STIGQter STIGQter: STIG Summary: Docker Enterprise 2.x Linux/UNIX Security Technical Implementation Guide Version: 2 Release: 1 Benchmark Date: 23 Apr 2021:

Log aggregation/SIEM systems must be configured to notify SA and ISSO on Docker Engine - Enterprise audit failure events.

DISA Rule

SV-235835r627632_rule

Vulnerability Number

V-235835

Group Title

SRG-APP-000360

Rule Version

DKER-EE-003340

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Work with the SIEM administrator to create an alert to notify the SA and ISSO when audit failure events occur.

Check Contents

Work with the SIEM administrator to determine if an alert is configured to notify the SA and ISSO when audit failure events occur.

If there is no alert configured, this is a finding.

Vulnerability Number

V-235835

Documentable

False

Rule Version

DKER-EE-003340

Severity Override Guidance

Work with the SIEM administrator to determine if an alert is configured to notify the SA and ISSO when audit failure events occur.

If there is no alert configured, this is a finding.

Check Content Reference

M

Target Key

5281

Comments