Check: SRG-APP-000133-CTR-000295
Container Platform SRG:
SRG-APP-000133-CTR-000295
(in versions v1 r5 through v1 r1)
Title
The container platform must limit privileges to the container platform runtime. (Cat II impact)
Discussion
To control what is instantiated within the container platform, it is important to control access to the runtime. Without this control, container platform specific services and customer services can be introduced without receiving approval and going through proper testing. Only those individuals and roles approved by the organization can have access to the container platform runtime.
Check Content
Review the container platform runtime configuration to determine if the level of access to the runtime is controlled through user privileges. Attempt to perform runtime operations to determine if the privileges are enforced. If the container platform runtime is not limited through user privileges or the user privileges are not enforced, this is a finding.
Fix Text
Configure the container platform to use and enforce user privileges when accessing the container platform runtime.
Additional Identifiers
Rule ID: SV-233067r879586_rule
Vulnerability ID: V-233067
Group Title: SRG-APP-000133
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-001499 |
The organization limits privileges to change software resident within software libraries. |
Controls
Number | Title |
---|---|
CM-5 (6) |
Limit Library Privileges |