The container platform keystore must implement encryption to prevent unauthorized disclosure of information at rest within the container platform.
Overview
Finding ID
Version
Rule ID
IA Controls
Severity
V-233220
SRG-APP-000429-CTR-001060
SV-233220r1050650_rule
High
Description
Container platform keystore is used for container deployments for persistent storage of all its REST API objects. These objects are sensitive in nature and should be encrypted at rest to avoid any unauthorized disclosure. Selection of a cryptographic mechanism is based on the need to protect the confidentiality of organizational information. The strength of mechanism is commensurate with the security category and/or classification of the information.