STIGQter STIGQter: STIG Summary: Palo Alto Networks Prisma Cloud Compute Security Technical Implementation Guide Version: 2 Release: 3 Benchmark Date: 01 Apr 2026:

The configuration integrity of the container platform must be ensured and vulnerabilities policies must be configured.

DISA Rule

SV-253543r961473_rule

Vulnerability Number

V-253543

Group Title

SRG-APP-000384-CTR-000915

Rule Version

CNTR-PC-001170

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

To enable vulnerabilities policies, navigate to Prisma Cloud Compute Console's Defend >> Vulnerabilities. Click tab to be edited.

To add rule:
- Click "Add rule".
- Enter rule name.
Scope = All
- Accept the defaults and click "Save".

Click the rule three-dot menu. Set to "Enable".

Click the rule row:
- Change the policy scope to "All".
- Click "Save".

Check Contents

To verify that vulnerabilities policies are enabled, navigate to Prisma Cloud Compute Console's Defend >> Vulnerabilities.

Select the "Code repositories" tab.
For the "Repositories" and "CI" tab:
- If "Default - alert all components" does not exist, this is a finding.
- Click the three dots in the "Actions" column for rule "Default - alert all components".
- If the policy is disabled, this is a finding.
- Click the "Default - alert all components" policy row.
- If "Default - alert all components" is not scoped to "All", this is a finding.

Select the "Images" tab.
For the "CI" and "Deployed" tab:
- If "Default - alert all components" does not exist, this is a finding.
- Click the three dots in the "Actions" column for rule "Default - alert all components".
- If the policy is disabled, this is a finding.
- Click the "Default - alert all components" policy row.
- If "Default - alert all components" is not scoped to "All", this is a finding.

Select the "Hosts" tab.
For the "Running hosts" and "VM images" tab:
- If the "Default - alert all components" does not exist, this is a finding.
- Click the three dots in the "Actions" column for rule "Default - alert all components".
- If the policy is disabled, this is a finding.
- Click the "Default - alert all components" policy row.
- If "Default - alert all components" is not scoped to "All", this is a finding.

Select the "Functions" tab.
For the "Functions" and "CI" tab:
- If the "Default - alert all components" does not exist, this is a finding.
- Click the three dots in the "Actions" column for rule "Default - alert all components".
- If the policy is disabled, this is a finding.
- Click the "Default - alert all components" policy row.
- If "Default - alert all components" is not scoped to "All", this is a finding.

Vulnerability Number

V-253543

Documentable

False

Rule Version

CNTR-PC-001170

Severity Override Guidance

To verify that vulnerabilities policies are enabled, navigate to Prisma Cloud Compute Console's Defend >> Vulnerabilities.

Select the "Code repositories" tab.
For the "Repositories" and "CI" tab:
- If "Default - alert all components" does not exist, this is a finding.
- Click the three dots in the "Actions" column for rule "Default - alert all components".
- If the policy is disabled, this is a finding.
- Click the "Default - alert all components" policy row.
- If "Default - alert all components" is not scoped to "All", this is a finding.

Select the "Images" tab.
For the "CI" and "Deployed" tab:
- If "Default - alert all components" does not exist, this is a finding.
- Click the three dots in the "Actions" column for rule "Default - alert all components".
- If the policy is disabled, this is a finding.
- Click the "Default - alert all components" policy row.
- If "Default - alert all components" is not scoped to "All", this is a finding.

Select the "Hosts" tab.
For the "Running hosts" and "VM images" tab:
- If the "Default - alert all components" does not exist, this is a finding.
- Click the three dots in the "Actions" column for rule "Default - alert all components".
- If the policy is disabled, this is a finding.
- Click the "Default - alert all components" policy row.
- If "Default - alert all components" is not scoped to "All", this is a finding.

Select the "Functions" tab.
For the "Functions" and "CI" tab:
- If the "Default - alert all components" does not exist, this is a finding.
- Click the three dots in the "Actions" column for rule "Default - alert all components".
- If the policy is disabled, this is a finding.
- Click the "Default - alert all components" policy row.
- If "Default - alert all components" is not scoped to "All", this is a finding.

Check Content Reference

M

Target Key

5473