UCF STIG Viewer Logo

The container platform must be able to store and instantiate industry standard container images.


Overview

Finding ID Version Rule ID IA Controls Severity
V-233274 SRG-APP-000516-CTR-001330 SV-233274r601854_rule Medium
Description
Monitoring the container images and containers during their lifecycle is important to guarantee the container platform is secure. To monitor the containers and images, security tools can be put in place. To fully utilize the security tools available, using images formatted in an industry standard format should be used. This allows the tools to fully understand the images and containers. One standard being worked on by industry leaders in the container space is the Open Container Initiative (OCI). This group is developing a standard container image format.
STIG Date
Container Platform Security Requirements Guide 2021-12-14

Details

Check Text ( C-36210r601887_chk )
Review the container platform configuration and documentation to determine if the platform is configured to store and instantiate industry standard container images.

If the container platform cannot instantiate industry standard container images, this is a finding.
Fix Text (F-36178r601310_fix)
Enable the container platform to store and instantiate industry standard container image formats.