Item Search

NameAudit NamePluginCategory
1.2.1 Ensure the container host has been HardenedCIS Docker v1.8.0 L1 OS LinuxUnix

CONFIGURATION MANAGEMENT

1.3 Do not use development tools in productionCIS Docker 1.6 v1.0.0 L1 LinuxUnix

CONFIGURATION MANAGEMENT

1.7 Ensure MySQL is Run Under a Sandbox EnvironmentCIS Oracle MySQL Community Server 9.7 v1.0.0 L2 MySQL RDBMS on Linux UnixUnix

SYSTEM AND COMMUNICATIONS PROTECTION

1.7 Ensure MySQL is Run Under a Sandbox EnvironmentCIS Oracle MySQL Enterprise Edition 9.7 v1.0.0 L2 MySQL RDBMS on Linux UnixUnix

SYSTEM AND COMMUNICATIONS PROTECTION

2.9 Ensure the default ulimit is configured appropriatelyCIS Docker v1.8.0 L1 OS LinuxUnix

CONFIGURATION MANAGEMENT

3.1 Ensure that the docker.service file ownership is set to root:rootCIS Docker v1.8.0 L1 OS LinuxUnix

ACCESS CONTROL

3.2 Ensure that docker.service file permissions are appropriately setCIS Docker v1.8.0 L1 OS LinuxUnix

ACCESS CONTROL, MEDIA PROTECTION

3.3 Ensure that docker.socket file ownership is set to root:rootCIS Docker v1.8.0 L1 OS LinuxUnix

ACCESS CONTROL

3.4 Ensure that docker.socket file permissions are set to 644 or more restrictiveCIS Docker v1.8.0 L1 OS LinuxUnix

ACCESS CONTROL, MEDIA PROTECTION

3.9 Ensure that TLS CA certificate file ownership is set to root:rootCIS Docker v1.8.0 L1 OS LinuxUnix

ACCESS CONTROL

3.10 Ensure that TLS CA certificate file permissions are set to 444 or more restrictivelyCIS Docker v1.8.0 L1 OS LinuxUnix

ACCESS CONTROL, MEDIA PROTECTION

3.17 Ensure that the daemon.json file ownership is set to root:rootCIS Docker v1.8.0 L2 OS LinuxUnix

ACCESS CONTROL

3.18 Ensure that daemon.json file permissions are set to 644 or more restrictiveCIS Docker v1.8.0 L2 OS LinuxUnix

ACCESS CONTROL, MEDIA PROTECTION

3.24 Ensure that the Containerd socket file permissions are set to 660 or more restrictivelyCIS Docker v1.8.0 L1 OS LinuxUnix

ACCESS CONTROL, MEDIA PROTECTION

4.1 Ensure that a user for the container has been createdCIS Docker v1.8.0 L1 OS LinuxUnix

ACCESS CONTROL

4.3 Ensure that unnecessary packages are not installed in the containerCIS Docker v1.8.0 L1 OS LinuxUnix

CONFIGURATION MANAGEMENT

4.4 Ensure images are scanned and rebuilt to include security patchesCIS Docker v1.8.0 L1 OS LinuxUnix

RISK ASSESSMENT

4.5 Ensure Content trust for Docker is EnabledCIS Docker v1.8.0 L2 OS LinuxUnix

SYSTEM AND COMMUNICATIONS PROTECTION

4.7 Ensure update instructions are not used alone in DockerfilesCIS Docker v1.8.0 L1 OS LinuxUnix

CONFIGURATION MANAGEMENT

4.9 Ensure that COPY is used instead of ADD in DockerfilesCIS Docker v1.8.0 L1 OS LinuxUnix

CONFIGURATION MANAGEMENT

4.12 Ensure all signed artifacts are validatedCIS Docker v1.8.0 L1 OS LinuxUnix

CONFIGURATION MANAGEMENT, SYSTEM AND INFORMATION INTEGRITY

5.5.1 Use COS_CONTAINERD node images for GKE node poolsCIS Google Kubernetes Engine GKE v2.0.0 L1 GCPGCP

CONFIGURATION MANAGEMENT

5.6 Ensure sensitive host system directories are not mounted on containersCIS Docker v1.8.0 L1 OS LinuxUnix

SYSTEM AND COMMUNICATIONS PROTECTION

5.9 Ensure that only needed ports are open on the containerCIS Docker v1.8.0 L1 OS LinuxUnix

CONFIGURATION MANAGEMENT

5.14 Ensure that incoming container traffic is bound to a specific host interfaceCIS Docker v1.8.0 L1 OS LinuxUnix

SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

5.15 Ensure that the 'on-failure' container restart policy is set to '5'CIS Docker v1.8.0 L1 OS LinuxUnix

CONFIGURATION MANAGEMENT

5.16 Ensure that the host's process namespace is not sharedCIS Docker v1.8.0 L1 OS LinuxUnix

SYSTEM AND COMMUNICATIONS PROTECTION

5.17 Ensure that the host's IPC namespace is not sharedCIS Docker v1.8.0 L1 OS LinuxUnix

SYSTEM AND COMMUNICATIONS PROTECTION

5.18 Ensure that host devices are not directly exposed to containersCIS Docker v1.8.0 L1 OS LinuxUnix

ACCESS CONTROL

5.19 Ensure that the default ulimit is overwritten at runtime if neededCIS Docker v1.8.0 L1 OS LinuxUnix

SYSTEM AND COMMUNICATIONS PROTECTION

5.20 Ensure mount propagation mode is not set to sharedCIS Docker v1.8.0 L1 OS LinuxUnix

SYSTEM AND COMMUNICATIONS PROTECTION

5.21 Ensure that the host's UTS namespace is not sharedCIS Docker v1.8.0 L1 OS LinuxUnix

SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

5.26 Ensure that the container is restricted from acquiring additional privilegesCIS Docker v1.8.0 L1 OS LinuxUnix

ACCESS CONTROL

5.31 Ensure that the host's user namespaces are not sharedCIS Docker v1.8.0 L1 OS LinuxUnix

SYSTEM AND COMMUNICATIONS PROTECTION

6.1 Ensure image sprawl is avoidedCIS Docker Community Edition v1.1.0 L1 Linux Host OSUnix

CONFIGURATION MANAGEMENT

6.2 Ensure that container sprawl is avoidedCIS Docker v1.8.0 L1 OS LinuxUnix

SYSTEM AND COMMUNICATIONS PROTECTION

6.4 Avoid image sprawlCIS Docker 1.12.0 v1.0.0 L1 LinuxUnix

CONFIGURATION MANAGEMENT

CIS_Docker_1.6_v1.0.0_L1_Docker.audit Level 1CIS Docker 1.6 v1.0.0 L1 DockerUnix
CIS_Docker_1.11.0_v1.0.0_L1.audit Level 1CIS Docker 1.11.0 v1.0.0 L1 DockerUnix
CIS_Docker_1.13.0_L1_v1.0.0.audit Level 1CIS Docker 1.13.0 v1.0.0 L1 DockerUnix
CIS_Docker_1.13.0_L2_v1.0.0.audit Level 2CIS Docker 1.13.0 v1.0.0 L2 DockerUnix
DKER-EE-002040 - Docker Enterprise host devices must not be directly exposed to containers.DISA STIG Docker Enterprise 2.x Linux/Unix v2r2Unix

CONFIGURATION MANAGEMENT

DKER-EE-002050 - Mount propagation mode must not set to shared in Docker Enterprise.DISA STIG Docker Enterprise 2.x Linux/Unix v2r2Unix

CONFIGURATION MANAGEMENT

DKER-EE-002770 - Docker Enterprise container health must be checked at runtime.DISA STIG Docker Enterprise 2.x Linux/Unix v2r2Unix

SYSTEM AND COMMUNICATIONS PROTECTION

DKER-EE-004030 - The on-failure container restart policy must be is set to 5 in Docker Enterprise.DISA STIG Docker Enterprise 2.x Linux/Unix v2r2Unix

SYSTEM AND COMMUNICATIONS PROTECTION

DKER-EE-005060 - Docker Swarm must have the minimum number of manager nodes.DISA STIG Docker Enterprise 2.x Linux/Unix v2r2Unix

CONFIGURATION MANAGEMENT

DKER-EE-005330 - Docker Enterprise daemon.json file ownership must be set to root:root.DISA STIG Docker Enterprise 2.x Linux/Unix v2r2Unix

CONFIGURATION MANAGEMENT

DKER-EE-005340 - Docker Enterprise daemon.json file permissions must be set to 644 or more restrictive.DISA STIG Docker Enterprise 2.x Linux/Unix v2r2Unix

CONFIGURATION MANAGEMENT

TCAT-AS-000390 - $CATALINA_HOME/bin folder permissions must be set to 750.DISA STIG Apache Tomcat Application Server 9 v3r4 MiddlewareUnix

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

TCAT-AS-001220 - $CATALINA_BASE/conf/ folder must be owned by root, group tomcat.DISA STIG Apache Tomcat Application Server 9 v3r4 MiddlewareUnix

CONFIGURATION MANAGEMENT