STIGQter STIGQter: STIG Summary:

Palo Alto Networks Prisma Cloud Compute Security Technical Implementation Guide

Version: 2

Release: 3 Benchmark Date: 01 Apr 2026

CheckedNameTitle
SV-253522r960759_rulePrisma Cloud Compute Console must use TLS 1.2 for user interface and API access. Communication TCP ports must adhere to the Ports, Protocols, and Services Management Category Assurance Levels (PSSM CAL).
SV-253523r1043176_ruleAccess to Prisma Cloud Compute must be managed based on user need and least privileged using external identity providers for authentication and grouping to role-based assignments when possible.
SV-253524r1137640_ruleUsers requiring access to Prisma Cloud Compute's Credential Store must be assigned and accessed by the appropriate role holders.
SV-253525r1137641_rulePrisma Cloud Compute Collections must be used to partition views and enforce organizational-defined need-to-know access.
SV-253526r1137642_rulePrisma Cloud Compute Cloud Native Network Firewall (CNNF) automatically monitors layer 4 (TCP) intercontainer communications. Enforcement policies must be created.
SV-253527r960897_rulePrisma Cloud Compute Defender must be deployed to containerization nodes that are to be monitored.
SV-253528r960903_rulePrisma Cloud Compute must be configured for forensic data collection.
SV-253529r960909_ruleThe configuration integrity of the container platform must be ensured and runtime policies must be configured.
SV-253530r960918_rulePrisma Cloud Compute must be configured to send events to the hosts' syslog.
SV-253531r960960_rulePrisma Cloud Compute host compliance baseline policies must be set.
SV-253532r960960_ruleThe configuration integrity of the container platform must be ensured and compliance policies must be configured.
SV-253533r960963_ruleImages stored within the container registry must contain only images to be run as containers within the container platform.
SV-253534r1043177_rulePrisma Cloud Compute must use TCP ports above 1024.
SV-253535r1051115_ruleAll Prisma Cloud Compute users must have a unique, individual account.
SV-253536r1051115_rulePrisma Cloud Compute Console must run as nonroot user (uid 2674).
SV-253537r1015785_rulePrisma Cloud Compute must be configured with unique user accounts.
SV-253538r1015786_rulePrisma Cloud Compute local accounts must enforce strong password requirements.
SV-253539r1188294_rulePrisma Cloud Compute must be configured to require local user accounts to use x.509 multifactor authentication.
SV-253540r1137644_rulePrisma Cloud Compute must prevent unauthorized and unintended information transfer.
SV-253541r961167_rulePrisma Cloud Compute must not write sensitive data to event logs.
SV-253542r961392_ruleThe node that runs Prisma Cloud Compute containers must have sufficient disk space to allocate audit record storage capacity in accordance with organization-defined audit record storage requirements.
SV-253543r961473_ruleThe configuration integrity of the container platform must be ensured and vulnerabilities policies must be configured.
SV-253544r961473_rulePrisma Cloud Compute must be configured to scan images that have not been instantiated as containers.
SV-253545r986174_rulePrisma Cloud Compute Defender must reestablish communication to the Console via mutual TLS v1.2 WebSocket session.
SV-253546r1050656_rulePrisma Cloud Compute Defender containers must run as root.
SV-253547r1137646_rulePrisma Cloud Compute must run within a defined/separate namespace (e.g., Twistlock).
SV-253548r961632_rulePrisma Cloud Compute must protect the confidentiality and integrity of transmitted information.
SV-253549r961677_rulePrisma Cloud Compute must be running the latest release.
SV-253550r1137650_rulePrisma Cloud Compute's Intelligence Stream must be kept up to date.
SV-253551r961734_ruleConfiguration of Prisma Cloud Compute must be continuously verified.
SV-253552r961896_rulePrisma Cloud Compute release tar distributions must have an associated SHA-256 digest.