STIGQter STIGQter: STIG Summary: Palo Alto Networks Prisma Cloud Compute Security Technical Implementation Guide Version: 2 Release: 3 Benchmark Date: 01 Apr 2026:

Prisma Cloud Compute's Intelligence Stream must be kept up to date.

DISA Rule

SV-253550r1137650_rule

Vulnerability Number

V-253550

Group Title

SRG-APP-000456-CTR-001130

Rule Version

CNTR-PC-001470

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Prisma Cloud Compute Console's ability to communicate with the Intelligence Stream endpoint (https://intelligence.twistlock.com) dictates the method of vulnerability updates.

If the Console is able to communicate with the internet, ensure that intelligence.twistlock.com is resolvable, routable, and can establish a TLS session on TCP port 443.

If the Console is in an isolated environment and is unable to communicate with the internet, configure the Console to receive Intelligence Stream updates using one of the following methods:
- Manual import.
- Central console.
- HTTP/S distribution point.

https://docs.paloaltonetworks.com/prisma/prisma-cloud/22-01/prisma-cloud-compute-edition-admin/tools/update_intel_stream_offline.html

Check Contents

Navigate to Prisma Cloud Compute Console's >> Manage >> System >> Intelligence tab.

If the "Last streams update" date is older than 36 hours, this is a finding.

Vulnerability Number

V-253550

Documentable

False

Rule Version

CNTR-PC-001470

Severity Override Guidance

Navigate to Prisma Cloud Compute Console's >> Manage >> System >> Intelligence tab.

If the "Last streams update" date is older than 36 hours, this is a finding.

Check Content Reference

M

Target Key

5473