STIGQter STIGQter: STIG Summary: Mirantis Kubernetes Engine Security Technical Implementation Guide Version: 2 Release: 1 Benchmark Date: 24 Jul 2024:

Vulnerability scanning must be enabled for all repositories in MSR.

DISA Rule

SV-260943r966186_rule

Vulnerability Number

V-260943

Group Title

SRG-APP-000414-CTR-001010

Rule Version

CNTR-MK-001490

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

If MSR is not being utilized, this is Not Applicable.

Enable vulnerability scanning on the MSR UI by logging in to the MSR web UI and navigating to System >> Security Tab.

Click the "Enable Scanning" slider to enable this capability.

Sync (online) or upload (offline) the vulnerability database.

Check Contents

If MSR is not being utilized, this is Not Applicable.

Check image vulnerability scanning enabled for all repositories.

Log in to the MSR web UI and navigate to System >> Security Tab.

Verify that the "Enable Scanning" slider is turned on and the vulnerability database has been successfully synced (online) or uploaded (offline).

If the "Enable Scanning" slider is tuned off, this is a finding.

If the vulnerability database is not synced or uploaded, this is a finding.

Vulnerability Number

V-260943

Documentable

False

Rule Version

CNTR-MK-001490

Severity Override Guidance

If MSR is not being utilized, this is Not Applicable.

Check image vulnerability scanning enabled for all repositories.

Log in to the MSR web UI and navigate to System >> Security Tab.

Verify that the "Enable Scanning" slider is turned on and the vulnerability database has been successfully synced (online) or uploaded (offline).

If the "Enable Scanning" slider is tuned off, this is a finding.

If the vulnerability database is not synced or uploaded, this is a finding.

Check Content Reference

M

Target Key

5595