Skip to content

I - Mission Critical Classified

Rules and Groups employed by this XCCDF Profile

  • SRG-APP-000026-CTR-000070

    Group
  • Rancher MCM must generate audit records for all DoD-defined auditable events within all components in the platform.

    Audit logs must be enabled. Rancher MCM provides audit record generation capabilities. Audit logs capture what happened, when it happened, who initiated it, and what cluster it affected to ensure ...
    Rule Medium Severity
  • SRG-APP-000028-CTR-000080

    Group
  • When allowed by the central authentication system, the default role assigned to a user must be User-Base.

    Rancher MCM uses roles for authentication. It is necessary to ensure the proper roles and permissions are configured. The role used by default does not ensure least privilege. The default role need...
    Rule Medium Severity
  • SRG-APP-000098-CTR-000185

    Group
  • Rancher MCM must allocate audit record storage and generate audit records associated with events, users, and groups.

    Rancher logging capability and optional aggregation The Rancher server automatically logs everything at the container level. These logs are stored on the system which are then optionally picked up...
    Rule Medium Severity
  • SRG-APP-000234-CTR-000590

    Group
  • Rancher MCM must never automatically remove or disable emergency accounts.

    Emergency accounts are administrator accounts that are established in response to crisis situations where the need for rapid account activation is required. Therefore, emergency account activation ...
    Rule Medium Severity
  • SRG-APP-000645-CTR-001410

    Group
  • Rancher MCM must prohibit or restrict the use of protocols that transmit unencrypted authentication information or use flawed cryptographic algorithms for transmission.

    The container platform and its components will adhere to NIST 800-52R2. To ensure that traffic coming through the ingress controller is re-encrypted internally, switch off port 80 on the service ob...
    Rule High Severity

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules