Skip to content

Container Platform Security Requirements Guide

Rules, Groups, and Values defined within the XCCDF Benchmark

  • SRG-APP-000454

    <GroupDescription></GroupDescription>
    Group
  • The container platform registry must remove old container images after updating versions have been made available.

    &lt;VulnDiscussion&gt;Obsolete and stale images need to be removed from the registry to ensure the container platform maintains a secure posture. W...
    Rule Medium Severity
  • SRG-APP-000456

    <GroupDescription></GroupDescription>
    Group
  • The container platform registry must contain the latest images with most recent updates and execute within the container platform runtime as authorized by IAVM, CTOs, DTMs, and STIGs.

    &lt;VulnDiscussion&gt;Software supporting the container platform, images in the registry must stay up to date with the latest patches, service pack...
    Rule Medium Severity
  • SRG-APP-000456

    <GroupDescription></GroupDescription>
    Group
  • SRG-APP-000493

    <GroupDescription></GroupDescription>
    Group
  • The container platform must generate audit records when successful/unsuccessful attempts to modify categories of information (e.g., classification levels) occur.

    &lt;VulnDiscussion&gt;Without generating audit records that are specific to the security and mission needs of the organization, it would be difficu...
    Rule Medium Severity
  • The container platform runtime must have updates installed within the time period directed by an authoritative source (e.g., IAVM, CTOs, DTMs, and STIGs).

    &lt;VulnDiscussion&gt;The container platform runtime must be carefully monitored for vulnerabilities, and when problems are detected, they must be ...
    Rule Medium Severity
  • SRG-APP-000472

    <GroupDescription></GroupDescription>
    Group
  • The organization-defined role must verify correct operation of security functions in the container platform.

    &lt;VulnDiscussion&gt;Without verification, security functions may not operate correctly and this failure may go unnoticed within the container pla...
    Rule Medium Severity

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules