5.5 Do not mount sensitive host system directories on containers

Information

https://docs.docker.com/userguide/dockervolumes

Solution

Do not mount host sensitive directories on containers especially in read-write mode.Impact-None.Default Value-Docker defaults to a read-write volume but you can also mount a directory read-only. By
default, no sensitive host directories are mounted on containers.
NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

See Also

https://workbench.cisecurity.org/files/517

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7b.

Plugin: Unix

Control ID: 4874d0d6de04d7676962549ea60ced9a366a211079ba4090ab3fe9e01de3705b