All audit records must identify what type of event has occurred within the container platform.
Overview
| Finding ID | Version | Rule ID | IA Controls | Severity |
| V-233042 | SRG-APP-000095-CTR-000170 | SV-233042r960891_rule | CCI-000130 | medium |
| Description | ||||
| Within the container platform, audit data can be generated from any of the deployed container platform components. This audit data is important when there are issues, such as security incidents, that must be investigated. To make the audit data worthwhile for the investigation of events, it is necessary to know what type of event occurred. | ||||
| STIG | Date | |||
| Container Platform Security Requirements Guide | 2025-05-15 | |||
Related Frameworks
4 paths across 3 frameworks
Related Frameworks
NIST 800-531 mapping
AU-3
1.00
- DISA · 2 · disa_xccdf · related
- DISA · 2025-01-23 · disa_cci_list · equivalent
NIST 800-1712 mappings
3.3.1
1.00
- DISA · 2 · disa_xccdf · related
- DISA · 2025-01-23 · disa_cci_list · equivalent
- NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
3.3.2
1.00
- DISA · 2 · disa_xccdf · related
- DISA · 2025-01-23 · disa_cci_list · equivalent
- NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
CCI1 mapping
CCI-000130
1.00
- DISA · 2 · disa_xccdf · related
Details
Check Text (C-233042r960891_chk)
Review the container platform configuration for audit event types. Ensure audit policy for event type is enabled.
Verify records showing what type of event occurred are written to the log.
Validate system documentation is current.
If log data does not show the type of event, this is a finding.
Fix Text (F-35946r600614_fix)
Configure the container platform to include the event type in the log data. Revise all applicable system documentation.