STIGQter STIGQter: STIG Summary: Container Platform Security Requirements Guide Version: 2 Release: 4 Benchmark Date: 28 Oct 2025:

The container platform runtime must have security-relevant software updates installed within 30 days unless the time period is directed by an authoritative source (e.g., IAVM, CTOs, DTMs, and STIGs).

DISA Rule

SV-233234r1137650_rule

Vulnerability Number

V-233234

Group Title

SRG-APP-000456

Rule Version

SRG-APP-000456-CTR-001130

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the container platform registry to use an approved vendor repository to ensure the latest images containing security-relevant updates are installed within 30 days unless the time period is directed by an authoritative source (e.g., IAVM, CTOs, DTMs, and STIGs).

Check Contents

Review documentation and configuration to determine if the container platform registry inspects and contains the latest approved vendor repository images containing security-relevant updates within 30 days unless the time period is directed by an authoritative source (e.g., IAVM, CTOs, DTMs, and STIGs).

If the container platform registry does not contain the latest image with security-relevant updates within 30 days unless the time period is directed by an authoritative source (e.g., IAVM, CTOs, DTMs, and STIGs), this is a finding.

The container platform registry should help the user understand from where the code in the environment was deployed and must provide controls that prevent deployment from untrusted sources or registries.

Vulnerability Number

V-233234

Documentable

False

Rule Version

SRG-APP-000456-CTR-001130

Severity Override Guidance

Review documentation and configuration to determine if the container platform registry inspects and contains the latest approved vendor repository images containing security-relevant updates within 30 days unless the time period is directed by an authoritative source (e.g., IAVM, CTOs, DTMs, and STIGs).

If the container platform registry does not contain the latest image with security-relevant updates within 30 days unless the time period is directed by an authoritative source (e.g., IAVM, CTOs, DTMs, and STIGs), this is a finding.

The container platform registry should help the user understand from where the code in the environment was deployed and must provide controls that prevent deployment from untrusted sources or registries.

Check Content Reference

M

Target Key

5239