The container platform must map the authenticated identity to the individual user or group account for PKI-based authentication.

Overview

Finding IDVersionRule IDIA ControlsSeverity
V-233101SRG-APP-000177-CTR-000465SV-233101r961044_ruleCCI-000187medium
Description
The container platform and its components may require authentication before use. When the authentication is PKI-based, the container platform or component must map the certificate to a user account. If the certificate is not mapped to a user account, the ability to determine the identity of the individual user or group will not be available for forensic analysis.
STIGDate
Container Platform Security Requirements Guide2025-09-10

Related Frameworks

3 paths across 3 frameworks
SCF1 mapping
IAC-10.2PKI-Based Authentication
1.00
  • DISA · V2R4 · disa_xccdf · related
  • DISA · 2025-01-23 · disa_cci_list · equivalent
  • Secure Controls Framework · 2026.2 · scf_strm · equivalent
NIST 800-531 mapping
  • DISA · V2R4 · disa_xccdf · related
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI1 mapping
CCI-000187
1.00
  • DISA · V2R4 · disa_xccdf · related

Details

Check Text (C-233101r961044_chk)

Review documentation and configuration to ensure the container platform provides a PKI integration capability that meets DoD PKI infrastructure requirements. If the container platform is not configured to meet this requirement, this is a finding.

Fix Text (F-36005r600791_fix)

Configure the container platform to utilize the DoD Enterprise PKI infrastructure.