2.9 Confirm default cgroup usage

Information

https://docs.docker.com/engine/reference/commandline/daemon/

Solution

The default setting is good enough and can be left as-is. If you want to specifically set a non-
default cgroup, pass --cgroup-parent parameter to the docker daemon when starting it.For Example,dockerd --cgroup-parent=/foobarImpact-None.
Default Value-By default, docker daemon uses /docker for fs cgroup driver and system.slice for
systemd cgroup driver.

See Also

https://workbench.cisecurity.org/files/517

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-39

Plugin: Unix

Control ID: 73dd3648637a3038b1e4bd540c09be7380bd2a34affc7187cc7ed11e057bac73