SV-253524r1137640_rule
V-253524
SRG-APP-000033-CTR-000100
CNTR-PC-000120
CAT II
10
Navigate to Prisma Cloud Compute Console's >> Manage >> Authentication >> Users tab.
- Set the users' role assignments to the ones who have the authority to review the audit data.
- Assign roles to all users and groups.
- Assign administrator and operator roles only to the users requiring the rights to modify the Prisma Cloud Compute's Credential Store.
- Remove the Administrator or Operator role for users who do not require access.
Navigate to Prisma Cloud Compute Console's >> Manage >> Authentication >> Groups tab.
- Set the groups' role assignments to the ones who have the authority to review audit data.
- Assign roles to all users and groups.
- Set the groups' Administrator and Operator role assignments to only to the groups requiring the rights to modify the Prisma Cloud Compute's Credential Store.
Adjust user, group, and Collection assignments to align with organizational policies.
Navigate to Prisma Cloud Compute Console's >> Manage >> Authentication >> Users tab.
Inspect the users' role assignments:
- Review role assigned to users. If role and/or the Collection assignment is incorrect, this is a finding.
- If a user is not assigned a role, this is a finding.
- Review users assigned the administrator role. If a user has the administrator role and does not require access, this is a finding.
Navigate to Prisma Cloud Compute Console's >> Manage >> Authentication >> Groups tab.
(Only the Administrator, Operator Prisma Cloud Compute roles have the ability to create/modify policy that could affect runtime behaviors.)
Inspect the groups' role assignments:
- If any users or groups are assigned the Auditor or higher role and do not require access to audit information, this is a finding.
- If a group is not assigned a role, this is a finding.
- If role and/or Collection assignment is incorrect, this is a finding.
- Review groups assigned the Administrator or Operator role. If a group has the Administrator or Operator role and does not require access to Prisma Cloud Compute's Credential Store, this is a finding.
V-253524
False
CNTR-PC-000120
Navigate to Prisma Cloud Compute Console's >> Manage >> Authentication >> Users tab.
Inspect the users' role assignments:
- Review role assigned to users. If role and/or the Collection assignment is incorrect, this is a finding.
- If a user is not assigned a role, this is a finding.
- Review users assigned the administrator role. If a user has the administrator role and does not require access, this is a finding.
Navigate to Prisma Cloud Compute Console's >> Manage >> Authentication >> Groups tab.
(Only the Administrator, Operator Prisma Cloud Compute roles have the ability to create/modify policy that could affect runtime behaviors.)
Inspect the groups' role assignments:
- If any users or groups are assigned the Auditor or higher role and do not require access to audit information, this is a finding.
- If a group is not assigned a role, this is a finding.
- If role and/or Collection assignment is incorrect, this is a finding.
- Review groups assigned the Administrator or Operator role. If a group has the Administrator or Operator role and does not require access to Prisma Cloud Compute's Credential Store, this is a finding.
M
5473