1.7 Audit docker daemon

Information

https://access.redhat.com/documentation/en-US/Red_Hat_Enterprise_Linux/6/html/Security_Guide/chap-system_auditing.html

Solution

Add a rule for Docker daemon.For example,Add the line as below line in /etc/audit/audit.rules file--w /usr/bin/docker -k dockerThen, restart the audit daemon. For example,service auditd restartImpact-Auditing generates quite big log files. Ensure to rotate and archive them periodically. Also,
create a separate partition of audit to avoid filling root file system.
Default Value-By default, Docker daemon is not audited.

See Also

https://workbench.cisecurity.org/files/517

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-12c.

Plugin: Unix

Control ID: 9e324dbc721675133ad3676cc860d92fba9a786db382b0d5a664f16563806cf9