SV-253543r961473_rule
V-253543
SRG-APP-000384-CTR-000915
CNTR-PC-001170
CAT I
10
To enable vulnerabilities policies, navigate to Prisma Cloud Compute Console's Defend >> Vulnerabilities. Click tab to be edited.
To add rule:
- Click "Add rule".
- Enter rule name.
Scope = All
- Accept the defaults and click "Save".
Click the rule three-dot menu. Set to "Enable".
Click the rule row:
- Change the policy scope to "All".
- Click "Save".
To verify that vulnerabilities policies are enabled, navigate to Prisma Cloud Compute Console's Defend >> Vulnerabilities.
Select the "Code repositories" tab.
For the "Repositories" and "CI" tab:
- If "Default - alert all components" does not exist, this is a finding.
- Click the three dots in the "Actions" column for rule "Default - alert all components".
- If the policy is disabled, this is a finding.
- Click the "Default - alert all components" policy row.
- If "Default - alert all components" is not scoped to "All", this is a finding.
Select the "Images" tab.
For the "CI" and "Deployed" tab:
- If "Default - alert all components" does not exist, this is a finding.
- Click the three dots in the "Actions" column for rule "Default - alert all components".
- If the policy is disabled, this is a finding.
- Click the "Default - alert all components" policy row.
- If "Default - alert all components" is not scoped to "All", this is a finding.
Select the "Hosts" tab.
For the "Running hosts" and "VM images" tab:
- If the "Default - alert all components" does not exist, this is a finding.
- Click the three dots in the "Actions" column for rule "Default - alert all components".
- If the policy is disabled, this is a finding.
- Click the "Default - alert all components" policy row.
- If "Default - alert all components" is not scoped to "All", this is a finding.
Select the "Functions" tab.
For the "Functions" and "CI" tab:
- If the "Default - alert all components" does not exist, this is a finding.
- Click the three dots in the "Actions" column for rule "Default - alert all components".
- If the policy is disabled, this is a finding.
- Click the "Default - alert all components" policy row.
- If "Default - alert all components" is not scoped to "All", this is a finding.
V-253543
False
CNTR-PC-001170
To verify that vulnerabilities policies are enabled, navigate to Prisma Cloud Compute Console's Defend >> Vulnerabilities.
Select the "Code repositories" tab.
For the "Repositories" and "CI" tab:
- If "Default - alert all components" does not exist, this is a finding.
- Click the three dots in the "Actions" column for rule "Default - alert all components".
- If the policy is disabled, this is a finding.
- Click the "Default - alert all components" policy row.
- If "Default - alert all components" is not scoped to "All", this is a finding.
Select the "Images" tab.
For the "CI" and "Deployed" tab:
- If "Default - alert all components" does not exist, this is a finding.
- Click the three dots in the "Actions" column for rule "Default - alert all components".
- If the policy is disabled, this is a finding.
- Click the "Default - alert all components" policy row.
- If "Default - alert all components" is not scoped to "All", this is a finding.
Select the "Hosts" tab.
For the "Running hosts" and "VM images" tab:
- If the "Default - alert all components" does not exist, this is a finding.
- Click the three dots in the "Actions" column for rule "Default - alert all components".
- If the policy is disabled, this is a finding.
- Click the "Default - alert all components" policy row.
- If "Default - alert all components" is not scoped to "All", this is a finding.
Select the "Functions" tab.
For the "Functions" and "CI" tab:
- If the "Default - alert all components" does not exist, this is a finding.
- Click the three dots in the "Actions" column for rule "Default - alert all components".
- If the policy is disabled, this is a finding.
- Click the "Default - alert all components" policy row.
- If "Default - alert all components" is not scoped to "All", this is a finding.
M
5473