| 1.1.1 Ensure that the API server pod specification file permissions are set to 600 or more restrictive | CIS Red Hat OpenShift Container Platform v1.9.0 L1 | OpenShift | ACCESS CONTROL, MEDIA PROTECTION |
| 1.1.3 Ensure that the controller manager pod specification file permissions are set to 600 or more restrictive | CIS Red Hat OpenShift Container Platform v1.9.0 L1 | OpenShift | ACCESS CONTROL, MEDIA PROTECTION |
| 1.1.7 Ensure that the etcd pod specification file permissions are set to 600 or more restrictive | CIS Red Hat OpenShift Container Platform v1.9.0 L1 | OpenShift | ACCESS CONTROL, MEDIA PROTECTION |
| 1.1.8 Ensure that the etcd pod specification file ownership is set to root:root | CIS Red Hat OpenShift Container Platform v1.9.0 L1 | OpenShift | ACCESS CONTROL |
| 1.1.11 Ensure that the etcd data directory permissions are set to 700 or more restrictive | CIS Red Hat OpenShift Container Platform v1.9.0 L1 | OpenShift | ACCESS CONTROL, MEDIA PROTECTION |
| 1.1.12 Ensure that the etcd data directory ownership is set to root:root | CIS Red Hat OpenShift Container Platform v1.9.0 L1 | OpenShift | ACCESS CONTROL |
| 1.1.13 Ensure that the kubeconfig file permissions are set to 600 or more restrictive | CIS Red Hat OpenShift Container Platform v1.9.0 L1 | OpenShift | ACCESS CONTROL, MEDIA PROTECTION |
| 1.1.21 Ensure that the OpenShift PKI key file permissions are set to 600 | CIS Red Hat OpenShift Container Platform v1.9.0 L1 | OpenShift | ACCESS CONTROL, MEDIA PROTECTION |
| 1.2.1 Ensure that anonymous requests are authorized | CIS Red Hat OpenShift Container Platform v1.9.0 L1 | OpenShift | ACCESS CONTROL, MEDIA PROTECTION |
| 1.2.4 Verify that the kubelet certificate authority is set as appropriate | CIS Red Hat OpenShift Container Platform v1.9.0 L1 | OpenShift | SYSTEM AND SERVICES ACQUISITION |
| 1.2.6 Verify that RBAC is enabled | CIS Red Hat OpenShift Container Platform v1.9.0 L1 | OpenShift | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY |
| 1.2.7 Ensure that the APIPriorityAndFairness feature gate is enabled | CIS Red Hat OpenShift Container Platform v1.9.0 L1 | OpenShift | ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION |
| 1.2.8 Ensure that the admission control plugin AlwaysAdmit is not set | CIS Red Hat OpenShift Container Platform v1.9.0 L1 | OpenShift | ACCESS CONTROL, MEDIA PROTECTION |
| 1.2.9 Ensure that the admission control plugin AlwaysPullImages is not set | CIS Red Hat OpenShift Container Platform v1.9.0 L1 | OpenShift | ACCESS CONTROL, MEDIA PROTECTION |
| 1.2.10 Ensure that the admission control plugin ServiceAccount is set | CIS Red Hat OpenShift Container Platform v1.9.0 L1 | OpenShift | ACCESS CONTROL, MEDIA PROTECTION |
| 1.2.12 Ensure that the admission control plugin SecurityContextConstraint is set | CIS Red Hat OpenShift Container Platform v1.9.0 L1 | OpenShift | SYSTEM AND SERVICES ACQUISITION |
| 1.2.15 Ensure that the --insecure-port argument is set to 0 | CIS Red Hat OpenShift Container Platform v1.9.0 L1 | OpenShift | SYSTEM AND SERVICES ACQUISITION |
| 1.2.20 Ensure that the maximumRetainedFiles argument is set to 10 or as appropriate | CIS Red Hat OpenShift Container Platform v1.9.0 L1 | OpenShift | AUDIT AND ACCOUNTABILITY |
| 1.2.21 Configure Kubernetes API Server Maximum Audit Log Size | CIS Red Hat OpenShift Container Platform v1.9.0 L1 | OpenShift | AUDIT AND ACCOUNTABILITY |
| 1.2.25 Ensure that the --etcd-certfile and --etcd-keyfile arguments are set as appropriate | CIS Red Hat OpenShift Container Platform v1.9.0 L1 | OpenShift | IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION |
| 1.2.26 Ensure that the --tls-cert-file and --tls-private-key-file arguments are set as appropriate | CIS Red Hat OpenShift Container Platform v1.9.0 L1 | OpenShift | ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION |
| 1.2.27 Ensure that the --client-ca-file argument is set as appropriate | CIS Red Hat OpenShift Container Platform v1.9.0 L1 | OpenShift | ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION |
| 1.2.29 Ensure that encryption providers are appropriately configured | CIS Red Hat OpenShift Container Platform v1.9.0 L1 | OpenShift | IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION |
| 1.3.3 Ensure that the --service-account-private-key-file argument is set as appropriate | CIS Red Hat OpenShift Container Platform v1.9.0 L1 | OpenShift | IDENTIFICATION AND AUTHENTICATION |
| 1.4.1 Ensure that the healthz endpoints for the scheduler are protected by RBAC | CIS Red Hat OpenShift Container Platform v1.9.0 L1 | OpenShift | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY |
| 2.1 Ensure that the --cert-file and --key-file arguments are set as appropriate | CIS Red Hat OpenShift Container Platform v1.9.0 L1 | OpenShift | IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION |
| 2.7 Ensure that a unique Certificate Authority is used for etcd | CIS Red Hat OpenShift Container Platform v1.9.0 L2 OpenShift | OpenShift | IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION |
| 3.1.1 Client certificate authentication should not be used for users | CIS Red Hat OpenShift Container Platform v1.9.0 L2 OpenShift | OpenShift | CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION |
| 3.2.2 Ensure that the audit policy covers key security concerns | CIS Red Hat OpenShift Container Platform v1.9.0 L2 OpenShift | OpenShift | AUDIT AND ACCOUNTABILITY |
| 4.1.2 Ensure that the kubelet service file ownership is set to root:root | CIS Red Hat OpenShift Container Platform v1.9.0 L1 | OpenShift | ACCESS CONTROL |
| 4.1.5 Ensure that the --kubeconfig kubelet.conf file permissions are set to 644 or more restrictive | CIS Red Hat OpenShift Container Platform v1.9.0 L1 | OpenShift | ACCESS CONTROL, MEDIA PROTECTION |
| 4.1.6 Ensure that the --kubeconfig kubelet.conf file ownership is set to root:root | CIS Red Hat OpenShift Container Platform v1.9.0 L1 | OpenShift | ACCESS CONTROL |
| 4.1.7 Ensure that the certificate authorities file permissions are set to 644 or more restrictive | CIS Red Hat OpenShift Container Platform v1.9.0 L1 | OpenShift | ACCESS CONTROL, MEDIA PROTECTION |
| 4.2.1 Activate Garbage collection in OpenShift Container Platform 4, as appropriate | CIS Red Hat OpenShift Container Platform v1.9.0 L1 | OpenShift | SYSTEM AND INFORMATION INTEGRITY |
| 4.2.8 Ensure that the kubeAPIQPS [--event-qps] argument is set to a level which ensures appropriate event capture | CIS Red Hat OpenShift Container Platform v1.9.0 L2 OpenShift | OpenShift | AUDIT AND ACCOUNTABILITY |
| 4.2.10 Ensure that the --rotate-certificates argument is not set to false | CIS Red Hat OpenShift Container Platform v1.9.0 L2 OpenShift | OpenShift | ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION |
| 4.2.11 Verify that the RotateKubeletServerCertificate argument is set to true | CIS Red Hat OpenShift Container Platform v1.9.0 L2 OpenShift | OpenShift | ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION |
| 4.2.12 Ensure that the Kubelet only makes use of Strong Cryptographic Ciphers | CIS Red Hat OpenShift Container Platform v1.9.0 L1 | OpenShift | IDENTIFICATION AND AUTHENTICATION |
| 5.1.6 Ensure that Service Account Tokens are only mounted where necessary | CIS Red Hat OpenShift Container Platform v1.9.0 L1 | OpenShift | CONFIGURATION MANAGEMENT |
| 5.2.2 Minimize the admission of containers wishing to share the host process ID namespace | CIS Red Hat OpenShift Container Platform v1.9.0 L1 | OpenShift | ACCESS CONTROL |
| 5.2.6 Minimize the admission of root containers | CIS Red Hat OpenShift Container Platform v1.9.0 L2 OpenShift | OpenShift | ACCESS CONTROL, SYSTEM AND INFORMATION INTEGRITY |
| 5.2.9 Minimize the admission of containers with capabilities assigned | CIS Red Hat OpenShift Container Platform v1.9.0 L2 OpenShift | OpenShift | CONFIGURATION MANAGEMENT |
| 5.2.10 Minimize access to privileged Security Context Constraints | CIS Red Hat OpenShift Container Platform v1.9.0 L2 OpenShift | OpenShift | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY |
| 5.3.2 Ensure that all Namespaces have Network Policies defined | CIS Red Hat OpenShift Container Platform v1.9.0 L2 OpenShift | OpenShift | SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION |
| 5.4.1 Prefer using secrets as files over secrets as environment variables | CIS Red Hat OpenShift Container Platform v1.9.0 L2 OpenShift | OpenShift | ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION |
| 5.4.2 Consider external secret storage | CIS Red Hat OpenShift Container Platform v1.9.0 L2 OpenShift | OpenShift | SYSTEM AND COMMUNICATIONS PROTECTION |
| 5.5.1 Configure Image Provenance using image controller configuration parameters | CIS Red Hat OpenShift Container Platform v1.9.0 L2 OpenShift | OpenShift | CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION |
| 5.7.2 Ensure that the seccomp profile is set to docker/default in your pod definitions | CIS Red Hat OpenShift Container Platform v1.9.0 L2 OpenShift | OpenShift | CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION |
| 5.7.3 Apply Security Context to Your Pods and Containers | CIS Red Hat OpenShift Container Platform v1.9.0 L2 OpenShift | OpenShift | RISK ASSESSMENT, SYSTEM AND INFORMATION INTEGRITY |
| 5.7.4 The default namespace should not be used | CIS Red Hat OpenShift Container Platform v1.9.0 L2 OpenShift | OpenShift | SYSTEM AND COMMUNICATIONS PROTECTION |