The container platform keystore must implement encryption to prevent unauthorized disclosure of information at rest within the container platform.

Overview

Finding IDVersionRule IDIA ControlsSeverity
V-233220SRG-APP-000429-CTR-001060SV-233220r1050650_ruleCCI-002476high
Description
Container platform keystore is used for container deployments for persistent storage of all its REST API objects. These objects are sensitive in nature and should be encrypted at rest to avoid any unauthorized disclosure. Selection of a cryptographic mechanism is based on the need to protect the confidentiality of organizational information. The strength of mechanism is commensurate with the security category and/or classification of the information.
STIGDate
Container Platform Security Requirements Guide2025-09-10

Related Frameworks

6 paths across 3 frameworks
SCF4 mappings
BCD-11.4Cryptographic Protection
0.50
  • DISA · V2R4 · disa_xccdf · related
  • DISA · 2025-01-23 · disa_cci_list · equivalent
  • Secure Controls Framework · 2026.2 · scf_strm · related
CRY-04Transmission Integrity
0.50
  • DISA · V2R4 · disa_xccdf · related
  • DISA · 2025-01-23 · disa_cci_list · equivalent
  • Secure Controls Framework · 2026.2 · scf_strm · related
CRY-05Encrypting Data At Rest
0.50
  • DISA · V2R4 · disa_xccdf · related
  • DISA · 2025-01-23 · disa_cci_list · equivalent
  • Secure Controls Framework · 2026.2 · scf_strm · related
DCH-07.2Encrypting Data In Storage Media
0.50
  • DISA · V2R4 · disa_xccdf · related
  • DISA · 2025-01-23 · disa_cci_list · equivalent
  • Secure Controls Framework · 2026.2 · scf_strm · related
NIST 800-531 mapping
  • DISA · V2R4 · disa_xccdf · related
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI1 mapping
CCI-002476
1.00
  • DISA · V2R4 · disa_xccdf · related

Details

Check Text (C-233220r1050650_chk)

Review container platform keystore documentation and configuration to verify encryption levels meet the information sensitivity level. If the container platform keystore encryption configuration does not meet system requirements, this is a finding.

Fix Text (F-36124r601148_fix)

Configure the container platform keystore encryption to maintain the confidentiality and integrity of information for applicable sensitivity level.