| 1.2.1 Ensure the container host has been Hardened | CIS Docker v1.8.0 L1 OS Linux | Unix | CONFIGURATION MANAGEMENT |
| 1.3 Do not use development tools in production | CIS Docker 1.6 v1.0.0 L1 Linux | Unix | CONFIGURATION MANAGEMENT |
| 1.7 Ensure MySQL is Run Under a Sandbox Environment | CIS Oracle MySQL Community Server 9.7 v1.0.0 L2 MySQL RDBMS on Linux Unix | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| 1.7 Ensure MySQL is Run Under a Sandbox Environment | CIS Oracle MySQL Enterprise Edition 9.7 v1.0.0 L2 MySQL RDBMS on Linux Unix | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| 2.9 Ensure the default ulimit is configured appropriately | CIS Docker v1.8.0 L1 OS Linux | Unix | CONFIGURATION MANAGEMENT |
| 3.1 Ensure that the docker.service file ownership is set to root:root | CIS Docker v1.8.0 L1 OS Linux | Unix | ACCESS CONTROL |
| 3.2 Ensure that docker.service file permissions are appropriately set | CIS Docker v1.8.0 L1 OS Linux | Unix | ACCESS CONTROL, MEDIA PROTECTION |
| 3.3 Ensure that docker.socket file ownership is set to root:root | CIS Docker v1.8.0 L1 OS Linux | Unix | ACCESS CONTROL |
| 3.4 Ensure that docker.socket file permissions are set to 644 or more restrictive | CIS Docker v1.8.0 L1 OS Linux | Unix | ACCESS CONTROL, MEDIA PROTECTION |
| 3.9 Ensure that TLS CA certificate file ownership is set to root:root | CIS Docker v1.8.0 L1 OS Linux | Unix | ACCESS CONTROL |
| 3.10 Ensure that TLS CA certificate file permissions are set to 444 or more restrictively | CIS Docker v1.8.0 L1 OS Linux | Unix | ACCESS CONTROL, MEDIA PROTECTION |
| 3.17 Ensure that the daemon.json file ownership is set to root:root | CIS Docker v1.8.0 L2 OS Linux | Unix | ACCESS CONTROL |
| 3.18 Ensure that daemon.json file permissions are set to 644 or more restrictive | CIS Docker v1.8.0 L2 OS Linux | Unix | ACCESS CONTROL, MEDIA PROTECTION |
| 3.24 Ensure that the Containerd socket file permissions are set to 660 or more restrictively | CIS Docker v1.8.0 L1 OS Linux | Unix | ACCESS CONTROL, MEDIA PROTECTION |
| 4.1 Ensure that a user for the container has been created | CIS Docker v1.8.0 L1 OS Linux | Unix | ACCESS CONTROL |
| 4.3 Ensure that unnecessary packages are not installed in the container | CIS Docker v1.8.0 L1 OS Linux | Unix | CONFIGURATION MANAGEMENT |
| 4.4 Ensure images are scanned and rebuilt to include security patches | CIS Docker v1.8.0 L1 OS Linux | Unix | RISK ASSESSMENT |
| 4.5 Ensure Content trust for Docker is Enabled | CIS Docker v1.8.0 L2 OS Linux | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| 4.7 Ensure update instructions are not used alone in Dockerfiles | CIS Docker v1.8.0 L1 OS Linux | Unix | CONFIGURATION MANAGEMENT |
| 4.9 Ensure that COPY is used instead of ADD in Dockerfiles | CIS Docker v1.8.0 L1 OS Linux | Unix | CONFIGURATION MANAGEMENT |
| 4.12 Ensure all signed artifacts are validated | CIS Docker v1.8.0 L1 OS Linux | Unix | CONFIGURATION MANAGEMENT, SYSTEM AND INFORMATION INTEGRITY |
| 5.5.1 Use COS_CONTAINERD node images for GKE node pools | CIS Google Kubernetes Engine GKE v2.0.0 L1 GCP | GCP | CONFIGURATION MANAGEMENT |
| 5.6 Ensure sensitive host system directories are not mounted on containers | CIS Docker v1.8.0 L1 OS Linux | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| 5.9 Ensure that only needed ports are open on the container | CIS Docker v1.8.0 L1 OS Linux | Unix | CONFIGURATION MANAGEMENT |
| 5.14 Ensure that incoming container traffic is bound to a specific host interface | CIS Docker v1.8.0 L1 OS Linux | Unix | SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION |
| 5.15 Ensure that the 'on-failure' container restart policy is set to '5' | CIS Docker v1.8.0 L1 OS Linux | Unix | CONFIGURATION MANAGEMENT |
| 5.16 Ensure that the host's process namespace is not shared | CIS Docker v1.8.0 L1 OS Linux | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| 5.17 Ensure that the host's IPC namespace is not shared | CIS Docker v1.8.0 L1 OS Linux | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| 5.18 Ensure that host devices are not directly exposed to containers | CIS Docker v1.8.0 L1 OS Linux | Unix | ACCESS CONTROL |
| 5.19 Ensure that the default ulimit is overwritten at runtime if needed | CIS Docker v1.8.0 L1 OS Linux | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| 5.20 Ensure mount propagation mode is not set to shared | CIS Docker v1.8.0 L1 OS Linux | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| 5.21 Ensure that the host's UTS namespace is not shared | CIS Docker v1.8.0 L1 OS Linux | Unix | SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION |
| 5.26 Ensure that the container is restricted from acquiring additional privileges | CIS Docker v1.8.0 L1 OS Linux | Unix | ACCESS CONTROL |
| 5.31 Ensure that the host's user namespaces are not shared | CIS Docker v1.8.0 L1 OS Linux | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| 6.1 Ensure image sprawl is avoided | CIS Docker Community Edition v1.1.0 L1 Linux Host OS | Unix | CONFIGURATION MANAGEMENT |
| 6.2 Ensure that container sprawl is avoided | CIS Docker v1.8.0 L1 OS Linux | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| 6.4 Avoid image sprawl | CIS Docker 1.12.0 v1.0.0 L1 Linux | Unix | CONFIGURATION MANAGEMENT |
| CIS_Docker_1.6_v1.0.0_L1_Docker.audit Level 1 | CIS Docker 1.6 v1.0.0 L1 Docker | Unix | |
| CIS_Docker_1.11.0_v1.0.0_L1.audit Level 1 | CIS Docker 1.11.0 v1.0.0 L1 Docker | Unix | |
| CIS_Docker_1.13.0_L1_v1.0.0.audit Level 1 | CIS Docker 1.13.0 v1.0.0 L1 Docker | Unix | |
| CIS_Docker_1.13.0_L2_v1.0.0.audit Level 2 | CIS Docker 1.13.0 v1.0.0 L2 Docker | Unix | |
| DKER-EE-002040 - Docker Enterprise host devices must not be directly exposed to containers. | DISA STIG Docker Enterprise 2.x Linux/Unix v2r2 | Unix | CONFIGURATION MANAGEMENT |
| DKER-EE-002050 - Mount propagation mode must not set to shared in Docker Enterprise. | DISA STIG Docker Enterprise 2.x Linux/Unix v2r2 | Unix | CONFIGURATION MANAGEMENT |
| DKER-EE-002770 - Docker Enterprise container health must be checked at runtime. | DISA STIG Docker Enterprise 2.x Linux/Unix v2r2 | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| DKER-EE-004030 - The on-failure container restart policy must be is set to 5 in Docker Enterprise. | DISA STIG Docker Enterprise 2.x Linux/Unix v2r2 | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| DKER-EE-005060 - Docker Swarm must have the minimum number of manager nodes. | DISA STIG Docker Enterprise 2.x Linux/Unix v2r2 | Unix | CONFIGURATION MANAGEMENT |
| DKER-EE-005330 - Docker Enterprise daemon.json file ownership must be set to root:root. | DISA STIG Docker Enterprise 2.x Linux/Unix v2r2 | Unix | CONFIGURATION MANAGEMENT |
| DKER-EE-005340 - Docker Enterprise daemon.json file permissions must be set to 644 or more restrictive. | DISA STIG Docker Enterprise 2.x Linux/Unix v2r2 | Unix | CONFIGURATION MANAGEMENT |
| TCAT-AS-000390 - $CATALINA_HOME/bin folder permissions must be set to 750. | DISA STIG Apache Tomcat Application Server 9 v3r4 Middleware | Unix | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY |
| TCAT-AS-001220 - $CATALINA_BASE/conf/ folder must be owned by root, group tomcat. | DISA STIG Apache Tomcat Application Server 9 v3r4 Middleware | Unix | CONFIGURATION MANAGEMENT |