SRG-APP-000243-CTR-000600 Controls

STIG IDVersionTitleProduct
CNTR-OS-000560V2R4OpenShift must prevent unauthorized and unintended information transfer via shared system resources and enable page poisoning.
CNTR-OS-000570V2R4OpenShift must disable virtual syscalls.
CNTR-OS-000580V2R4OpenShift must enable poisoning of SLUB/SLAB objects.
CNTR-OS-000590V2R4OpenShift must set the sticky bit for world-writable directories.
CNTR-OS-000600V2R4OpenShift must restrict access to the kernel buffer.
CNTR-OS-000610V2R4OpenShift must prevent kernel profiling.
CNTR-R2-000970V2R4Rancher RKE2 runtime must maintain separate execution domains for each container by assigning each container a separate address space to prevent unauthorized and unintended information transfer via shared system resources.