Rule ID
SV-285757r1272383_rule
STIG
Rancher Government Solutions (RGS) Harvester Government CTR Security Technical Implementation GuideVersion
V1R1
Harvester Government platform must send audit events to a central managed audit log repository to provide reporting, analysis, and alert notification. Incident response relies on successful timely, accurate system analysis in order for the organization to identify and respond to possible security events. Protecting the integrity of the tools used for auditing purposes is a critical step to ensuring the integrity of audit data. Audit data includes all information (e.g., audit records, audit settings, and audit reports) needed to successfully audit information system activity. Satisfies: SRG-APP-000111-CTR-000220, SRG-APP-000181-CTR-000485, SRG-APP-000290-CTR-000670, SRG-APP-000357-CTR-000800, SRG-APP-000358-CTR-000805, SRG-APP-000381-CTR-000905, SRG-APP-000447-CTR-001100, SRG-APP-000745-CTR-000120
Verify logging capability is enabled and are forwarded to a centralized location by accessing the Rancher Multi-Cluster Manager (MCM) managing the Rancher Harvester cluster. 1. Navigate to the hamburger menu >> Virtualization Management >> Select Harvester Cluster >> Advanced >> Addons. 2. Verify the "rancher-logging" add-on is deployed successfully. If the "rancher-logging" add-on is disabled or not in a healthy state, this is a finding. 3. Verify ClusterFlow is configured to process audit logs. Navigate to Cluster >> Monitoring & Logging >> Logging >> ClusterFlow. If no ClusterFlow exists that processes audit logs and forwards them via outputRefs, this is a finding. 4. Verify ClusterOutput is configured for centralized log forwarding. Navigate to Cluster >> Monitoring & Logging >> Logging >> ClusterOutput. If ClusterOutputs are not configured to send logs to an external centralized system, this is a finding. If secure transport (e.g., TLS) is not configured for the logs, this is a finding. 5. Verify corresponding log records are present in the centralized logging system. If audit logs are not observed at the centralized destination, this is a finding.
Configure Harvester Government for audit logging. 1. Navigate to the hamburger menu >> Virtualization Management >> Select Harvester Instance >> Advanced >> Addons. 2. From this screen, enable "rancher-logging". a. Click "rancher-logging". b. Select the three-dot menu. c. Click "Enable". 3. Configure a Cluster Output and a Cluster Flow of type "Audit". - Select Monitoring & Logging >> Logging >> Cluster Output. - Select Monitoring & Logging >> Logging >> Cluster Flow. a. Click "Create". b. Fill out the form. c. Click "Create".