I - Mission Critical Public
Rules and Groups employed by this XCCDF Profile
-
SRG-APP-000454
<GroupDescription></GroupDescription>Group -
Docker Enterprise older Universal Control Plane (UCP) and Docker Trusted Registry (DTR) images must be removed from all cluster nodes upon upgrading.
<VulnDiscussion>When upgrading either the UCP or DTR components of Docker Enterprise, the newer images are pulled (or unpacked if offline) on...Rule Medium Severity -
SRG-APP-000475
<GroupDescription></GroupDescription>Group -
Only trusted, signed images must be stored in Docker Trusted Registry (DTR) in Docker Enterprise.
<VulnDiscussion>The Universal Control Plane (UCP) and DTR components of Docker Enterprise can be used in concert to perform an integrity chec...Rule Medium Severity -
SRG-APP-000485
<GroupDescription></GroupDescription>Group -
Docker Content Trust enforcement must be enabled in Universal Control Plane (UCP).
<VulnDiscussion>The UCP and Docker Trusted Registry (DTR) components of Docker Enterprise can be used in concert with built-in audit logging ...Rule Medium Severity -
SRG-APP-000516
<GroupDescription></GroupDescription>Group -
Docker Swarm must have the minimum number of manager nodes.
<VulnDiscussion>Ensure that the minimum number of required manager nodes is created in a swarm. Manager nodes within a swarm have control ov...Rule Medium Severity -
SRG-APP-000516
<GroupDescription></GroupDescription>Group -
Docker Enterprise Swarm manager auto-lock key must be rotated periodically.
<VulnDiscussion>Rotate swarm manager auto-lock key periodically. Swarm manager auto-lock key is not automatically rotated. Rotate them perio...Rule Medium Severity
Node 2
The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.