SV-257586r961863_rule
V-257586
SRG-APP-000516-CTR-001335
CNTR-OS-001060
CAT II
10
Vulnerability scanning can be performed by the Container Security Operator, Red Hat Advanced Cluster Security (formerly StackRox) or by external applications. Follow instructions from the application vendor if using external tool for vulnerability scanning. To install the Container Security Operator into the cluster, run the following:
oc apply -f - << 'EOF'
---
apiVersion: operators.coreos.com/v1alpha1
kind: Subscription
metadata:
labels:
operators.coreos.com/container-security-operator.openshift-operators: ''
name: container-security-operator
namespace: openshift-operators
spec:
channel: stable-3.8
installPlanApproval: Automatic
name: container-security-operator
source: redhat-operators
sourceNamespace: openshift-marketplace
EOF
To check if the Container Security Operator is running, execute the following:
oc get deploy -n openshift-operators container-security-operator -ojsonpath='{.status.readyReplicas}'
If this command returns an error or the number 0, and a separate tool is not being used to perform continuous vulnerability scans of components, containers, and container images, this is a finding.
V-257586
False
CNTR-OS-001060
To check if the Container Security Operator is running, execute the following:
oc get deploy -n openshift-operators container-security-operator -ojsonpath='{.status.readyReplicas}'
If this command returns an error or the number 0, and a separate tool is not being used to perform continuous vulnerability scans of components, containers, and container images, this is a finding.
M
5547