Uploaded image for project: 'OpenShift Request For Enhancement'
  1. OpenShift Request For Enhancement
  2. RFE-7472

File Integrity Monitoring for PCI-DSS

XMLWordPrintable

    • Icon: Feature Request Feature Request
    • Resolution: Unresolved
    • Icon: Major Major
    • None
    • 4.16, 4.18, 4.17
    • rhacs
    • None
    • Product / Portfolio Work
    • None
    • False
    • Hide

      None

      Show
      None
    • None
    • None
    • None
    • None
    • None
    • None
    • None
    • None

      1. Proposed title of this feature request
      File Integrity Monitoring for PCI-DSS

      2. What is the nature and description of the request?
      Provide File Integrity Monitoring with richer features to met new PCI-DSS challenges
      Openshift provides File Integrity Operator, an AIDE based solution to monitor file at node level.
      More requirements come with PCI-DSS v4 in this area AIDE won't solve. Here after missing features.
      Some customers dealing with strong compliancies and regulation rules need a diffent tooling than AIDE.
      CrowdStrike provides a solution for kubernetes which is doing File Integrity Monitoring.
      My customer decided to go with this solution for this year since File Intergity Operator based on AIDE
      does not provide answers to PCI-DSS challenges

      3. Why does the customer need this? (List the business requirements here)
      Openshift provides File Integrity Operator, an AIDE based solution to monitor file at node level.
      More requirements come with PCI-DSS v4 in this area AIDE won't solve. Here after missing features.

      Detection

      • Which process altered the monitored file
      • Which user spawn the process

      Dashboard and reports to provide evidence during audit

      • What changed on the node
      • When it changed
      • First time it changed
      • How many time since first occurence

      Policy driven monitoring

      • Which files to monitor
      • Which directory
      • Which filesystems

      4. List any affected packages or components.
      File Integrity Operator

              rh-ee-masimonm Maria Simon Marcos
              rh-support-fgrosjea Franck Grosjean
              None
              Votes:
              0 Vote for this issue
              Watchers:
              4 Start watching this issue

                Created:
                Updated:
                None
                None