STIGQter STIGQter: STIG Summary: Container Platform Security Requirements Guide Version: 2 Release: 4 Benchmark Date: 28 Oct 2025:

The container root filesystem must be mounted as read-only.

DISA Rule

SV-270876r1050649_rule

Vulnerability Number

V-270876

Group Title

SRG-APP-000380

Rule Version

SRG-APP-000380-CTR-000340

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Review and remove nonsystem containers previously created with read-write permissions. Configure the container platform to force the root filesystem to be mounted as read-only.

Check Contents

Review the container platform configuration to determine that the root filesystem is mounted as read-only.

If the container platform does not enforce such access restrictions, this is a finding.

Vulnerability Number

V-270876

Documentable

False

Rule Version

SRG-APP-000380-CTR-000340

Severity Override Guidance

Review the container platform configuration to determine that the root filesystem is mounted as read-only.

If the container platform does not enforce such access restrictions, this is a finding.

Check Content Reference

M

Target Key

5239