STIGQter STIGQter: STIG Summary: Container Platform Security Requirements Guide Version: 1 Release: 1 Benchmark Date: 20 Nov 2020:

Least privilege access and need to know must be required to access the container platform runtime.

DISA Rule

SV-233027r599509_rule

Vulnerability Number

V-233027

Group Title

SRG-APP-000033

Rule Version

SRG-APP-000033-CTR-000095

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the container platform to use least privilege and need to know when granting access to the container runtime. The fix ensures the proper roles and permissions are configured.

Check Contents

Review the container platform to determine if only those individuals with runtime duties have access to the container platform runtime.

If users have access to the container platform runtime that do not have runtime duties, this is a finding.

Vulnerability Number

V-233027

Documentable

False

Rule Version

SRG-APP-000033-CTR-000095

Severity Override Guidance

Review the container platform to determine if only those individuals with runtime duties have access to the container platform runtime.

If users have access to the container platform runtime that do not have runtime duties, this is a finding.

Check Content Reference

M

Target Key

5239

Comments