Check: SRG-APP-000111-CTR-000220
Container Platform SRG:
SRG-APP-000111-CTR-000220
(in versions v1 r5 through v1 r1)
Title
The container platform components must provide the ability to send audit logs to a central enterprise repository for review and analysis. (Cat II impact)
Discussion
The container platform components must send audit events to a central managed audit log repository to provide reporting, analysis, and alert notification. Incident response relies on successful timely, accurate system analysis in order for the organization to identify and respond to possible security events.
Check Content
Review the configuration settings to determine if the container platform components are configured to send audit events to central managed audit log repository. If the container platform is not configured to send audit events to central managed audit log repository, this is a finding.
Fix Text
Configure the container platform components to send audit logs to a central managed audit log repository.
Additional Identifiers
Rule ID: SV-233052r879572_rule
Vulnerability ID: V-233052
Group Title: SRG-APP-000111
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000154 |
The information system provides the capability to centrally review and analyze audit records from multiple components within the system. |
Controls
Number | Title |
---|---|
AU-6 (4) |
Central Review And Analysis |