Check: SRG-APP-000089-CTR-000150
Container Platform SRG:
SRG-APP-000089-CTR-000150
(in versions v1 r5 through v1 r1)
Title
The container platform must generate audit records for all DoD-defined auditable events within all components in the platform. (Cat II impact)
Discussion
Within the container platform, audit data can be generated from any of the deployed container platform components. This audit data is important when there are issues, including security incidents that must be investigated. To make the audit data worthwhile for the investigation of events, it is necessary to have the appropriate and required data logged. To handle the need to log DoD-defined auditable events, the container platform must offer a mechanism to change and manage the events that are audited.
Check Content
Review the container platform configuration to determine if the container platform is configured to generate audit records for all DoD-defined auditable events within all components in the platform. Generate DoD-defined auditable events within all the components to determine if the events are being audited. If the container platform is not configured to generate audit records for all DoD-defined auditable events within the components or the events are not generating audit records, this is a finding.
Fix Text
Configure the container platform to generate audit records for all DoD-defined auditable events within all the components of the container platform.
Additional Identifiers
Rule ID: SV-233038r879559_rule
Vulnerability ID: V-233038
Group Title: SRG-APP-000089
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000169 |
The information system provides audit record generation capability for the auditable events defined in AU-2 a. at organization-defined information system components. |
Controls
Number | Title |
---|---|
AU-12 |
Audit Generation |