V-233043
SV-233043r960894_rule
CAT II
The container platform audit records must have a date and time association with all events.
From: Container Platform Security Requirements Guide (V2R4)
Description
<VulnDiscussion>Within the container platform, audit data can be generated from any of the deployed container platform components. This audit data is important when there are issues, such as security incidents, that must be investigated. To make the audit data worthwhile for the investigation of events, it is necessary to know when the event occurred. To establish the time of the event, the audit record must contain the date and time.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls>
Check Procedure
Review the container platform configuration for audit events date and time.
Ensure audit policy for event date and time are enabled.
Verify records showing event date and time are included in the log.
Validate system documentation is current.
If the date and time are not included, this is a finding.
Fix Text
Configure the container platform to include log date and time with the event. Revise all applicable system documentation.
CCI Reference
CCI-000131- Created
- 2026-04-07 20:08:14
- Last Updated
- 2026-04-07 20:08:14