UCF STIG Viewer Logo
Changes are coming to https://stigviewer.com. Take our survey to help us understand your usage and how we can better serve you in the future.
Take Survey

The container platform runtime must isolate security functions from non-security functions.


Overview

Finding ID Version Rule ID IA Controls Severity
V-233125 SRG-APP-000233-CTR-000585 SV-233125r879643_rule Medium
Description
The container platform runtime must be configured to isolate those services used for security functions from those used for non-security functions. This separation can be performed using environment variables, labels, network segregation, and kernel groups.
STIG Date
Container Platform Security Requirements Guide 2023-11-30

Details

Check Text ( C-36061r601750_chk )
Verify container platform runtime configuration settings to determine whether container services used for security functions are located in an isolated security function such as a separate environment variables, labels, network segregation, and kernel groups.

If security-related functions are not separate, this is a finding.
Fix Text (F-36029r600863_fix)
Configure the container platform runtime to isolate security functions from non-security functions.