Check: SRG-APP-000450-CTR-001105
Container Platform SRG:
SRG-APP-000450-CTR-001105
(in versions v1 r5 through v1 r1)
Title
The container platform must implement organization-defined security safeguards to protect system CPU and memory from resource depletion and unauthorized code execution. (Cat II impact)
Discussion
The execution of images within the container platform runtime must implement organizational defined security safeguards to prevent distributed denial-of-service (DDOS) and other possible attacks against the container image at runtime. Security safeguards employed to protect memory and CPU include, for example, data execution prevention and address space layout randomization. Data execution prevention safeguards can be software-enforced. Other means of protection are to limit memory and CPU resources to a container.
Check Content
Review the container platform configuration to determine if safeguards are in place to protect the system memory and CPU from resource depletion and unauthorized execution. If safeguards are not in place, this is a finding.
Fix Text
Configure the container platform to have safeguards in place to protect the system memory and CPU from resource depletion and unauthorized code execution.
Additional Identifiers
Rule ID: SV-233229r879821_rule
Vulnerability ID: V-233229
Group Title: SRG-APP-000450
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-002824 |
The information system implements organization-defined security safeguards to protect its memory from unauthorized code execution. |
Controls
Number | Title |
---|---|
SI-16 |
Memory Protection |