4.2 Use trusted base images for containers

Information

Ensure that the container image is written either from scratch or is based on another established and trusted base image downloaded over a secure channel.

Rationale:

Official repositories are Docker images curated and optimized by the Docker community or the vendor. There could be other potentially unsafe public repositories. You should thus exercise a lot of caution when obtaining container images.

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

Configure and use Docker Content trust.

Impact:

None.

Default Value:

Not Applicable.

See Also

https://workbench.cisecurity.org/files/1476

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7(5)

Plugin: Unix

Control ID: 97fe5c92cdd03b798fe7f487466b2fe76a1ebc474c6394e7f9a5953231deda62