Check: SRG-APP-000148-CTR-000345
Container Platform SRG:
SRG-APP-000148-CTR-000345
(in versions v1 r5 through v1 r1)
Title
The container platform must uniquely identify and authenticate processes acting on behalf of the users. (Cat II impact)
Discussion
The container platform will instantiate a container image and use the user privileges given to the user used to execute the container. To ensure accountability and prevent unauthenticated access to containers, the user the container is using to execute must be uniquely identified and authenticated to prevent potential misuse and compromise of the system.
Check Content
Review the container platform configuration to determine if processes acting on behalf of users are uniquely identified and authenticated. If processes acting on behalf of users are not uniquely identified or are not authenticated, this is a finding.
Fix Text
Configure the container platform to uniquely identify and authenticate processes acting on behalf of users.
Additional Identifiers
Rule ID: SV-233077r879589_rule
Vulnerability ID: V-233077
Group Title: SRG-APP-000148
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000764 |
The information system uniquely identifies and authenticates organizational users (or processes acting on behalf of organizational users). |
Controls
Number | Title |
---|---|
IA-2 |
Identification And Authentication (Organizational Users) |