UCF STIG Viewer Logo
Changes are coming to https://stigviewer.com. Take our survey to help us understand your usage and how we can better serve you in the future.
Take Survey

Least privilege access and need to know must be required to access the container platform runtime.


Overview

Finding ID Version Rule ID IA Controls Severity
V-233027 SRG-APP-000033-CTR-000095 SV-233027r960792_rule Medium
Description
The container platform runtime is used to instantiate containers. If this process is accessed by those persons who are not authorized, those containers offering services can be brought to a denial of service (DoS) situation, disabling a large number of services with a small change to the container platform. To limit this threat, it is important to limit access to the runtime to only those individuals with runtime duties.
STIG Date
Container Platform Security Requirements Guide 2024-05-28

Details

Check Text ( C-35963r600568_chk )
Review the container platform to determine if only those individuals with runtime duties have access to the container platform runtime.

If users have access to the container platform runtime that do not have runtime duties, this is a finding.
Fix Text (F-35931r600569_fix)
Configure the container platform to use least privilege and need to know when granting access to the container runtime. The fix ensures the proper roles and permissions are configured.