Uploaded image for project: 'OpenShift CFE'
  1. OpenShift CFE
  2. CFE-293

AC-6(8) - Code execution privilege levels

XMLWordPrintable

    • CFE Sprint 216

      The information system prevents [Assignment: organization-defined software] from executing at higher privilege levels than users executing the software.

      Supplemental Guidance:  In certain situations, software applications/programs need to execute with elevated privileges to perform required functions. However, if the privileges required for execution are at a higher level than the privileges assigned to organizational users invoking such applications/programs, those users are indirectly provided with greater privileges than assigned by organizations.

      References :

      https://issues.redhat.com/browse/CMP-121

       

      Work to do:

      • SCC settings and which user role/permissions are required to update SCC config.
      • Any update on roles/permissions validation rules.
      • Update control response.

              tgeer@redhat.com Trilok Geer
              tgeer@redhat.com Trilok Geer
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

                Created:
                Updated:
                Resolved:

                  Estimated:
                  Original Estimate - Not Specified
                  Not Specified
                  Remaining:
                  Remaining Estimate - 0 minutes
                  0m
                  Logged:
                  Time Spent - 1 day
                  1d