cis-docker-5.23
Ensure that docker exec commands are not used with the privileged option
1.21k repo starsObserved in 1 repos
DevOps & Security
Browse reusable Agent Skills, each with a clear purpose and practical guidance.
Ensure that docker exec commands are not used with the privileged option
Ensure that docker exec commands are not used with the user=root option
Ensure that the container is restricted from acquiring additional privileges
Ensure that container health is checked at runtime
Ensure that Docker commands always make use of the latest version of their image
Ensure that the PIDs cgroup limit is used
Ensure that, if applicable, SELinux security options are set
Ensure that Docker's default bridge docker0 is not used
Ensure that the host's user namespaces are not shared
Ensure that the Docker socket is not mounted inside any containers