The container platform must limit privileges to the container platform registry.
Overview
Finding ID
Version
Rule ID
IA Controls
Severity
V-233066
SRG-APP-000133-CTR-000290
SV-233066r960960_rule
Medium
Description
To control what is instantiated within the container platform, it is important to control access to the registry. Without this control, container images can be introduced and instantiated by accident or on container platform startup. Without control of the registry, security measures put in place for the runtime can be bypassed meaning the controls of approval and testing are also bypassed. Only those individuals and roles approved by the organization can have access to the container platform registry.