STIGQter STIGQter: STIG Summary: Container Platform Security Requirements Guide Version: 1 Release: 1 Benchmark Date: 20 Nov 2020:

Least privilege access and need to know must be required to access the container platform keystore.

DISA Rule

SV-233028r599509_rule

Vulnerability Number

V-233028

Group Title

SRG-APP-000033

Rule Version

SRG-APP-000033-CTR-000100

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the container platform to use least privilege and need to know when granting access to the container keystore. The fix ensures the proper roles and permissions are configured.

Check Contents

Review the container platform to determine if only those individuals with keystore duties have access to the container platform keystore.

If users have access to the container platform keystore that do not have keystore duties, this is a finding.

Vulnerability Number

V-233028

Documentable

False

Rule Version

SRG-APP-000033-CTR-000100

Severity Override Guidance

Review the container platform to determine if only those individuals with keystore duties have access to the container platform keystore.

If users have access to the container platform keystore that do not have keystore duties, this is a finding.

Check Content Reference

M

Target Key

5239

Comments