configuration of date and time. | MobileIron - DISA Motorola Solutions Android 11 COBO v1r3 | MDM | CONFIGURATION MANAGEMENT |