4.11 Install verified packages only

Information

Verify authenticity of the packages before installing them in the image.Verifying authenticity of the packages is essential for building a secure container image.
Tampered packages could potentially be malicious or have some known vulnerabilities that
could be exploited.

Solution

Use GPG keys for downloading and verifying packages or any other secure package
distribution mechanism of your choice.Impact-NoneDefault Value-Not Applicable

See Also

https://workbench.cisecurity.org/files/517

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7b.

Plugin: Unix

Control ID: 6e829a611af2106db5471b83cd9816c2d422714722c0a3d7d568c5cec3ce568c