STIGQter STIGQter: STIG Summary:

Red Hat OpenShift Container Platform 4.x Security Technical Implementation Guide

Version: 2

Release: 6 Benchmark Date: 01 Jul 2026

CheckedNameTitle
SV-257505r960759_ruleOpenShift must use TLS 1.2 or greater for secure container image transport from trusted sources.
SV-257506r960759_ruleOpenShift must use TLS 1.2 or greater for secure communication.
SV-257507r1043176_ruleOpenShift must use a centralized user management solution to support account management functions.
SV-257508r1043176_ruleThe kubeadmin account must be disabled.
SV-257509r960777_ruleOpenShift must automatically audit account creation.
SV-257510r960780_ruleOpenShift must automatically audit account modification.
SV-257511r1015792_ruleOpenShift must generate audit rules to capture account related actions.
SV-257512r960786_ruleOpen Shift must automatically audit account removal actions.
SV-257513r1156752_ruleOpenShift role-based access controls (RBAC) must be enforced.
SV-257514r1208195_ruleOpenShift must enforce network policy on the namespace for controlling the flow of information within the container platform based on organization-defined information flow control policies.
SV-257515r1208198_ruleOpenShift must enforce approved authorizations for controlling the flow of information within the container platform based on organization-defined information flow control policies.
SV-257516r960843_ruleOpenShift must display the Standard Mandatory DOD Notice and Consent Banner before granting access to platform components.
SV-257517r1208201_ruleOpenShift must generate audit records for all DOD-defined auditable events within all components in the platform.
SV-257518r1050653_ruleOpenShift must generate audit records when successful/unsuccessful attempts to access privileges occur.
SV-257519r960888_ruleRed Hat Enterprise Linux CoreOS (RHCOS) must initiate session audits at system startup.
SV-257520r960891_ruleAll audit records must identify what type of event has occurred within OpenShift.
SV-257521r960894_ruleOpenShift audit records must have a date and time association with all events.
SV-257522r960903_ruleAll audit records must generate the event results within OpenShift.
SV-257523r1050555_ruleOpenShift must take appropriate action upon an audit failure.
SV-257524r960918_ruleOpenShift components must provide the ability to send audit logs to a central enterprise repository for review and analysis.
SV-257525r960927_ruleOpenShift must use internal system clocks to generate audit record time stamps.
SV-257526r960927_ruleThe Red Hat Enterprise Linux CoreOS (RHCOS) chrony Daemon must use multiple NTP servers to generate audit record time stamps.
SV-257527r960930_ruleOpenShift must protect audit logs from any type of unauthorized access.
SV-257528r960930_ruleOpenShift must protect system journal file from any type of unauthorized access by setting file permissions.
SV-257529r960930_ruleOpenShift must protect system journal file from any type of unauthorized access by setting owner permissions.
SV-257530r960930_ruleOpenShift must protect log directory from any type of unauthorized access by setting file permissions.
SV-257531r960930_ruleOpenShift must protect log directory from any type of unauthorized access by setting owner permissions.
SV-257532r960930_ruleOpenShift must protect pod log files from any type of unauthorized access by setting owner permissions.
SV-257533r960933_ruleOpenShift must protect audit information from unauthorized modification.
SV-257534r960939_ruleOpenShift must prevent unauthorized changes to logon UIDs.
SV-257535r960939_ruleOpenShift must protect audit tools from unauthorized access.
SV-257536r960951_ruleOpenShift must use FIPS-validated cryptographic mechanisms to protect the integrity of log information.
SV-257537r1015794_ruleOpenShift must verify container images.
SV-257538r960963_ruleOpenShift must contain only container images for those capabilities being offered by the container platform.
SV-257539r1043177_ruleOpenShift runtime must enforce ports, protocols, and services that adhere to the PPSM CAL.
SV-257540r1156731_ruleOpenShift must disable root and terminate network connections.
SV-257541r960972_ruleOpenShift must use multifactor authentication for network access to accounts.
SV-257542r960993_ruleOpenShift must use FIPS-validated SHA-1 or higher hash function to provide replay-resistant authentication mechanisms for network access to privileged accounts.
SV-257543r1015795_ruleOpenShift must use FIPS validated LDAP or OpenIDConnect.
SV-257544r1015796_ruleOpenShift must terminate all network connections associated with a communications session at the end of the session, or as follows: for in-band management sessions (privileged sessions), the session must be terminated after 10 minutes of inactivity.
SV-257545r1208204_ruleOpenShift must separate user functionality (including user interface services) from information system management functionality.
SV-257546r1043178_ruleOpenShift must protect authenticity of communications sessions with the use of FIPS-validated 140-2 or 140-3 validated cryptography.
SV-257547r961131_ruleOpenShift runtime must isolate security functions from nonsecurity functions.
SV-257548r1156737_ruleOpenShift must prevent unauthorized and unintended information transfer via shared system resources and enable page poisoning.
SV-257549r1137645_ruleOpenShift must disable virtual syscalls.
SV-257550r1137645_ruleOpenShift must enable poisoning of SLUB/SLAB objects.
SV-257551r1137645_ruleOpenShift must set the sticky bit for world-writable directories.
SV-257552r1137645_ruleOpenShift must restrict access to the kernel buffer.
SV-257553r1137645_ruleOpenShift must prevent kernel profiling.
SV-257554r961152_ruleOpenShift must restrict individuals the ability to launch organizational-defined Denial-of-Service (DOS) attacks against other information systems by setting a default Resource Quota.
SV-257555r1208206_ruleOpenShift must restrict individuals' ability to launch organization-defined denial-of-service (DOS) attacks against other information systems by rate-limiting.
SV-257556r961227_ruleOpenShift must display an explicit logout message indicating the reliable termination of authenticated communication sessions.
SV-257557r961359_ruleContainer images instantiated by OpenShift must execute using least privileges.
SV-257558r961392_ruleRed Hat Enterprise Linux CoreOS (RHCOS) must allocate audit record storage capacity to store at least one weeks' worth of audit records, when audit records are not immediately sent to a central audit record storage facility.
SV-257559r961401_ruleOpenShift must configure Alert Manger Receivers to notify SA and ISSO of all audit failure events requiring real-time alerts.
SV-257560r1015797_ruleOpenShift must enforce access restrictions and support auditing of the enforcement actions.
SV-257561r1156740_ruleOpenShift must prevent the installation of patches, service packs, device drivers, or operating system components without verification they have been digitally signed using a certificate that is recognized and approved by the organization.
SV-257562r961521_ruleOpenShift must set server token max age no greater than eight hours.
SV-257563r961563_ruleVulnerability scanning applications must implement privileged access authorization to all OpenShift components, containers, and container images for selected organization-defined vulnerability scanning activities.
SV-257564r1050650_ruleOpenShift keystore must implement encryption to prevent unauthorized disclosure of information at rest within the container platform.
SV-257565r961620_ruleOpenShift must protect against or limit the effects of all types of Denial-of-Service (DoS) attacks by employing organization-defined security safeguards by including a default resource quota.
SV-257566r961620_ruleOpenShift must protect against or limit the effects of all types of Denial-of-Service (DoS) attacks by defining resource quotas on a namespace.
SV-257567r961632_ruleOpenShift must protect the confidentiality and integrity of transmitted information.
SV-257568r961665_ruleRed Hat Enterprise Linux CoreOS (RHCOS) must implement nonexecutable data to protect its memory from unauthorized code execution.
SV-257569r961665_ruleRed Hat Enterprise Linux CoreOS (RHCOS) must implement ASLR (Address Space Layout Randomization) from unauthorized code execution.
SV-257570r961677_ruleOpenShift must remove old components after updated versions have been installed.
SV-257571r1137649_ruleOpenShift must contain the latest images with most recent updates and execute within the container platform runtime as authorized by IAVM, CTOs, DTMs, and STIGs.
SV-257572r1137650_ruleOpenShift runtime must have updates installed within the period directed by an authoritative source (e.g., IAVM, CTOs, DTMs, and STIGs).
SV-257573r961731_ruleThe Compliance Operator must be configured.
SV-257574r961734_ruleOpenShift must perform verification of the correct operation of security functions: upon startup and/or restart; upon command by a user with privileged access; and/or every 30 days.
SV-257575r961800_ruleOpenShift must generate audit records when successful/unsuccessful attempts to modify privileges occur.
SV-257576r961803_ruleOpenShift must generate audit records when successful/unsuccessful attempts to modify security objects occur.
SV-257577r961812_ruleOpenShift must generate audit records when successful/unsuccessful attempts to delete privileges occur.
SV-257578r961818_ruleOpenShift must generate audit records when successful/unsuccessful attempts to delete security objects occur.
SV-257579r961824_ruleOpenShift must generate audit records when successful/unsuccessful logon attempts occur.
SV-257580r961827_ruleRed Hat Enterprise Linux CoreOS (RHCOS) must be configured to audit the loading and unloading of dynamic kernel modules.
SV-257581r961830_ruleOpenShift audit records must record user access start and end times.
SV-257582r961833_ruleOpenShift must generate audit records when concurrent logons from different workstations and systems occur.
SV-257583r960963_ruleRed Hat Enterprise Linux CoreOS (RHCOS) must disable SSHD service.
SV-257584r1208209_ruleRed Hat Enterprise Linux CoreOS (RHCOS) must disable USB Storage kernel module.
SV-257585r960963_ruleRed Hat Enterprise Linux CoreOS (RHCOS) must use USBGuard for hosts that include a USB Controller.
SV-257586r961863_ruleOpenShift must continuously scan components, containers, and images for vulnerabilities.
SV-257587r961896_ruleOpenShift must use FIPS-validated SHA-2 or higher hash function for digital signature generation and verification (nonlegacy use).