STIGQter STIGQter: STIG Summary: Palo Alto Networks Prisma Cloud Compute Security Technical Implementation Guide Version: 2 Release: 3 Benchmark Date: 01 Apr 2026:

Prisma Cloud Compute Defender containers must run as root.

DISA Rule

SV-253546r1050656_rule

Vulnerability Number

V-253546

Group Title

SRG-APP-000414-CTR-001010

Rule Version

CNTR-PC-001350

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Redeploy the Defender with appropriate rights by setting "Run Defenders as privileged" to "On".

Delete the old twistlock-defender-ds daemonSet and redeploy daemonSet with the new yaml in which the securityContext - privileged = "on".

Check Contents

Verify that when deploying the Defender via daemonSet, "Run Defenders as privileged" is set to "On".

Verify the Defender containers were deployed using the daemonSet.yaml in which the securityContext is privileged (privileged = "on").

If "Run Defenders as privileged" is not set to "On" or the Defender containers were not deployed using the daemonSet.yaml in which the securityContext - privileged = "on", this is a finding.

Vulnerability Number

V-253546

Documentable

False

Rule Version

CNTR-PC-001350

Severity Override Guidance

Verify that when deploying the Defender via daemonSet, "Run Defenders as privileged" is set to "On".

Verify the Defender containers were deployed using the daemonSet.yaml in which the securityContext is privileged (privileged = "on").

If "Run Defenders as privileged" is not set to "On" or the Defender containers were not deployed using the daemonSet.yaml in which the securityContext - privileged = "on", this is a finding.

Check Content Reference

M

Target Key

5473