The container platform must implement the capability to centrally review and analyze audit records from multiple components within the system.

STIG ID: SRG-APP-000745-CTR-000120  |  SRG: SRG-APP-000745 |  Severity: medium |  CCI: CCI-003821 |  Vulnerability Id: V-263587

Vulnerability Discussion

Automated mechanisms for centralized reviews and analyses include Security Information and Event Management products.

Check

Verify the container platform is configured to implement the capability to centrally review and analyze audit records from multiple components within the system.

If the container platform is not configured to implement the capability to centrally review and analyze audit records from multiple components within the system, this is a finding.

Fix

Configure the container platform to implement the capability to centrally review and analyze audit records from multiple components within the system.