STIGhubSTIGhub
STIGhub— A free STIG search and compliance tool·STIGs updated 3 hours ago
Powered by Pylon·Privacy·Terms·Feedback·© 2026 Beacon Cloud Solutions, Inc.
← Back to Rancher Government Solutions (RGS) Harvester Government CTR Security Technical Implementation Guide

V-285762

CAT II (Medium)

Harvester Government platform must configure alerts and notifications for system administrators (SAs) and the information system security officer (ISSO).

Rule ID

SV-285762r1272725_rule

STIG

Rancher Government Solutions (RGS) Harvester Government CTR Security Technical Implementation Guide

Version

V1R1

CCIs

CCI-000015CCI-001855CCI-001858CCI-002702CCI-003831

Discussion

Failure to configure alerts and notifications for SAs and the ISSO reduces the organization’s ability to detect, respond to, and mitigate security-relevant events in a timely manner. Without automated alerting, critical events may go unnoticed, increasing the risk of prolonged system exposure, operational degradation, or compromise. The Rancher Harvester platform provides monitoring and alerting capabilities that notify designated personnel of defined conditions and security events. Proper configuration ensures that alerts are generated based on organization-defined thresholds and are delivered through approved communication channels. Satisfies: SRG-APP-000291-CTR-000675, SRG-APP-000292-CTR-000680, SRG-APP-000293-CTR-000685, SRG-APP-000294-CTR-000690, SRG-APP-000320-CTR-000750, SRG-APP-000359-CTR-000810, SRG-APP-000360-CTR-000815, SRG-APP-000474-CTR-001180, SRG-APP-000795-CTR-000130

Check Content

Verify the Harvester Government platform is configured to forward audit and system logs to a centralized logging capability that supports alerting for security-relevant events.

Verify Centralized Logging Capability:
1. Access the Harvester or Rancher management interface or node configuration with appropriate privileges.

2. Verify that a centralized logging solution (e.g., SIEM, log aggregation platform) is configured and actively receiving logs from:
- Verified Harvester nodes.
- RKE2 control plane components.
- System and application workloads (as applicable).

If a centralized logging capability is not configured or not receiving logs, this is a finding. 

Verify Alerting Capability:
1. Review the configuration of the centralized logging solution.

2. Verify that alerting is configured to notify the SA and ISSO for:
- Security-relevant events defined by the Authorizing Official (AO).
- Audit processing failures (e.g., log forwarding failures, dropped logs, or pipeline errors).
- Critical system or authentication events.

If alerting is not configured for AO-defined security events, this is a finding.

If alerting is not configured for audit/log processing failures, this is a finding.

Validate Alert Configuration:
1. Confirm that:
- Alert rules or correlation policies are defined for required events.
- Notification mechanisms (e.g., email) are configured and alert recipients include designated SA and ISSO personnel.

If alerts are not configured to notify the SA and ISSO, this is a finding.

Fix Text

Configure the Harvester Government platform and centralized logging solution to support alerting for audit events and log processing failures.

Configure Centralized Logging:
1. Configure Harvester to forward logs to an approved centralized logging solution (e.g., SIEM or log aggregation platform).

2. Ensure the following sources are included:
- Control plane components (kube-apiserver, controller-manager, scheduler).
- Node-level system logs.
- Application and workload logs (as required).

Configure Alerting Rules:
1. Within the centralized logging solution, configure alerting policies to generate alerts for:
- Security-relevant events defined by the AO.
- Authentication and authorization events.
- System errors and failures.
- Audit/log processing failures (e.g., ingestion failures, pipeline errors, dropped logs).

Configure Notification Mechanisms:
1. Configure alert notifications to ensure delivery SAs and the ISSO.

2. Ensure notification methods are appropriate (e.g., email).

Note: Harvester environments commonly rely on external SIEM or log aggregation solutions; configuration may reside outside the platform.