5.24 Confirm cgroup usage

Information

https://docs.docker.com/engine/reference/run/#specifying-custom-cgroups
2.https://access.redhat.com/documentation/en-US/Red_Hat_Enterprise_Linux/6/html/Resource_Management_Guide/ch01.html

Solution

Do not use --cgroup-parentoption in docker run command unless needed.
Impact-
None.
Default Value-
By default, containers run under dockercgroup.

See Also

https://workbench.cisecurity.org/files/516

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-39

Plugin: Unix

Control ID: 5c88f4d20d1f8a83d26a8a77c8b648ecdb45fa62db27f5bf4bc4afa2b038d8e2