Skip to content

Palo Alto Networks Prisma Cloud Compute Security Technical Implementation Guide

Rules, Groups, and Values defined within the XCCDF Benchmark

  • Images stored within the container registry must contain only images to be run as containers within the container platform.

    <VulnDiscussion>The Prisma Cloud Compute Trusted Images feature allows the declaration, by policy, of which registries, repositories, and ima...
    Rule Medium Severity
  • SRG-APP-000142-CTR-000330

    <GroupDescription></GroupDescription>
    Group
  • Prisma Cloud Compute must use TCP ports above 1024.

    &lt;VulnDiscussion&gt;Privileged ports are ports below 1024 that require system privileges for their use. If containers are able to use these ports...
    Rule Medium Severity
  • SRG-APP-000148-CTR-000335

    <GroupDescription></GroupDescription>
    Group
  • Prisma Cloud Compute release tar distributions must have an associated SHA-256 digest.

    &lt;VulnDiscussion&gt;Each Prisma Cloud Compute release's tar file has an associated SHA-256 digest hash value to ensure the components have not be...
    Rule Medium Severity
  • Prisma Cloud Compute local accounts must enforce strong password requirements.

    &lt;VulnDiscussion&gt;Use of a complex password helps to increase the time and resources required to compromise the password. Password complexity, ...
    Rule Medium Severity
  • SRG-APP-000177-CTR-000465

    <GroupDescription></GroupDescription>
    Group
  • Prisma Cloud Compute must be configured to require local user accounts to use x.509 multifactor authentication.

    &lt;VulnDiscussion&gt;Without the use of multifactor authentication, the ease of access to privileged functions is greatly increased. Multifactor ...
    Rule Medium Severity
  • SRG-APP-000243-CTR-000595

    <GroupDescription></GroupDescription>
    Group
  • Prisma Cloud Compute must prevent unauthorized and unintended information transfer.

    &lt;VulnDiscussion&gt;Prisma Cloud Compute Compliance policies must be enabled to ensure running containers do not access privileged resources. Sa...
    Rule Medium Severity

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules