SV-253532r960960_rule
V-253532
SRG-APP-000133-CTR-000305
CNTR-PC-000450
CAT I
10
Enable compliance policies.
Navigate to Prisma Cloud Compute Console's Defend >> Compliance and click tab to be edited.
To add rule:
- Click "Add rule."
- Enter rule name.
Scope = All
- Accept the defaults and click "Save".
Click the rule's three-dot menu. Set to "Enable".
Click the rule row.
- Change the policy scope to "All".
- Click "Save".
Verify compliance policies are enabled.
Navigate to Prisma Cloud Compute Console's Defend >> Compliance.
Select the "Code repositories" tab.
Select the "Repositories" and "CI" tab.
- If "Default – alert all components" does not exist, this is a finding.
- Click the three dots in the "Actions" column for rule "Default - alert all components".
- If the policy is disabled, this is a finding.
- Click the "Default – alert all components" policy row.
- If the "Default - alert on critical and high" policy is not scoped to "All", this is a finding.
Select the "Containers and images" tab.
For the "Deployed" and "CI" tab:
- If the "Default - alert on critical and high" does not exist, this is a finding.
- Click the three dots in the "Actions" column for rule "Default - alert on critical and high".
- If the policy is disabled, this is a finding.
- Click the "Default - alert on critical and high" policy row.
- If the "Default - alert on critical and high" policy is not scoped to "All", this is a finding.
Select the "Hosts" tab.
For the "Running hosts" and "VM images" tab:
- If the "Default - alert on critical and high" does not exist, this is a finding.
- Click the three dots in the "Actions" column for rule "Default - alert on critical and high".
- If the policy is disabled, this is a finding.
- Click the "Default - alert on critical and high" policy row.
- If the "Default - alert on critical and high" policy is not scoped to "All", this is a finding.
Select the "Functions" tab.
For the "Functions" and "CI" tab:
- If the "Default – alert all components" does not exist, this is a finding.
- Click the three dots in the "Actions" column for rule "Default -alert all components".
- If the policy is disabled, this is a finding.
- Click the "Default - alert all components" policy row.
- If the "Default - alert on critical and high" policy is not scoped to "All", this is a finding.
V-253532
False
CNTR-PC-000450
Verify compliance policies are enabled.
Navigate to Prisma Cloud Compute Console's Defend >> Compliance.
Select the "Code repositories" tab.
Select the "Repositories" and "CI" tab.
- If "Default – alert all components" does not exist, this is a finding.
- Click the three dots in the "Actions" column for rule "Default - alert all components".
- If the policy is disabled, this is a finding.
- Click the "Default – alert all components" policy row.
- If the "Default - alert on critical and high" policy is not scoped to "All", this is a finding.
Select the "Containers and images" tab.
For the "Deployed" and "CI" tab:
- If the "Default - alert on critical and high" does not exist, this is a finding.
- Click the three dots in the "Actions" column for rule "Default - alert on critical and high".
- If the policy is disabled, this is a finding.
- Click the "Default - alert on critical and high" policy row.
- If the "Default - alert on critical and high" policy is not scoped to "All", this is a finding.
Select the "Hosts" tab.
For the "Running hosts" and "VM images" tab:
- If the "Default - alert on critical and high" does not exist, this is a finding.
- Click the three dots in the "Actions" column for rule "Default - alert on critical and high".
- If the policy is disabled, this is a finding.
- Click the "Default - alert on critical and high" policy row.
- If the "Default - alert on critical and high" policy is not scoped to "All", this is a finding.
Select the "Functions" tab.
For the "Functions" and "CI" tab:
- If the "Default – alert all components" does not exist, this is a finding.
- Click the three dots in the "Actions" column for rule "Default -alert all components".
- If the policy is disabled, this is a finding.
- Click the "Default - alert all components" policy row.
- If the "Default - alert on critical and high" policy is not scoped to "All", this is a finding.
M
5473