Prisma Cloud Compute Defender must be deployed to containerization nodes that are to be monitored.

Severity
Group ID
Group Title
Version
Rule ID
Date
STIG Version
mediumV-253527SRG-APP-000097-CTR-000180CNTR-PC-000240SV-253527r960897_rule2024-12-062
Description
Container platforms distribute workloads across several nodes. The ability to uniquely identify an event within an environment is critical. Prisma Cloud Compute Container Runtime audits record the time, container, corresponding image, and node where the event occurred. Satisfies: SRG-APP-000097-CTR-000180, SRG-APP-000100-CTR-000200
ℹ️ Check
Navigate to Prisma Cloud Compute Console's >> Manage >> Defenders >> Manage tab. Verify Prisma Cloud Compute Defenders have been deployed to all container runtime nodes to be monitored. Review the list of deployed Defenders. If a Defender is missing, this is a finding.
✔️ Fix
Navigate to Prisma Cloud Compute Console's >> Manage >> Defenders >> Manage tab. Deploy Defender to containerization node: - Select the method of Defender deployment. - Configure the Defender policy.