The container runtime must generate audit records for all container execution, shutdown, restart events, and program initiations.

Severity
Group ID
Group Title
Version
Rule ID
Date
STIG Version
mediumV-233270SRG-APP-000510SRG-APP-000510-CTR-001310SV-233270r961845_rule2024-12-052
Description
The container runtime must generate audit records that are specific to the security and mission needs of the organization. Without audit record, it would be difficult to establish, correlate, and investigate events relating to an incident.
ℹ️ Check
Review the container runtime configuration to validate audit record generation for container execution, shutdown, and restart events. If the container runtime does not generate records for container execution, shutdown and restart events, this is a finding.
✔️ Fix
Configure the container runtime to generate audit records for container execution, shutdown, and restart events.