Ensure that the cluster-admin role is only used where required (Automated)
Quellsprache: Englisch
Menü
Skills in diesem Repository
SkillsMP hat 7.442 Skills aus CyberStrikeus/CyberStrike gesammelt. Öffne einen Skill, um Quelle und Details zu prüfen.
CyberStrikeus/CyberStrikeEs werden 40 von 7.442 gesammelten Skills angezeigt.
Ensure that the cluster-admin role is only used where required (Automated)
Quellsprache: Englisch
Minimize access to secrets (Automated)
Quellsprache: Englisch
Minimize wildcard use in Roles and ClusterRoles (Automated)
Quellsprache: Englisch
Minimize access to create pods (Automated)
Quellsprache: Englisch
Ensure that default service accounts are not actively used (Automated)
Quellsprache: Englisch
Ensure that Service Account Tokens are only mounted where necessary (Automated)
Quellsprache: Englisch
Minimize the admission of privileged containers (Automated)
Quellsprache: Englisch
Minimize the admission of containers wishing to share the host process ID namespace (Automated)
Quellsprache: Englisch
Minimize the admission of containers wishing to share the host IPC namespace (Automated)
Quellsprache: Englisch
Minimize the admission of containers wishing to share the host network namespace (Automated)
Quellsprache: Englisch
Minimize the admission of containers with allowPrivilegeEscalation (Automated)
Quellsprache: Englisch
Ensure latest CNI version is used (Automated)
Quellsprache: Englisch
Ensure that all Namespaces have Network Policies defined (Automated)
Quellsprache: Englisch
Prefer using secrets as files over secrets as environment variables (Automated)
Quellsprache: Englisch
Consider external secret storage (Manual)
Quellsprache: Englisch
Create administrative boundaries between resources using namespaces (Manual)
Quellsprache: Englisch
Apply Security Context to Your Pods and Containers (Manual)
Quellsprache: Englisch
The default namespace should not be used (Automated)
Quellsprache: Englisch
Oracle Cloud Security Penetration and Vulnerability Testing (Manual)
Quellsprache: Englisch
Minimize user access control to Container Engine for Kubernetes (Manual)
Quellsprache: Englisch
Minimize cluster access to read-only (Manual)
Quellsprache: Englisch
Minimize Container Registries to only those approved (Manual)
Quellsprache: Englisch
Prefer using dedicated Service Accounts (Automated)
Quellsprache: Englisch
Encrypting Kubernetes Secrets at Rest in Etcd (Manual)
Quellsprache: Englisch
Restrict Access to the Control Plane Endpoint (Automated)
Quellsprache: Englisch
Ensure clusters created with Private Endpoint Enabled and Public Access Disabled (Automated)
Quellsprache: Englisch
Ensure clusters are created with Private Nodes (Automated)
Quellsprache: Englisch
Ensure Network Policy is Enabled and set as appropriate (Automated)
Quellsprache: Englisch
Encrypt traffic to HTTPS load balancers with TLS certificates (Manual)
Quellsprache: Englisch
Access Control and Container Engine for Kubernetes (Manual)
Quellsprache: Englisch
Client certificate authentication should not be used for users (Manual)
Quellsprache: Englisch
Ensure access to OCI Audit service Log for OKE (Manual)
Quellsprache: Englisch
Ensure that the kubelet-config.json file permissions are set to 644 or more restrictive (Automated)
Quellsprache: Englisch
Ensure that the kubelet-config.json file ownership is set to root:root (Automated)
Quellsprache: Englisch
Ensure that the kubelet configuration file has permissions set to 644 or more restrictive (Automated)
Quellsprache: Englisch
Ensure that the kubelet configuration file ownership is set to root:root (Automated)
Quellsprache: Englisch
Ensure that the --anonymous-auth argument is set to false (Automated)
Quellsprache: Englisch
Ensure that the --rotate-server-certificates argument is set to true (Automated)
Quellsprache: Englisch
Ensure that the --authorization-mode argument is not set to AlwaysAllow (Automated)
Quellsprache: Englisch
Ensure that the --client-ca-file argument is set as appropriate (Automated)
Quellsprache: Englisch