Rancher MCM must allocate audit record storage and generate audit records associated with events, users, and groups.
DISA Rule
SV-252846r960900_rule
Vulnerability Number
V-252846
Group Title
SRG-APP-000098-CTR-000185
Rule Version
CNTR-RM-000250
Severity
CAT II
CCI(s)
- CCI-000133 - Ensure that audit records containing information that establishes the source of the event.
- CCI-000135 - Generate audit records containing the organization-defined additional information that is to be included in the audit records.
- CCI-000172 - Generate audit records for the event types defined in AU-2 c that include the audit record content defined in AU-3.
- CCI-000366 - Implement the security configuration settings.
- CCI-001487 - Ensure that audit records containing information that establishes the identity of any individuals, subjects, or objects/entities associated with the event.
- CCI-001496 - Implement cryptographic mechanisms to protect the integrity of audit tools.
- CCI-001849 - Allocate audit log storage capacity to accommodate organization-defined audit record retention requirements.
- CCI-001855 - Provide a warning to organization-defined personnel, roles, and/or locations within an organization-defined time period when allocated audit log storage volume reaches an organization-defined percentage of repository maximum audit log storage capacity.
- CCI-001858 - Provide an alert in an organization-defined real-time-period to organization-defined personnel, roles, and/or locations when organization-defined audit failure events requiring real-time alerts occur.
- CCI-001876 - Provide an audit reduction capability that supports on-demand reporting requirements.
Weight
10
Fix Recommendation
Enable log aggregation:
Navigate to Triple Bar Symbol(Global).
For each cluster in "EXPLORE CLUSTER":
-Select "Cluster".
-Select "Cluster Tools" (bottom left).
-In the "Logging Block", select "Install".
-Select the newest version of logging in the dropdown.
-Open the "Install into Project Dropdown".
-Select the Project. (Note: Kubernetes STIG requires creating new project and namespace for deployments. Using Default or System is not best practice.)
-Click "Next".
-Review the options and click "Install".
Check Contents
Ensure logging aggregation is enabled:
Navigate to Triple Bar Symbol(Global).
For each cluster in "EXPLORE CLUSTER":
-Select "Cluster".
-Select "Cluster Tools" (bottom left).
This screen shows the current configuration for logging.
OR
Ensure logs are being aggregated and stored in a central logging solution.
If the logging block has an Install button OR logs are not being aggregated in a central logging solution, this is a finding.
Vulnerability Number
V-252846
Documentable
False
Rule Version
CNTR-RM-000250
Severity Override Guidance
Ensure logging aggregation is enabled:
Navigate to Triple Bar Symbol(Global).
For each cluster in "EXPLORE CLUSTER":
-Select "Cluster".
-Select "Cluster Tools" (bottom left).
This screen shows the current configuration for logging.
OR
Ensure logs are being aggregated and stored in a central logging solution.
If the logging block has an Install button OR logs are not being aggregated in a central logging solution, this is a finding.
Check Content Reference
M
Target Key
5467