Skip to content

Commit

Permalink
Define notes and rules for BSI APP.4.4.A12
Browse files Browse the repository at this point in the history
  • Loading branch information
benruland committed Dec 18, 2023
1 parent cf0ae8c commit 1b5f76e
Show file tree
Hide file tree
Showing 3 changed files with 8 additions and 3 deletions.
Original file line number Diff line number Diff line change
Expand Up @@ -34,6 +34,7 @@ references:
cis@ocp4: '5.5.1'
nist: CM-5(3)
srg: SRG-APP-000014-CTR-000035
bsi: APP.4.4.A12

ocil_clause: 'allowedRegistriesForImport is configured with insecure option for image access'

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -30,6 +30,7 @@ references:
cis@ocp4: '5.5.1'
nist: CM-5(3)
srg: SRG-APP-000014-CTR-000035
bsi: APP.4.4.A12

ocil_clause: 'insecure registry sources is configured for image access'

Expand Down
9 changes: 6 additions & 3 deletions controls/bsi_app_4_4.yml
Original file line number Diff line number Diff line change
Expand Up @@ -217,9 +217,12 @@ controls:
• Logging of changes
• Regular data backups.
notes: >-
TBD
status: pending
rules: []
This requirement needs to be adressed in the respective separate systems.
However, one requirement can be checked automated: Encrypted communication all image registries.
status: automated
rules:
- ocp_insecure_registries
- ocp_insecure_allowed_registries_for_import

- id: APP.4.4.A13
title: Automated Configuration Auditing
Expand Down

0 comments on commit 1b5f76e

Please sign in to comment.