5.6 Do not mount sensitive host system directories on containers

Information

https://docs.docker.com/userguide/dockervolumes

Solution

Do not mount host sensitive directories on containers especially in read-write mode.

Impact-None.

Default Value-Docker defaults to a read-write volume but you can also mount a directory read-only. By
default, no sensitive host directories are mounted on containers.

See Also

https://workbench.cisecurity.org/files/514

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7b.

Plugin: Unix

Control ID: 4b3cc4d68abb101907be402dc33b31dc11d20ab872abc77ad1677fd3712e45fa