Check: SRG-APP-000033-CTR-000095
Container Platform SRG:
SRG-APP-000033-CTR-000095
(in versions v1 r5 through v1 r1)
Title
Least privilege access and need to know must be required to access the container platform runtime. (Cat II impact)
Discussion
The container platform runtime is used to instantiate containers. If this process is accessed by those persons who are not authorized, those containers offering services can be brought to a denial of service (DoS) situation, disabling a large number of services with a small change to the container platform. To limit this threat, it is important to limit access to the runtime to only those individuals with runtime duties.
Check Content
Review the container platform to determine if only those individuals with runtime duties have access to the container platform runtime. If users have access to the container platform runtime that do not have runtime duties, this is a finding.
Fix Text
Configure the container platform to use least privilege and need to know when granting access to the container runtime. The fix ensures the proper roles and permissions are configured.
Additional Identifiers
Rule ID: SV-233027r879530_rule
Vulnerability ID: V-233027
Group Title: SRG-APP-000033
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000213 |
The information system enforces approved authorizations for logical access to information and system resources in accordance with applicable access control policies. |
Controls
Number | Title |
---|---|
AC-3 |
Access Enforcement |