| Checked | Name | Title |
|---|---|---|
| ☐ | SV-260903r1015767_rule | The Lifetime Minutes and Renewal Threshold Minutes Login Session Controls on MKE must be set. |
| ☐ | SV-260904r966069_rule | In an MSR organization, user permissions and repositories must be configured. |
| ☐ | SV-260905r966072_rule | User-managed resources must be created in dedicated namespaces. |
| ☐ | SV-260906r1015768_rule | Least privilege access and need to know must be required to access MKE runtime and instantiate container images. |
| ☐ | SV-260907r966078_rule | Only required ports must be open on containers in MKE. |
| ☐ | SV-260908r966081_rule | FIPS mode must be enabled. |
| ☐ | SV-260909r1015769_rule | MKE must be configured to integrate with an Enterprise Identity Provider. |
| ☐ | SV-260910r966087_rule | SSH must not run within Linux containers. |
| ☐ | SV-260911r1015770_rule | Swarm Secrets or Kubernetes Secrets must be used. |
| ☐ | SV-260912r966093_rule | MKE must have Grants created to control authorization to cluster resources. |
| ☐ | SV-260913r966096_rule | MKE host network namespace must not be shared. |
| ☐ | SV-260914r966099_rule | Audit logging must be enabled on MKE. |
| ☐ | SV-260915r966102_rule | MKE must be configured to send audit data to a centralized log server. |
| ☐ | SV-260916r966105_rule | MSR's self-signed certificates must be replaced with DOD trusted, signed certificates. |
| ☐ | SV-260917r966108_rule | Allowing users and administrators to schedule containers on all nodes must be disabled. |
| ☐ | SV-260918r966111_rule | MKE telemetry must be disabled. |
| ☐ | SV-260919r966114_rule | MSR telemetry must be disabled. |
| ☐ | SV-260920r966117_rule | For MKE's deployed on an Ubuntu host operating system, the AppArmor profile must be enabled. |
| ☐ | SV-260921r966120_rule | If MKE is deployed on a Red Hat or CentOS system, SELinux security must be enabled. |
| ☐ | SV-260922r966123_rule | The Docker socket must not be mounted inside any containers. |
| ☐ | SV-260923r966126_rule | Linux Kernel capabilities must be restricted within containers. |
| ☐ | SV-260924r966129_rule | Incoming container traffic must be bound to a specific host interface. |
| ☐ | SV-260925r966132_rule | CPU priority must be set appropriately on all containers. |
| ☐ | SV-260926r966135_rule | MKE must use a non-AUFS storage driver. |
| ☐ | SV-260927r966138_rule | MKE's self-signed certificates must be replaced with DOD trusted, signed certificates. |
| ☐ | SV-260928r966141_rule | The "Create repository on push" option in MSR must be disabled. |
| ☐ | SV-260929r966144_rule | Containers must not map to privileged ports. |
| ☐ | SV-260930r966147_rule | MKE must not permit users to create pods that share host process namespace. |
| ☐ | SV-260931r966150_rule | IPSec network encryption must be configured. |
| ☐ | SV-260932r966153_rule | MKE must preserve any information necessary to determine the cause of the disruption or failure. |
| ☐ | SV-260933r966156_rule | MKE must enable kernel protection. |
| ☐ | SV-260934r966159_rule | All containers must be restricted from acquiring additional privileges. |
| ☐ | SV-260935r966162_rule | Host IPC namespace must not be shared. |
| ☐ | SV-260936r966165_rule | All containers must be restricted to mounting the root filesystem as read only. |
| ☐ | SV-260937r966168_rule | The default seccomp profile must not be disabled. |
| ☐ | SV-260938r1015771_rule | Docker CLI commands must be run with an MKE client trust bundle and without unnecessary permissions. |
| ☐ | SV-260939r966174_rule | MKE users must not have permissions to create containers or pods that share the host user namespace. |
| ☐ | SV-260940r966177_rule | Use of privileged Linux containers must be limited to system containers. |
| ☐ | SV-260941r966180_rule | The network ports on all running containers must be limited to required ports. |
| ☐ | SV-260942r1015772_rule | MKE must only run signed images. |
| ☐ | SV-260943r966186_rule | Vulnerability scanning must be enabled for all repositories in MSR. |
| ☐ | SV-260944r966189_rule | Older Universal Control Plane (MKE) and Docker Trusted Registry (DTR) images must be removed from all cluster nodes upon upgrading. |
| ☐ | SV-260945r966192_rule | MKE must contain the latest updates. |
| ☐ | SV-260946r966345_rule | MKE must display the Standard Mandatory DOD Notice and Consent Banner before granting access to platform components. |