1.8 Audit Docker files and directories - /var/lib/docker

Information

Audit /var/lib/docker.Apart from auditing your regular Linux file system and system calls, audit all Docker related files and directories. Docker daemon runs with 'root' privileges. Its behavior depends on some key files and directories. /var/lib/docker is one such directory. It holds all the information about containers. It must be audited.

Solution

Add a rule for/var/lib/docker directory.

For example,
Add the line as below in /etc/audit/audit.rules file-
-w /var/lib/docker -k docker
Then, restart the audit daemon. For example,
service auditd restart
Impact-
Auditing generates quite big log files. Ensure to rotate and archive them periodically. Also, create a separate partition of audit to avoid filling root file system.
Default Value-
By default, Docker related files and directories are not audited.

See Also

https://workbench.cisecurity.org/files/516

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-12c.

Plugin: Unix

Control ID: 18a31213b5d577202b979751d3d75bd442eea8ee8b76805e2d454703c1e9a626