Uploaded image for project: 'Cloud Infrastructure Security & Compliance'
  1. Cloud Infrastructure Security & Compliance
  2. CMP-1014

[CM-11]: Check that there exists an allowed list of registries

    XMLWordPrintable

Details

    • Story
    • Resolution: Done
    • Undefined
    • None
    • None
    • None

    Description

      The contol says:

      The organization:
      a. Establishes [Assignment: organization-defined policies] governing the installation of software by users;
      b. Enforces software installation policies through [Assignment: organization-defined methods]; and
      c. Monitors policy compliance at [Assignment: organization-defined frequency].

      Regarding the monitoring, the control says: "Policy enforcement methods
      include procedural methods (e.g., periodic examination of user accounts),
      automated methods (e.g., configuration settings implemented on organizational
      information systems), or both." which makes me think that periodically running
      the checks that look if signing is enforced and if registries have been
      configured is enough. It would be nice to write the openscap rule so that
      the list of allowed registries is configurable, that would provide nicer auditing.

       

      In addition to checking signatures, which we already do, we should make sure that only the allowed registries are configured as per https://docs.openshift.com/container-platform/4.7/openshift_images/image-configuration.html

      Attachments

        Activity

          People

            Unassigned Unassigned
            jhrozek@redhat.com Jakub Hrozek
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: