Check: SRG-APP-000233-CTR-000585
Container Platform SRG:
SRG-APP-000233-CTR-000585
(in versions v1 r5 through v1 r1)
Title
The container platform runtime must isolate security functions from non-security functions. (Cat II impact)
Discussion
The container platform runtime must be configured to isolate those services used for security functions from those used for non-security functions. This separation can be performed using environment variables, labels, network segregation, and kernel groups.
Check Content
Verify container platform runtime configuration settings to determine whether container services used for security functions are located in an isolated security function such as a separate environment variables, labels, network segregation, and kernel groups. If security-related functions are not separate, this is a finding.
Fix Text
Configure the container platform runtime to isolate security functions from non-security functions.
Additional Identifiers
Rule ID: SV-233125r879643_rule
Vulnerability ID: V-233125
Group Title: SRG-APP-000233
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-001084 |
The information system isolates security functions from nonsecurity functions. |
Controls
Number | Title |
---|---|
SC-3 |
Security Function Isolation |