STIGQter STIGQter: STIG Summary: Container Platform Security Requirements Guide Version: 1 Release: 1 Benchmark Date: 20 Nov 2020:

Least privilege access and need to know must be required to access the container platform registry.

DISA Rule

SV-233026r599511_rule

Vulnerability Number

V-233026

Group Title

SRG-APP-000033

Rule Version

SRG-APP-000033-CTR-000090

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the container platform to use least privilege and need to know when granting access to the container platform registry. The fix ensures the proper roles and permissions are configured.

Check Contents

Review the container platform configuration to determine if least privilege and need-to-know access is being used for container platform registry access.

If least privilege and need-to-know access is not being used for container platform registry access, this is a finding.

Vulnerability Number

V-233026

Documentable

False

Rule Version

SRG-APP-000033-CTR-000090

Severity Override Guidance

Review the container platform configuration to determine if least privilege and need-to-know access is being used for container platform registry access.

If least privilege and need-to-know access is not being used for container platform registry access, this is a finding.

Check Content Reference

M

Target Key

5239

Comments