STIGQter STIGQter: STIG Summary: Container Platform Security Requirements Guide Version: 1 Release: 1 Benchmark Date: 20 Nov 2020:

The container platform must generate audit records containing the full-text recording of privileged commands or the individual identities of group account users.

DISA Rule

SV-233049r599543_rule

Vulnerability Number

V-233049

Group Title

SRG-APP-000101

Rule Version

SRG-APP-000101-CTR-000205

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the container platform to generate the full-text recording of privileged commands, or the individual identities of group users, or both.

Check Contents

Review the documentation and deployment configuration to determine if the container platform is configured to generate full-text recording of privileged commands or the individual identities of group users at a minimum.

Have a user execute a privileged command and review the log data to validate that the full-text or identity of the individual is being logged.

If the container platform is not meeting this requirement, this is a finding.

Vulnerability Number

V-233049

Documentable

False

Rule Version

SRG-APP-000101-CTR-000205

Severity Override Guidance

Review the documentation and deployment configuration to determine if the container platform is configured to generate full-text recording of privileged commands or the individual identities of group users at a minimum.

Have a user execute a privileged command and review the log data to validate that the full-text or identity of the individual is being logged.

If the container platform is not meeting this requirement, this is a finding.

Check Content Reference

M

Target Key

5239

Comments