Skip to content

Commit f08027a

Browse files
authored
Merge pull request #10618 from jhrozek/SRG-APP-000090-CTR-000155
SRG-APP-000090-CTR-000155: No longer Does not Meet, but instead covered by setting the OCP audit profile
2 parents 528a9ad + 40c52c7 commit f08027a

File tree

2 files changed

+3
-17
lines changed

2 files changed

+3
-17
lines changed

applications/openshift/logging/audit_profile_set/rule.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -59,7 +59,7 @@ references:
5959
nist: AU-2,AU-3,AU-3(1),AU-6,AU-6(1),AU-7,AU-7(1),AU-8,AU-8(1),AU-9,AU-12,AU-12(1),AU-12(3),CM-5(1),SI-11,SI-12,SI-4(20),SI-4(23)
6060
pcidss: Req-2.2,Req-12.5.5
6161
pcidss4: "12.1.4"
62-
srg: SRG-APP-000089-CTR-000150,SRG-APP-000101-CTR-000205
62+
srg: SRG-APP-000089-CTR-000150,SRG-APP-000090-CTR-000155,SRG-APP-000101-CTR-000205
6363

6464
ocil_clause: 'The proper audit profile is not set'
6565

controls/srg_ctr/SRG-APP-000090-CTR-000155.yml

Lines changed: 2 additions & 16 deletions
Original file line numberDiff line numberDiff line change
@@ -4,21 +4,7 @@ controls:
44
- medium
55
title: {{{ full_name }}} must allow only the ISSM (or individuals or roles
66
appointed by the ISSM) to select which auditable events are to be audited.
7-
related_rules:
7+
rules:
88
- audit_profile_set
9-
status: does not meet
10-
status_justification: |-
11-
The OpenShift Container Platform records every request/action against the API Server[1]. The platform allows for configuring the verbosity, such as meta-data only, or the entire request body. But, all events are audited, and the ISSM or admins are not able to filter or select only certain event types to be audited.
9+
status: automated
1210

13-
[1] https://docs.openshift.com/container-platform/latest/security/audit-log-policy-config.html
14-
artifact_description: |-
15-
Supporting evidence is in the following documentation
16-
17-
https://docs.openshift.com/container-platform/latest/security/audit-log-policy-config.html
18-
mitigation: |-
19-
All requests to the API Server are audited.
20-
fixtext: |-
21-
This requirement is a permanent finding and cannot be fixed.
22-
check: |-
23-
{{{ full_name }}} does not support this requirement.
24-
This is an applicable-does not meet finding.

0 commit comments

Comments
 (0)