Skip to content

Prisma Cloud Compute must run within a defined/separate namespace (e.g., Twistlock).

An XCCDF Rule

Description

<VulnDiscussion>Namespaces are a key boundary for network policies, orchestrator access control restrictions, and other important security controls. Prisma Cloud Compute containers running within a separate and exclusive namespace will inherit the namespace's security features. Separating workloads into namespaces can help contain attacks and limit the impact of mistakes or destructive actions by authorized users.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls>

ID
SV-253547r961608_rule
Severity
Medium
References
Updated



Remediation - Manual Procedure

Deploy the Prisma Cloud Compute Console and Defender containers within a distinct namespace.