Check: SRG-APP-000441-CTR-001090
Container Platform SRG:
SRG-APP-000441-CTR-001090
(in versions v1 r5 through v1 r1)
Title
The container platform must maintain the confidentiality and integrity of information during preparation for transmission. (Cat II impact)
Discussion
Information may be unintentionally or maliciously disclosed or modified during preparation for transmission within the container platform during aggregation, at protocol transformation points, and during container image runtime. These unauthorized disclosures or modifications compromise the confidentiality or integrity of the information. When transmitting data, the container platform components need to leverage transmission protection mechanisms, such as TLS, TLS VPNs, or IPsec.
Check Content
Review the documentation and deployed configuration to determine if the container platform maintains the confidentiality and integrity of information during preparation before transmission. If the confidentiality and integrity are not maintained using mechanisms such as TLS, TLS VPNs, or IPsec during preparation before transmission, this is a finding.
Fix Text
Configure the container platform to maintain the confidentiality and integrity of information using mechanisms such as TLS, TLS VPNs, or IPsec during preparation for transmission.
Additional Identifiers
Rule ID: SV-233226r879812_rule
Vulnerability ID: V-233226
Group Title: SRG-APP-000441
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-002420 |
The information system maintains the confidentiality and/or integrity of information during preparation for transmission. |
Controls
Number | Title |
---|---|
SC-8 (2) |
Pre / Post Transmission Handling |