5.2 Verify SELinux security options, if applicable (Scored)

Information

http://docs.fedoraproject.org/en-US/Fedora/13/html/Security-Enhanced_Linux/

Solution

If SELinux is applicable for your Linux OS, use it. You may have to follow below set of steps-

1. Set the SELinux State.
2. Set the SELinux Policy.
3. Create or import a SELinux policy template for Docker containers.
4. Start Docker in daemon mode with SELinux enabled. For example,docker -d --selinux-enabled5. Start your Docker container using the security options. For example,docker run -i -t --security-opt label-level-TopSecret centos /bin/bashImpact-The container (process) would have set of restrictions as defined in SELinux policy. If your
SELinux policy is mis-configured, then the container may not entirely work as expected.Default Value-By default, no SELinux security options are applied on containers.

See Also

https://workbench.cisecurity.org/files/514

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-3(3)

Plugin: Unix

Control ID: 9f056ee8aefc307d90d14d823bf36c37dacfbf40e9cb1d8c58628a2bd39c2807