Check: SRG-APP-000516-CTR-001335
Container Platform SRG:
SRG-APP-000516-CTR-001335
(in versions v1 r5 through v1 r1)
Title
The container platform must continuously scan components, containers, and images for vulnerabilities. (Cat II impact)
Discussion
Finding vulnerabilities quickly within the container platform and within containers deployed within the platform is important to keep the overall platform secure. When a vulnerability within a component or container is unknown or allowed to remain unpatched, other containers and customers within the platform become vulnerability. The vulnerability can lead to the loss of application data, organizational infrastructure data, and denial of service (DoS) to hosted applications. Vulnerability scanning can be performed by the container platform or by external applications.
Check Content
Review the container platform to validate continuous vulnerability scans of components, containers, and container images are being performed. If continuous vulnerability scans are not being performed, this is a finding.
Fix Text
Implement continuous vulnerability scans of container platform components, containers, and container images either by the container platform or from external vulnerability scanning applications.
Additional Identifiers
Rule ID: SV-233275r879887_rule
Vulnerability ID: V-233275
Group Title: SRG-APP-000516
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000366 |
The organization implements the security configuration settings. |
Controls
Number | Title |
---|---|
CM-6 |
Configuration Settings |