Item Search

NameAudit NamePluginCategory
CNTR-K8-000150 - The Kubernetes Controller Manager must use TLS 1.2, at a minimum, to protect the confidentiality of sensitive data during electronic dissemination.DISA Kubernetes STIG v2r6Unix

ACCESS CONTROL

CNTR-K8-000180 - The Kubernetes etcd must use TLS to protect the confidentiality of sensitive data during electronic dissemination.DISA Kubernetes STIG v2r6Unix

ACCESS CONTROL

CNTR-K8-000190 - The Kubernetes etcd must use TLS to protect the confidentiality of sensitive data during electronic dissemination.DISA Kubernetes STIG v2r6Unix

ACCESS CONTROL

CNTR-K8-000220 - The Kubernetes Controller Manager must create unique service accounts for each work payload.DISA Kubernetes STIG v2r6Unix

ACCESS CONTROL

CNTR-K8-000270 - The Kubernetes API Server must enable Node,RBAC as the authorization mode.DISA Kubernetes STIG v2r6Unix

ACCESS CONTROL

CNTR-K8-000290 - User-managed resources must be created in dedicated namespaces.DISA Kubernetes STIG v2r6Unix

CONFIGURATION MANAGEMENT

CNTR-K8-000300 - The Kubernetes Scheduler must have secure binding.DISA Kubernetes STIG v2r6Unix

ACCESS CONTROL

CNTR-K8-000330 - The Kubernetes Kubelet must have the "readOnlyPort" flag disabled.DISA Kubernetes STIG v2r6Unix

ACCESS CONTROL

CNTR-K8-000370 - The Kubernetes Kubelet must have anonymous authentication disabled.DISA Kubernetes STIG v2r6Unix

ACCESS CONTROL

CNTR-K8-000410 - Kubernetes Worker Nodes must not have the sshd service enabled.DISA Kubernetes STIG v2r6Unix

ACCESS CONTROL

CNTR-K8-000420 - Kubernetes dashboard must not be enabled.DISA Kubernetes STIG v2r6Unix

ACCESS CONTROL

CNTR-K8-000440 - The Kubernetes kubelet staticPodPath must not enable static pods.DISA Kubernetes STIG v2r6Unix

ACCESS CONTROL

CNTR-K8-000450 - Kubernetes DynamicAuditing must not be enabled.DISA Kubernetes STIG v2r6Unix

ACCESS CONTROL

CNTR-K8-000460 - Kubernetes DynamicKubeletConfig must not be enabled.DISA Kubernetes STIG v2r6Unix

ACCESS CONTROL

CNTR-K8-000470 - The Kubernetes API server must have Alpha APIs disabled.DISA Kubernetes STIG v2r6Unix

ACCESS CONTROL

CNTR-K8-000610 - The Kubernetes API Server must have an audit log path set.DISA Kubernetes STIG v2r6Unix

AUDIT AND ACCOUNTABILITY

CNTR-K8-000700 - Kubernetes API Server must generate audit records that identify what type of event has occurred, identify the source of the event, contain the event results, identify any users, and identify any containers associated with the event.DISA Kubernetes STIG v2r6Unix

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

CNTR-K8-000850 - Kubernetes Kubelet must deny hostname override.DISA Kubernetes STIG v2r6Unix

CONFIGURATION MANAGEMENT

CNTR-K8-000880 - The Kubernetes KubeletConfiguration file must be owned by root.DISA Kubernetes STIG v2r6Unix

CONFIGURATION MANAGEMENT

CNTR-K8-000890 - The Kubernetes KubeletConfiguration files must have file permissions set to 644 or more restrictive.DISA Kubernetes STIG v2r6Unix

CONFIGURATION MANAGEMENT

CNTR-K8-000900 - The Kubernetes manifest files must have least privileges.DISA Kubernetes STIG v2r6Unix

CONFIGURATION MANAGEMENT

CNTR-K8-000920 - The Kubernetes API Server must enforce ports, protocols, and services (PPS) that adhere to the Ports, Protocols, and Services Management Category Assurance List (PPSM CAL).DISA Kubernetes STIG v2r6Unix

CONFIGURATION MANAGEMENT

CNTR-K8-000930 - The Kubernetes Scheduler must enforce ports, protocols, and services (PPS) that adhere to the Ports, Protocols, and Services Management Category Assurance List (PPSM CAL).DISA Kubernetes STIG v2r6Unix

CONFIGURATION MANAGEMENT

CNTR-K8-000950 - The Kubernetes etcd must enforce ports, protocols, and services (PPS) that adhere to the Ports, Protocols, and Services Management Category Assurance List (PPSM CAL).DISA Kubernetes STIG v2r6Unix

CONFIGURATION MANAGEMENT

CNTR-K8-000960 - The Kubernetes cluster must use non-privileged host ports for user pods.DISA Kubernetes STIG v2r6Unix

CONFIGURATION MANAGEMENT

CNTR-K8-001160 - Secrets in Kubernetes must not be stored as environment variables.DISA Kubernetes STIG v2r6Unix

IDENTIFICATION AND AUTHENTICATION

CNTR-K8-001161 - Sensitive information must be stored using Kubernetes Secrets or an external Secret store provider.DISA Kubernetes STIG v2r6Unix

IDENTIFICATION AND AUTHENTICATION

CNTR-K8-001360 - Kubernetes must separate user functionality.DISA Kubernetes STIG v2r6Unix

SYSTEM AND COMMUNICATIONS PROTECTION

CNTR-K8-001410 - Kubernetes API Server must have the SSL Certificate Authority set.DISA Kubernetes STIG v2r6Unix

SYSTEM AND COMMUNICATIONS PROTECTION

CNTR-K8-001420 - Kubernetes Kubelet must have the SSL Certificate Authority set.DISA Kubernetes STIG v2r6Unix

SYSTEM AND COMMUNICATIONS PROTECTION

CNTR-K8-001450 - Kubernetes etcd must enable client authentication to secure service.DISA Kubernetes STIG v2r6Unix

SYSTEM AND COMMUNICATIONS PROTECTION

CNTR-K8-001490 - Kubernetes etcd must have a key file for secure communication.DISA Kubernetes STIG v2r6Unix

SYSTEM AND COMMUNICATIONS PROTECTION

CNTR-K8-001510 - Kubernetes etcd must have the SSL Certificate Authority set.DISA Kubernetes STIG v2r6Unix

SYSTEM AND COMMUNICATIONS PROTECTION

CNTR-K8-001520 - Kubernetes etcd must have a certificate for communication.DISA Kubernetes STIG v2r6Unix

SYSTEM AND COMMUNICATIONS PROTECTION

CNTR-K8-002000 - The Kubernetes API server must have the ValidatingAdmissionWebhook enabled.DISA Kubernetes STIG v2r6Unix

ACCESS CONTROL

CNTR-K8-002001 - Kubernetes must enable PodSecurity admission controller on static pods and Kubelets.DISA Kubernetes STIG v2r6Unix

ACCESS CONTROL

CNTR-K8-002011 - Kubernetes must have a Pod Security Admission control file configured.DISA Kubernetes STIG v2r6Unix

ACCESS CONTROL

CNTR-K8-002620 - Kubernetes API Server must disable basic authentication to protect information in transit.DISA Kubernetes STIG v2r6Unix

SYSTEM AND COMMUNICATIONS PROTECTION

CNTR-K8-002700 - Kubernetes must remove old components after updated versions have been installed.DISA Kubernetes STIG v2r6Unix

SYSTEM AND INFORMATION INTEGRITY

CNTR-K8-002720 - Kubernetes must contain the latest updates as authorized by IAVMs, CTOs, DTMs, and STIGs.DISA Kubernetes STIG v2r6Unix

SYSTEM AND INFORMATION INTEGRITY

CNTR-K8-003150 - The Kubernetes Kube Proxy kubeconfig must be owned by root.DISA Kubernetes STIG v2r6Unix

CONFIGURATION MANAGEMENT

CNTR-K8-003180 - The Kubernetes component PKI must be owned by root.DISA Kubernetes STIG v2r6Unix

CONFIGURATION MANAGEMENT

CNTR-K8-003190 - The Kubernetes kubelet KubeConfig must have file permissions set to 644 or more restrictive.DISA Kubernetes STIG v2r6Unix

CONFIGURATION MANAGEMENT

CNTR-K8-003230 - The Kubernetes kubelet config must have file permissions set to 644 or more restrictive.DISA Kubernetes STIG v2r6Unix

CONFIGURATION MANAGEMENT

CNTR-K8-003260 - The Kubernetes etcd must have file permissions set to 644 or more restrictive.DISA Kubernetes STIG v2r6Unix

CONFIGURATION MANAGEMENT

CNTR-K8-003290 - The Kubernetes API Server must be set to audit log max size.DISA Kubernetes STIG v2r6Unix

CONFIGURATION MANAGEMENT

CNTR-K8-003310 - The Kubernetes API Server audit log retention must be set.DISA Kubernetes STIG v2r6Unix

CONFIGURATION MANAGEMENT

DTOO262 - Run in FIPS compliant mode must be enforced.DISA STIG Microsoft Outlook 2013 v1r14Windows

IDENTIFICATION AND AUTHENTICATION

MOTS-11-010200 - Motorola Solutions Android 11 must be configured to disallow configuration of date and time.AirWatch - DISA Motorola Solutions Android 11 COBO v1r3MDM

CONFIGURATION MANAGEMENT

MOTS-11-010200 - Motorola Solutions Android 11 must be configured to disallow configuration of date and time.MobileIron - DISA Motorola Solutions Android 11 COBO v1r3MDM

CONFIGURATION MANAGEMENT