STIGQter STIGQter: STIG Summary: Palo Alto Networks Prisma Cloud Compute Security Technical Implementation Guide Version: 2 Release: 3 Benchmark Date: 01 Apr 2026:

Prisma Cloud Compute must be configured to scan images that have not been instantiated as containers.

DISA Rule

SV-253544r961473_rule

Vulnerability Number

V-253544

Group Title

SRG-APP-000384-CTR-000915

Rule Version

CNTR-PC-001220

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

Navigate to Prisma Cloud Compute Console's >> Manage >> System >> Scan tab.

For Running images:
- Set "Only scan images with running containers" = "Off".
- Click "Save".

Check Contents

Navigate to Prisma Cloud Compute Console's >> Manage >> System >> Scan tab.

Verify that for Running images, For Running images, "Only scan images with running containers" is set to "Off".

If "Only scan images with running containers" is set to "On", this is a finding.

Vulnerability Number

V-253544

Documentable

False

Rule Version

CNTR-PC-001220

Severity Override Guidance

Navigate to Prisma Cloud Compute Console's >> Manage >> System >> Scan tab.

Verify that for Running images, For Running images, "Only scan images with running containers" is set to "Off".

If "Only scan images with running containers" is set to "On", this is a finding.

Check Content Reference

M

Target Key

5473