Skip to content

The container platform must be built from verified packages.

An XCCDF Rule

Description

It is important to patch and upgrade the container platform when patches and upgrades are available. More important is to get these patches and upgrades from a known source. To validate the authenticity of any patches and upgrades before installation, the container platform must check that the files are digitally signed by sources approved by the organization.

ID
SV-233064r981843_rule
Version
SRG-APP-000131-CTR-000280
Severity
Medium
References
Updated

Remediation Templates

A Manual Procedure

Rebuild the container platform from verified packages that are digitally signed by known and approved sources.