Check: SRG-APP-000126-CTR-000275
Container Platform SRG:
SRG-APP-000126-CTR-000275
(in versions v1 r5 through v1 r1)
Title
The container platform must use FIPS validated cryptographic mechanisms to protect the integrity of log information. (Cat II impact)
Discussion
To fully investigate an incident and to have trust in the audit data that is generated, it is important to put in place data protections. Without integrity protections, unauthorized changes may be made to the audit files and reliable forensic analysis and discovery of the source of malicious system activity may be degraded. Although digital signatures are one example of protecting integrity, this control is not intended to cause a new cryptographic hash to be generated every time a record is added to a log file. Integrity protections can also be implemented by using cryptographic techniques for security function isolation and file system protections to protect against unauthorized changes.
Check Content
Review the container platform configuration to determine if FIPS-validated cryptographic mechanisms are being used to protect the integrity of log information. If FIPS-validated cryptographic mechanisms are not being used to protect the integrity of log information, this is a finding.
Fix Text
Configure the container platform to use FIPS-validated cryptographic mechanisms to protect the integrity of log information.
Additional Identifiers
Rule ID: SV-233063r879583_rule
Vulnerability ID: V-233063
Group Title: SRG-APP-000126
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-001350 |
The information system implements cryptographic mechanisms to protect the integrity of audit information. |
Controls
Number | Title |
---|---|
AU-9 (3) |
Cryptographic Protection |