STIGQter STIGQter: STIG Summary: Palo Alto Networks Prisma Cloud Compute Security Technical Implementation Guide Version: 2 Release: 3 Benchmark Date: 01 Apr 2026:

The configuration integrity of the container platform must be ensured and compliance policies must be configured.

DISA Rule

SV-253532r960960_rule

Vulnerability Number

V-253532

Group Title

SRG-APP-000133-CTR-000305

Rule Version

CNTR-PC-000450

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

Enable compliance policies.

Navigate to Prisma Cloud Compute Console's Defend >> Compliance and click tab to be edited.

To add rule:
- Click "Add rule."
- Enter rule name.
Scope = All
- Accept the defaults and click "Save".

Click the rule's three-dot menu. Set to "Enable".

Click the rule row.
- Change the policy scope to "All".
- Click "Save".

Check Contents

Verify compliance policies are enabled.

Navigate to Prisma Cloud Compute Console's Defend >> Compliance.

Select the "Code repositories" tab.
Select the "Repositories" and "CI" tab.
- If "Default – alert all components" does not exist, this is a finding.
- Click the three dots in the "Actions" column for rule "Default - alert all components".
- If the policy is disabled, this is a finding.
- Click the "Default – alert all components" policy row.
- If the "Default - alert on critical and high" policy is not scoped to "All", this is a finding.

Select the "Containers and images" tab.
For the "Deployed" and "CI" tab:
- If the "Default - alert on critical and high" does not exist, this is a finding.
- Click the three dots in the "Actions" column for rule "Default - alert on critical and high".
- If the policy is disabled, this is a finding.
- Click the "Default - alert on critical and high" policy row.
- If the "Default - alert on critical and high" policy is not scoped to "All", this is a finding.

Select the "Hosts" tab.
For the "Running hosts" and "VM images" tab:
- If the "Default - alert on critical and high" does not exist, this is a finding.
- Click the three dots in the "Actions" column for rule "Default - alert on critical and high".
- If the policy is disabled, this is a finding.
- Click the "Default - alert on critical and high" policy row.
- If the "Default - alert on critical and high" policy is not scoped to "All", this is a finding.

Select the "Functions" tab.
For the "Functions" and "CI" tab:
- If the "Default – alert all components" does not exist, this is a finding.
- Click the three dots in the "Actions" column for rule "Default -alert all components".
- If the policy is disabled, this is a finding.
- Click the "Default - alert all components" policy row.
- If the "Default - alert on critical and high" policy is not scoped to "All", this is a finding.

Vulnerability Number

V-253532

Documentable

False

Rule Version

CNTR-PC-000450

Severity Override Guidance

Verify compliance policies are enabled.

Navigate to Prisma Cloud Compute Console's Defend >> Compliance.

Select the "Code repositories" tab.
Select the "Repositories" and "CI" tab.
- If "Default – alert all components" does not exist, this is a finding.
- Click the three dots in the "Actions" column for rule "Default - alert all components".
- If the policy is disabled, this is a finding.
- Click the "Default – alert all components" policy row.
- If the "Default - alert on critical and high" policy is not scoped to "All", this is a finding.

Select the "Containers and images" tab.
For the "Deployed" and "CI" tab:
- If the "Default - alert on critical and high" does not exist, this is a finding.
- Click the three dots in the "Actions" column for rule "Default - alert on critical and high".
- If the policy is disabled, this is a finding.
- Click the "Default - alert on critical and high" policy row.
- If the "Default - alert on critical and high" policy is not scoped to "All", this is a finding.

Select the "Hosts" tab.
For the "Running hosts" and "VM images" tab:
- If the "Default - alert on critical and high" does not exist, this is a finding.
- Click the three dots in the "Actions" column for rule "Default - alert on critical and high".
- If the policy is disabled, this is a finding.
- Click the "Default - alert on critical and high" policy row.
- If the "Default - alert on critical and high" policy is not scoped to "All", this is a finding.

Select the "Functions" tab.
For the "Functions" and "CI" tab:
- If the "Default – alert all components" does not exist, this is a finding.
- Click the three dots in the "Actions" column for rule "Default -alert all components".
- If the policy is disabled, this is a finding.
- Click the "Default - alert all components" policy row.
- If the "Default - alert on critical and high" policy is not scoped to "All", this is a finding.

Check Content Reference

M

Target Key

5473