SV-233231r599707_rule
V-233231
SRG-APP-000454
SRG-APP-000454-CTR-001115
CAT II
10
Configure the container platform registry to update organization-defined images with current approved vendor version and remove obsolete images after updated versions have been installed. Configure the container platform runtime to execute latest organization-defined images from the container platform registry.
Review container platform registry documentation and configuration to determine if organization-defined images contains latest approved vendor software image version.
If organization-defined images do not contain the latest approved vendor software image version, this is a finding.
Review container platform registry documentation and configuration to determine if organization-defined images are removed after updated versions have been installed.
If organization-defined images are not removed after updated versions have been installed, this is a finding.
Review container platform runtime documentation and configuration to determine if organization-defined images are executing latest image version from the container registry.
If container platform runtime is not executing latest organization-defined images from the container platform registry, this is a finding.
V-233231
False
SRG-APP-000454-CTR-001115
Review container platform registry documentation and configuration to determine if organization-defined images contains latest approved vendor software image version.
If organization-defined images do not contain the latest approved vendor software image version, this is a finding.
Review container platform registry documentation and configuration to determine if organization-defined images are removed after updated versions have been installed.
If organization-defined images are not removed after updated versions have been installed, this is a finding.
Review container platform runtime documentation and configuration to determine if organization-defined images are executing latest image version from the container registry.
If container platform runtime is not executing latest organization-defined images from the container platform registry, this is a finding.
M
5239