Check: SRG-APP-000099-CTR-000190
Container Platform SRG:
SRG-APP-000099-CTR-000190
(in versions v1 r5 through v1 r1)
Title
All audit records must generate the event results within the container platform. (Cat II impact)
Discussion
Within the container platform, audit data can be generated from any of the deployed container platform components. This audit data is important when there are issues, such as security incidents, that must be investigated. To make the audit data worthwhile for the investigation of events, it is necessary to know the outcome of the event.
Check Content
Review the container platform configuration to determine if audit records contain the audit event results. Generate audit records and review the data to validate that the record does contain the event result. If the container platform is not configured to generate audit records with the event result or the audit record does not contain the event result, this is a finding.
Fix Text
Configure the container platform to generate audit records that contain the event result.
Additional Identifiers
Rule ID: SV-233046r879567_rule
Vulnerability ID: V-233046
Group Title: SRG-APP-000099
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000134 |
The information system generates audit records containing information that establishes the outcome of the event. |
Controls
Number | Title |
---|---|
AU-3 |
Content Of Audit Records |