Check: SRG-APP-000033-CTR-000100
Container Platform SRG:
SRG-APP-000033-CTR-000100
(in versions v1 r5 through v1 r1)
Title
Least privilege access and need to know must be required to access the container platform keystore. (Cat II impact)
Discussion
The container platform keystore is used to store access keys and tokens for trusted access to and from the container platform. The keystore gives the container platform a method to store the confidential data in a secure way and to encrypt the data when at rest. If this data is not protected through access controls, it can be used to access trusted sources as the container platform breaking the trusted relationship. To circumvent unauthorized access to the keystore, the container platform must have access controls in place to only allow those individuals with keystore duties.
Check Content
Review the container platform to determine if only those individuals with keystore duties have access to the container platform keystore. If users have access to the container platform keystore that do not have keystore duties, this is a finding.
Fix Text
Configure the container platform to use least privilege and need to know when granting access to the container keystore. The fix ensures the proper roles and permissions are configured.
Additional Identifiers
Rule ID: SV-233028r879530_rule
Vulnerability ID: V-233028
Group Title: SRG-APP-000033
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000213 |
The information system enforces approved authorizations for logical access to information and system resources in accordance with applicable access control policies. |
Controls
Number | Title |
---|---|
AC-3 |
Access Enforcement |