Skip to content
Back to skills

Cis Ocp V170 5.2.9

ASecurity

Minimize admission of containers with capabilities assigned (Manual)

  • 2,182 stars
  • 0 votes
  • 0 copies
  • 2 views
  • Added May 30, 2026
securityrustgobashkubernetessecurity

Security analysis

A100/100

Scanned May 30, 2026

npx -y skills add CyberStrikeus/CyberStrike --skill cis-ocp-v170-5.2.9 --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Cis Ocp V170 5.2.9?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Cis Ocp V170 5.2.9
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/cyberstrikeus-cis-ocp-v170-5-2-9/badge)](https://www.skillsdirectory.com/skills/cyberstrikeus-cis-ocp-v170-5-2-9)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: cis-ocp-v170-5.2.9
description: "Minimize admission of containers with capabilities assigned (Manual)"
category: cis-openshift
version: "1.7.0"
author: cyberstrike-official
tags: [cis, openshift, kubernetes, redhat, policies, security-context-constraints]
cis_id: "5.2.9"
cis_benchmark: "CIS Red Hat OpenShift Container Platform Benchmark v1.7.0"
tech_stack: [kubernetes, openshift, redhat]
cwe_ids: []
chains_with: []
prerequisites: []
severity_boost: {}
---

# CIS Red Hat OpenShift Container Platform Benchmark v1.7.0 - Control 5.2.9

## Profile Applicability

- **Level:** 2

## Description

Do not generally permit containers with capabilities.

## Rationale

Containers run with a default set of capabilities as assigned by the Container Runtime. Capabilities are parts of the rights generally granted on a Linux system to the root user.

In many cases applications running in containers do not require any capabilities to operate, so from the perspective of the principal of least privilege use of capabilities should be minimized.

## Impact

Pods with containers which require capabilities to operate will not be permitted.

## Audit Procedure

Use the following command to list SCCs that drop all capabilities from containers:

```bash
oc get scc -A -o json | jq '.items[] |
select(.requiredDropCapabilities[]?|any(. == "ALL"; .)) | .metadata.name'
```

Verify at least one SCC is returned.

## Remediation

Review the use of capabilities in applications running on your cluster. Where a namespace contains applications which do not require any Linux capabilities to operate, consider adding a SCC which forbids the admission of containers which do not drop all capabilities.

## Default Value

By default, OpenShift includes three SCCs that drop all container capabilities:

```
"hostnetwork-v2"
"nonroot-v2"
"restricted-v2"
```

## References

1. https://docs.openshift.com/container-platform/latest/authentication/managing-security-context-constraints.html
2. https://kubernetes.io/docs/concepts/policy/pod-security-policy/#enabling-pod-security-policies
3. https://www.nccgroup.trust/uk/our-research/abusing-privileged-and-unprivileged-linux-containers/

## CIS Controls

| Controls Version | Control                                                                         | IG 1 | IG 2 | IG 3 |
| ---------------- | ------------------------------------------------------------------------------- | ---- | ---- | ---- |
| v8               | 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software |      | \*   | \*   |
| v7               | 5.2 Maintain Secure Images                                                      |      | \*   | \*   |

## MITRE ATT&CK Mappings

| Techniques / Sub-techniques | Tactics        | Mitigations  |
| --------------------------- | -------------- | ------------ |
| T1204                       | TA0002, TA0003 | M1045, M1047 |

## Profile

**Level 2** (Manual)

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…