STIGQter STIGQter: STIG Summary: Container Platform Security Requirements Guide Version: 1 Release: 1 Benchmark Date: 20 Nov 2020:

The container platform registry must contain the latest images with most recent updates and execute within the container platform runtime as authorized by IAVM, CTOs, DTMs, and STIGs.

DISA Rule

SV-233233r599671_rule

Vulnerability Number

V-233233

Group Title

SRG-APP-000456

Rule Version

SRG-APP-000456-CTR-001125

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the container platform registry to use approved vendor repository to ensure latest images containing security-relevant updates are installed.

Check Contents

Review documentation and configuration to determine if the container platform registry inspects and contains approved vendor repository latest images containing security-relevant updates within a timeframe directed by an authoritative source (IAVM, CTOs, DTMs, STIGs, etc.).

If the container platform registry does not contain the latest image with security-relevant updates within the time period directed by the authoritative source, this is a finding.

The container platform registry should help the user understand where the code in the environment was deployed from, and must provide controls that prevent deployment from untrusted sources or registries.

Vulnerability Number

V-233233

Documentable

False

Rule Version

SRG-APP-000456-CTR-001125

Severity Override Guidance

Review documentation and configuration to determine if the container platform registry inspects and contains approved vendor repository latest images containing security-relevant updates within a timeframe directed by an authoritative source (IAVM, CTOs, DTMs, STIGs, etc.).

If the container platform registry does not contain the latest image with security-relevant updates within the time period directed by the authoritative source, this is a finding.

The container platform registry should help the user understand where the code in the environment was deployed from, and must provide controls that prevent deployment from untrusted sources or registries.

Check Content Reference

M

Target Key

5239

Comments