Rancher MCM must generate audit records for all DoD-defined auditable events within all components in the platform.
DISA Rule
SV-252844r960777_rule
Vulnerability Number
V-252844
Group Title
SRG-APP-000026-CTR-000070
Rule Version
CNTR-RM-000060
Severity
CAT II
CCI(s)
- CCI-000018 - Automatically audit account creation actions.
- CCI-000130 - Ensure that audit records containing information that establishes what type of event occurred.
- CCI-000131 - Ensure that audit records containing information that establishes when the event occurred.
- CCI-000140 - Take organization-defined actions upon audit failure include, shutting down the system, overwriting oldest audit records, and stopping the generation of audit records.
- CCI-000169 - Provide audit record generation capability for the event types the system is capable of auditing as defined in AU-2 a. on organization-defined information system components.
- CCI-000171 - Allow organization-defined personnel or roles to select the event types that are to be logged by specific components of the system.
- CCI-000172 - Generate audit records for the event types defined in AU-2 c that include the audit record content defined in AU-3.
- CCI-000213 - Enforce approved authorizations for logical access to information and system resources in accordance with applicable access control policies.
- CCI-001464 - Initiates session audits automatically at system start-up.
- CCI-001851 - Transfer audit logs per organization-defined frequency to a different system, system component, or media than the system or system component conducting the logging.
- CCI-001889 - Record time stamps for audit records that meet organization-defined granularity of time measurement.
- CCI-001890 - Record time stamps for audit records that use Coordinated Universal Time, have a fixed local time offset from Coordinated Universal Time, or that include the local time offset as part of the time stamp.
- CCI-002234 - Log the execution of privileged functions.
Weight
10
Fix Recommendation
Ensure audit logging is enabled:
Navigate to Triple Bar Symbol(Global) >> <local cluster>
-From the drop down next to the cluster name, select 'cattle-system'.
-Click "deployments" under Workload menu item.
-Select "rancher" in the Deployments section.
-Click the three dot config menu on the right.
-Choose "Edit Config".
-Scroll down to the "Environment Variables" section.
-Change the AUDIT_LEVEL value to "2" or "3" and then click "Save".
If the variable does not exist:
-Click "Add Variable".
-Keep Default key/Value Pair as "Type"
-Add "AUDIT_LEVEL" as Variable Name.
-Input "2,3" for a value.
-Click "Save".
Check Contents
Ensure audit logging is enabled:
Navigate to Triple Bar Symbol(Global) >> <local cluster>
-From the drop down next to the cluster name, select "cattle-system".
-Click "deployments" under Workload menu item.
-Select "rancher" in the Deployments section.
-Click the three dot config menu on the right.
-Choose "Edit Config".
-Scroll down to the "Environment Variables" section.
If the 'AUDIT_LEVEL' environment variable does not exist or < Level 2, this is a finding.
Vulnerability Number
V-252844
Documentable
False
Rule Version
CNTR-RM-000060
Severity Override Guidance
Ensure audit logging is enabled:
Navigate to Triple Bar Symbol(Global) >> <local cluster>
-From the drop down next to the cluster name, select "cattle-system".
-Click "deployments" under Workload menu item.
-Select "rancher" in the Deployments section.
-Click the three dot config menu on the right.
-Choose "Edit Config".
-Scroll down to the "Environment Variables" section.
If the 'AUDIT_LEVEL' environment variable does not exist or < Level 2, this is a finding.
Check Content Reference
M
Target Key
5467