Check: SRG-APP-000429-CTR-001060
Container Platform SRG:
SRG-APP-000429-CTR-001060
(in versions v1 r5 through v1 r1)
Title
The container platform keystore must implement encryption to prevent unauthorized disclosure of information at rest within the container platform. (Cat II impact)
Discussion
Container platform keystore is used for container deployments for persistent storage of all its REST API objects. These objects are sensitive in nature and should be encrypted at rest to avoid any unauthorized disclosure. Selection of a cryptographic mechanism is based on the need to protect the confidentiality of organizational information. The strength of mechanism is commensurate with the security category and/or classification of the information.
Check Content
Review container platform keystore documentation and configuration to verify encryption levels meet the information sensitivity level. If the container platform keystore encryption configuration does not meet system requirements, this is a finding.
Fix Text
Configure the container platform keystore encryption to maintain the confidentiality and integrity of information for applicable sensitivity level.
Additional Identifiers
Rule ID: SV-233220r879800_rule
Vulnerability ID: V-233220
Group Title: SRG-APP-000429
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-002476 |
The information system implements cryptographic mechanisms to prevent unauthorized disclosure of organization-defined information at rest on organization-defined information system components. |
Controls
Number | Title |
---|---|
SC-28 (1) |
Cryptographic Protection |