| Checked | Name | Title |
|---|
| ☐ | SV-257505r960759_rule | OpenShift must use TLS 1.2 or greater for secure container image transport from trusted sources. |
| ☐ | SV-257506r960759_rule | OpenShift must use TLS 1.2 or greater for secure communication. |
| ☐ | SV-257507r1043176_rule | OpenShift must use a centralized user management solution to support account management functions. |
| ☐ | SV-257508r1043176_rule | The kubeadmin account must be disabled. |
| ☐ | SV-257509r960777_rule | OpenShift must automatically audit account creation. |
| ☐ | SV-257510r960780_rule | OpenShift must automatically audit account modification. |
| ☐ | SV-257511r1015792_rule | OpenShift must generate audit rules to capture account related actions. |
| ☐ | SV-257512r960786_rule | Open Shift must automatically audit account removal actions. |
| ☐ | SV-257513r1156752_rule | OpenShift role-based access controls (RBAC) must be enforced. |
| ☐ | SV-257514r1208195_rule | OpenShift must enforce network policy on the namespace for controlling the flow of information within the container platform based on organization-defined information flow control policies. |
| ☐ | SV-257515r1208198_rule | OpenShift must enforce approved authorizations for controlling the flow of information within the container platform based on organization-defined information flow control policies. |
| ☐ | SV-257516r960843_rule | OpenShift must display the Standard Mandatory DOD Notice and Consent Banner before granting access to platform components. |
| ☐ | SV-257517r1208201_rule | OpenShift must generate audit records for all DOD-defined auditable events within all components in the platform. |
| ☐ | SV-257518r1050653_rule | OpenShift must generate audit records when successful/unsuccessful attempts to access privileges occur. |
| ☐ | SV-257519r960888_rule | Red Hat Enterprise Linux CoreOS (RHCOS) must initiate session audits at system startup. |
| ☐ | SV-257520r960891_rule | All audit records must identify what type of event has occurred within OpenShift. |
| ☐ | SV-257521r960894_rule | OpenShift audit records must have a date and time association with all events. |
| ☐ | SV-257522r960903_rule | All audit records must generate the event results within OpenShift. |
| ☐ | SV-257523r1050555_rule | OpenShift must take appropriate action upon an audit failure. |
| ☐ | SV-257524r960918_rule | OpenShift components must provide the ability to send audit logs to a central enterprise repository for review and analysis. |
| ☐ | SV-257525r960927_rule | OpenShift must use internal system clocks to generate audit record time stamps. |
| ☐ | SV-257526r960927_rule | The Red Hat Enterprise Linux CoreOS (RHCOS) chrony Daemon must use multiple NTP servers to generate audit record time stamps. |
| ☐ | SV-257527r960930_rule | OpenShift must protect audit logs from any type of unauthorized access. |
| ☐ | SV-257528r960930_rule | OpenShift must protect system journal file from any type of unauthorized access by setting file permissions. |
| ☐ | SV-257529r960930_rule | OpenShift must protect system journal file from any type of unauthorized access by setting owner permissions. |
| ☐ | SV-257530r960930_rule | OpenShift must protect log directory from any type of unauthorized access by setting file permissions. |
| ☐ | SV-257531r960930_rule | OpenShift must protect log directory from any type of unauthorized access by setting owner permissions. |
| ☐ | SV-257532r960930_rule | OpenShift must protect pod log files from any type of unauthorized access by setting owner permissions. |
| ☐ | SV-257533r960933_rule | OpenShift must protect audit information from unauthorized modification. |
| ☐ | SV-257534r960939_rule | OpenShift must prevent unauthorized changes to logon UIDs. |
| ☐ | SV-257535r960939_rule | OpenShift must protect audit tools from unauthorized access. |
| ☐ | SV-257536r960951_rule | OpenShift must use FIPS-validated cryptographic mechanisms to protect the integrity of log information. |
| ☐ | SV-257537r1015794_rule | OpenShift must verify container images. |
| ☐ | SV-257538r960963_rule | OpenShift must contain only container images for those capabilities being offered by the container platform. |
| ☐ | SV-257539r1043177_rule | OpenShift runtime must enforce ports, protocols, and services that adhere to the PPSM CAL. |
| ☐ | SV-257540r1156731_rule | OpenShift must disable root and terminate network connections. |
| ☐ | SV-257541r960972_rule | OpenShift must use multifactor authentication for network access to accounts. |
| ☐ | SV-257542r960993_rule | OpenShift must use FIPS-validated SHA-1 or higher hash function to provide replay-resistant authentication mechanisms for network access to privileged accounts. |
| ☐ | SV-257543r1015795_rule | OpenShift must use FIPS validated LDAP or OpenIDConnect. |
| ☐ | SV-257544r1015796_rule | OpenShift must terminate all network connections associated with a communications session at the end of the session, or as follows: for in-band management sessions (privileged sessions), the session must be terminated after 10 minutes of inactivity. |
| ☐ | SV-257545r1208204_rule | OpenShift must separate user functionality (including user interface services) from information system management functionality. |
| ☐ | SV-257546r1043178_rule | OpenShift must protect authenticity of communications sessions with the use of FIPS-validated 140-2 or 140-3 validated cryptography. |
| ☐ | SV-257547r961131_rule | OpenShift runtime must isolate security functions from nonsecurity functions. |
| ☐ | SV-257548r1156737_rule | OpenShift must prevent unauthorized and unintended information transfer via shared system resources and enable page poisoning. |
| ☐ | SV-257549r1137645_rule | OpenShift must disable virtual syscalls. |
| ☐ | SV-257550r1137645_rule | OpenShift must enable poisoning of SLUB/SLAB objects. |
| ☐ | SV-257551r1137645_rule | OpenShift must set the sticky bit for world-writable directories. |
| ☐ | SV-257552r1137645_rule | OpenShift must restrict access to the kernel buffer. |
| ☐ | SV-257553r1137645_rule | OpenShift must prevent kernel profiling. |
| ☐ | SV-257554r961152_rule | OpenShift must restrict individuals the ability to launch organizational-defined Denial-of-Service (DOS) attacks against other information systems by setting a default Resource Quota. |
| ☐ | SV-257555r1208206_rule | OpenShift must restrict individuals' ability to launch organization-defined denial-of-service (DOS) attacks against other information systems by rate-limiting. |
| ☐ | SV-257556r961227_rule | OpenShift must display an explicit logout message indicating the reliable termination of authenticated communication sessions. |
| ☐ | SV-257557r961359_rule | Container images instantiated by OpenShift must execute using least privileges. |
| ☐ | SV-257558r961392_rule | Red Hat Enterprise Linux CoreOS (RHCOS) must allocate audit record storage capacity to store at least one weeks' worth of audit records, when audit records are not immediately sent to a central audit record storage facility. |
| ☐ | SV-257559r961401_rule | OpenShift must configure Alert Manger Receivers to notify SA and ISSO of all audit failure events requiring real-time alerts. |
| ☐ | SV-257560r1015797_rule | OpenShift must enforce access restrictions and support auditing of the enforcement actions. |
| ☐ | SV-257561r1156740_rule | OpenShift must prevent the installation of patches, service packs, device drivers, or operating system components without verification they have been digitally signed using a certificate that is recognized and approved by the organization. |
| ☐ | SV-257562r961521_rule | OpenShift must set server token max age no greater than eight hours. |
| ☐ | SV-257563r961563_rule | Vulnerability scanning applications must implement privileged access authorization to all OpenShift components, containers, and container images for selected organization-defined vulnerability scanning activities. |
| ☐ | SV-257564r1050650_rule | OpenShift keystore must implement encryption to prevent unauthorized disclosure of information at rest within the container platform. |
| ☐ | SV-257565r961620_rule | OpenShift must protect against or limit the effects of all types of Denial-of-Service (DoS) attacks by employing organization-defined security safeguards by including a default resource quota. |
| ☐ | SV-257566r961620_rule | OpenShift must protect against or limit the effects of all types of Denial-of-Service (DoS) attacks by defining resource quotas on a namespace. |
| ☐ | SV-257567r961632_rule | OpenShift must protect the confidentiality and integrity of transmitted information. |
| ☐ | SV-257568r961665_rule | Red Hat Enterprise Linux CoreOS (RHCOS) must implement nonexecutable data to protect its memory from unauthorized code execution. |
| ☐ | SV-257569r961665_rule | Red Hat Enterprise Linux CoreOS (RHCOS) must implement ASLR (Address Space Layout Randomization) from unauthorized code execution. |
| ☐ | SV-257570r961677_rule | OpenShift must remove old components after updated versions have been installed. |
| ☐ | SV-257571r1137649_rule | OpenShift must contain the latest images with most recent updates and execute within the container platform runtime as authorized by IAVM, CTOs, DTMs, and STIGs. |
| ☐ | SV-257572r1137650_rule | OpenShift runtime must have updates installed within the period directed by an authoritative source (e.g., IAVM, CTOs, DTMs, and STIGs). |
| ☐ | SV-257573r961731_rule | The Compliance Operator must be configured. |
| ☐ | SV-257574r961734_rule | OpenShift must perform verification of the correct operation of security functions: upon startup and/or restart; upon command by a user with privileged access; and/or every 30 days. |
| ☐ | SV-257575r961800_rule | OpenShift must generate audit records when successful/unsuccessful attempts to modify privileges occur. |
| ☐ | SV-257576r961803_rule | OpenShift must generate audit records when successful/unsuccessful attempts to modify security objects occur. |
| ☐ | SV-257577r961812_rule | OpenShift must generate audit records when successful/unsuccessful attempts to delete privileges occur. |
| ☐ | SV-257578r961818_rule | OpenShift must generate audit records when successful/unsuccessful attempts to delete security objects occur. |
| ☐ | SV-257579r961824_rule | OpenShift must generate audit records when successful/unsuccessful logon attempts occur. |
| ☐ | SV-257580r961827_rule | Red Hat Enterprise Linux CoreOS (RHCOS) must be configured to audit the loading and unloading of dynamic kernel modules. |
| ☐ | SV-257581r961830_rule | OpenShift audit records must record user access start and end times. |
| ☐ | SV-257582r961833_rule | OpenShift must generate audit records when concurrent logons from different workstations and systems occur. |
| ☐ | SV-257583r960963_rule | Red Hat Enterprise Linux CoreOS (RHCOS) must disable SSHD service. |
| ☐ | SV-257584r1208209_rule | Red Hat Enterprise Linux CoreOS (RHCOS) must disable USB Storage kernel module. |
| ☐ | SV-257585r960963_rule | Red Hat Enterprise Linux CoreOS (RHCOS) must use USBGuard for hosts that include a USB Controller. |
| ☐ | SV-257586r961863_rule | OpenShift must continuously scan components, containers, and images for vulnerabilities. |
| ☐ | SV-257587r961896_rule | OpenShift must use FIPS-validated SHA-2 or higher hash function for digital signature generation and verification (nonlegacy use). |