Check: SRG-APP-000409-CTR-000990
Container Platform SRG:
SRG-APP-000409-CTR-000990
(in versions v1 r5 through v1 r1)
Title
The container platform must audit non-local maintenance and diagnostic sessions' organization-defined audit events associated with non-local maintenance. (Cat II impact)
Discussion
To fully investigate an attack, it is important to understand the event and those events taking place during the same time period. Often, non-local administrative access and diagnostic sessions are not logged. These events are seen as only administrative functions and not worthy of being audited, but these events are important in any investigation and are a major tool for assessing and investigating attacks.
Check Content
Review the container platform to verify if the platform is auditing non-local maintenance and diagnostic sessions' organization-defined audit events. If the container platform is not auditing non-local maintenance and diagnostic sessions' organization-defined audit events, this is a finding.
Fix Text
Configure the container platform to audit non-local maintenance and diagnostic sessions' organization-defined audit events.
Additional Identifiers
Rule ID: SV-233206r879782_rule
Vulnerability ID: V-233206
Group Title: SRG-APP-000409
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-002884 |
The organization audits nonlocal maintenance and diagnostic sessions^ organization-defined audit events. |
Controls
Number | Title |
---|---|
MA-4 (1) |
Auditing And Review |