V-233227
SV-233227r961641_rule
CAT II
The container platform must maintain the confidentiality and integrity of information during reception.
From: Container Platform Security Requirements Guide (V2R4)
Description
<VulnDiscussion>Information either can be unintentionally or maliciously disclosed or modified during reception for reception within the container platform during aggregation, at protocol transformation points, and during container image runtime. These unauthorized disclosures or modifications compromise the confidentiality or integrity of the information. When receiving data, the container platform components need to leverage protection mechanisms, such as TLS, TLS VPNs, or IPsec.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls>
Check Procedure
Review documentation and configuration settings to determine if the container platform maintains the confidentiality and integrity of information during reception.
If confidentiality and integrity are not maintained using mechanisms such as TLS, TLS VPNs, or IPsec during reception, this is a finding.
Fix Text
Configure the container platform to maintain the confidentiality and integrity using mechanisms such as TLS, TLS VPNs, or IPsec during reception.
CCI Reference
CCI-002422- Created
- 2026-04-07 20:08:14
- Last Updated
- 2026-04-07 20:08:14