Skip to content

I - Mission Critical Sensitive

Rules and Groups employed by this XCCDF Profile

  • A policy set using the built-in role-based access control (RBAC) capabilities in the Docker Trusted Registry (DTR) component of Docker Enterprise must be set.

    <VulnDiscussion>Both the Universal Control Plane (UCP) and DTR components of Docker Enterprise leverage the same authentication and authoriza...
    Rule Medium Severity
  • SRG-APP-000033

    <GroupDescription></GroupDescription>
    Group
  • Docker Enterprise sensitive host system directories must not be mounted on containers.

    &lt;VulnDiscussion&gt;Sensitive host system directories such as below should not be allowed to be mounted as container volumes especially in read-w...
    Rule Medium Severity
  • SRG-APP-000039

    <GroupDescription></GroupDescription>
    Group
  • The Docker Enterprise hosts process namespace must not be shared.

    &lt;VulnDiscussion&gt;Process ID (PID) namespaces isolate the PID number space, meaning that processes in different PID namespaces can have the sam...
    Rule Medium Severity

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules