STIGQter STIGQter: STIG Summary: Mirantis Kubernetes Engine Security Technical Implementation Guide Version: 2 Release: 1 Benchmark Date: 24 Jul 2024:

Audit logging must be enabled on MKE.

DISA Rule

SV-260914r966099_rule

Vulnerability Number

V-260914

Group Title

SRG-APP-000092-CTR-000165

Rule Version

CNTR-MK-000220

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Log in to the MKE web UI and navigate to admin >> Admin Settings >> Logs & Audit Logs.

In the "Configure Audit Log Level" section, select "Request"

In the "Configure Global Log Level" section, select "INFO" or "DEBUG".
Note: The recommended setting is "INFO".

Click "Save".

Check Contents

Check auditing configuration level for MKE nodes and controller:

Log in to the MKE web UI and navigate to admin >> Admin Settings >> Logs & Audit Logs.

If "AUDIT LOG LEVEL" is not set to "Request", this is a finding.

If "DEBUG LEVEL" is set to "ERROR", this is a finding.

Vulnerability Number

V-260914

Documentable

False

Rule Version

CNTR-MK-000220

Severity Override Guidance

Check auditing configuration level for MKE nodes and controller:

Log in to the MKE web UI and navigate to admin >> Admin Settings >> Logs & Audit Logs.

If "AUDIT LOG LEVEL" is not set to "Request", this is a finding.

If "DEBUG LEVEL" is set to "ERROR", this is a finding.

Check Content Reference

M

Target Key

5595