Check: SRG-APP-000131-CTR-000280
Container Platform SRG:
SRG-APP-000131-CTR-000280
(in versions v1 r5 through v1 r1)
Title
The container platform must be built from verified packages. (Cat II impact)
Discussion
It is important to patch and upgrade the container platform when patches and upgrades are available. More important is to get these patches and upgrades from a known source. To validate the authenticity of any patches and upgrades before installation, the container platform must check that the files are digitally signed by sources approved by the organization.
Check Content
Review the container platform configuration to verify it has been built from packages that are digitally signed by known and approved sources. If the container platform was built from packages that are not digitally signed or are from unknown or non-approved sources, this is a finding.
Fix Text
Rebuild the container platform from verified packages that are digitally signed by known and approved sources.
Additional Identifiers
Rule ID: SV-233064r879584_rule
Vulnerability ID: V-233064
Group Title: SRG-APP-000131
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-001749 |
The information system prevents the installation of organization-defined software components without verification the software component has been digitally signed using a certificate that is recognized and approved by the organization. |
Controls
Number | Title |
---|---|
CM-5 (3) |
Signed Components |