Prisma Cloud Compute must run within a defined/separate namespace (e.g., Twistlock).
An XCCDF Rule
Description
Namespaces are a key boundary for network policies, orchestrator access control restrictions, and other important security controls. Prisma Cloud Compute containers running within a separate and exclusive namespace will inherit the namespace's security features. Separating workloads into namespaces can help contain attacks and limit the impact of mistakes or destructive actions by authorized users.
- ID
- SV-253547r961608_rule
- Version
- CNTR-PC-001380
- Severity
- Medium
- References
- Updated
Remediation Templates
A Manual Procedure
Deploy the Prisma Cloud Compute Console and Defender containers within a distinct namespace.