4.2 Use trusted base images for containers

Information

Ensure that the container image is written either from scratch or is based on another established and trusted base image downloaded over a secure channel.

Rationale:

Official repositories are Docker images curated and optimized by the Docker community or the vendor. There could be other potentially unsafe public repositories. You should thus exercise a lot of caution when obtaining container images.

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

Configure and use Docker Content trust.

Impact:

None.

Default Value:

Not Applicable.

See Also

https://workbench.cisecurity.org/files/1476

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7(5)

Plugin: Unix

Control ID: 94c493a2de6788a75748a181a1ac271a56c285a07b515cf3998e5a4b78c245e9