CIS Docker v1.6.0 L1 Docker Swarm

Audit Details

Name: CIS Docker v1.6.0 L1 Docker Swarm

Updated: 6/17/2024

Authority: CIS

Plugin: Unix

Revision: 1.1

Estimated Item Count: 10

File Details

Filename: CIS_Docker_v1.6.0_L1_Docker_Swarm.audit

Size: 19.1 kB

MD5: 322d6224e0a2ac2961dbdff4846676dd
SHA256: a1e5d56087fff37cf34a5640ce25f3c19aa2449de508192768b385b243569ef7

Audit Items

DescriptionCategories
7.1 Ensure that the minimum number of manager nodes have been created in a swarm

CONFIGURATION MANAGEMENT

7.2 Ensure that swarm services are bound to a specific host interface

SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

7.3 Ensure that all Docker swarm overlay networks are encrypted

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

7.4 Ensure that Docker's secret management commands are used for managing secrets in a swarm cluster

CONFIGURATION MANAGEMENT

7.5 Ensure that swarm manager is run in auto-lock mode

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

7.6 Ensure that the swarm manager auto-lock key is rotated periodically

IDENTIFICATION AND AUTHENTICATION

7.7 Ensure that node certificates are rotated as appropriate

IDENTIFICATION AND AUTHENTICATION

7.8 Ensure that CA certificates are rotated as appropriate

IDENTIFICATION AND AUTHENTICATION

7.9 Ensure that management plane traffic is separated from data plane traffic

SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

CIS_Docker_v1.6.0_L1_Docker_Swarm.audit from CIS Docker Benchmark v1.6.0