Skip to content

I - Mission Critical Public

Rules and Groups employed by this XCCDF Profile

  • SSH must not run within Linux containers.

    <VulnDiscussion>To limit the attack surface of MKE, it is important that the nonessential services are not installed. Containers are designed...
    Rule Medium Severity
  • SRG-APP-000033-CTR-000100

    <GroupDescription></GroupDescription>
    Group
  • Swarm Secrets or Kubernetes Secrets must be used.

    &lt;VulnDiscussion&gt;Swarm Secrets in Docker Swarm and Kubernetes Secrets both provide mechanisms for encrypting sensitive data at rest. This adds...
    Rule Medium Severity
  • SRG-APP-000038-CTR-000105

    <GroupDescription></GroupDescription>
    Group
  • MKE must have Grants created to control authorization to cluster resources.

    &lt;VulnDiscussion&gt;MKE uses Role-Based Access Controls (RBAC) to enforce approved authorizations for logical access to information and system re...
    Rule Medium Severity

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules