The container platform must display the Standard Mandatory DoD Notice and Consent Banner before granting access to platform components.

STIG ID: SRG-APP-000068-CTR-000120  |  SRG: SRG-APP-000068 |  Severity: low |  CCI: CCI-000048 |  Vulnerability Id: V-233032

Vulnerability Discussion

The container platform has countless components where different access levels are needed. To control access, the user must first log in to the component and then be presented with a DoD-approved use notification banner before granting access to the component. This guarantees privacy and security notification verbiage used is consistent with applicable federal laws, Executive Orders, directives, policies, regulations, standards, and guidance.

Check

Review the container platform configuration to determine if the Standard Mandatory DoD Notice and Consent Banner is configured to be displayed before granting access to platform components.

Log in to the container platform components and verify that the Standard Mandatory DoD Notice and Consent Banner is being displayed before granting access.

If the Standard Mandatory DoD Notice and Consent Banner is not configured or is not displayed before granting access to container platform components, this is a finding.

Fix

Configure the container platform to display the Standard Mandatory DoD Notice and Consent Banner before granting access to container platform components.