- Cloud Native Applications
- Application Security
- Application Security
- Web Application Security
- Application Security Posture Management (ASPM)
- Microsegmentation
- Python Security
- SaaS Security
- Node.JS Security
- PHP Security
- AI in Cyber Security
- Cybersecurity for Financial Services
- The Principle of Least Privilege (PoLP)
- Identity and Access Management
- Cybersecurity in Banking
- Threat Detection and Response
- Cyber Kill Chain
- Threat Hunting
- Zero Trust Security
- Zero Trust Architecture
- Fileless Attacks
- DSPM
- Container Scanning
- Kubernetes
- Kubernetes
- Kubernetes Alternatives
- Kubernetes Namespace
- Kubernetes Architecture
- Kubernetes Cluster
- Kubernetes Nodes
- Kubernetes Pods
- Kubernetes Jobs
- Kubernetes Workloads
- Kubernetes Monitoring
- Kubernetes Security
- Kubernetes RBAC
- Secret Scanning
- Kubernetes Security Posture Management (KSPM)
- Kubernetes on AWS
- Kubernetes on VMware
- Kubernetes Vulnerability Scanning
- Managing Containers in Kubernetes
- K3s
- eBPF in Kubernetes
- Kubernetes Dashboard
- Kubernetes Operators
- Kubernetes Services
- Kubernetes Devops
- Kubernetes Networking
- Kubernetes ConfigMap
- Kubernetes Management
- Kubernetes Helm
- Kubernetes as a Service
- Kubernetes Serverless
- Kubernetes Tutorials
- Cloud Attacks
- Cloud Attacks
- Malware Attacks
- Zero Day Attack
- Top 10 Cyber Security Threats
- Arbitrary Code Execution
- Cryptojacking
- AI Attacks
- Prompt Injection
- Backdoor Attacks
- Reverse Shell Attack
- Remote Code Execution
- Defense Evasion
- Honeypots in Cybersecurity
- Malware Analysis
- AI Malware
- Lateral Movement
- Advanced Malware Protection
- CNAPP
- AI Security
- Container Platforms
- Containerized Architecture
- Containerized Architecture
- Docker Secrets
- Container Runtime Interface
- Container Images
- Image Scanning
- Container Compliance
- Docker Security Best Practices
- Container Security
- Container Security Best Practices
- Container Security Tools
- ECS Security
- Network Segmentation
- Istio security
- runC
- Service Mesh
- Image Repository
- Container Escape
- Container Runtime
- Docker Container
- OSS Container Image Scanning Tools
- What Is a Container?
- Docker Images
- Containerization 101
- VM vs. Container
- Containerization vs. Virtualization
- Containerized Applications
- Microservices and Containerization
- Registry Scanning
- Docker CVEs
- Docker Monitoring
- Securing Containers with Docker Scanning
- Docker CIS Benchmark
- Seccomp
- Docker Alpine
- Docker API
- Docker Tools
- 100 Best Docker Tutorials
- Docker Alternatives
- Docker Swarm
- Docker Containers vs. Virtual Machines (VMs)
- Docker Architecture
- Docker Networking
- Docker Registries
- Docker Orchestration
- OpenShift vs Docker
- Container Cloud Computing
- Container DevOps
- Docker in Production
- Container Monitoring
- Container Advantages
- Docker Hub
- Serverless Architecture
- Supply Chain Security
- Supply Chain Compliance
- SolarWinds Attack
- Supply Chain Security
- Secure Software Development Lifecycle
- Software Supply Chain Attacks
- Dependency Confusion Attack
- SLSA
- SSDF
- Software Composition Analysis
- Security Misconfigurations
- Repojacking
- Privilege Escalation
- CI/CD Security
- SAST Security
- GitLab Security
- GitHub Secret Scanning
- OWASP Dependency-Check
- Software Bill of Materials
- SBOM Tools
- NPM Vulnerabilities
- Log4j Vulnerability
- Text4Shell
- Secrets Management
- Jenkins Security
- Yarn vs. NPM
- Source Code Leaks
- Container Image Signing
- Open Source Licenses
- Vulnerability Management
- Vulnerability Management Tools
- Vulnerability Scanning Process
- Vulnerability Management
- Vulnerability Scanning
- Vulnerability Prioritization
- Open Source Vulnerability Scanning
- Vulnerability Remediation
- Vulnerability Scanner
- Risk-Based Vulnerability Management
- Vulnerability Exploitability eXchange (VEX)
- Malware Detection
- Fileless Malware
- Attack Vectors
- Malicious Code
- Risk Posture
- Alert Fatigue in Cybersecurity
- Cyber Security Posture
- MITRE ATT&CK
- MITRE ATT&CK Framework
- LLM Security
- Code Scanning
- Attack Surface
- Attack Surface Management
- What Are Indicators of Compromise (IoC)?
- Secure Code
- Configuration Drift
- Trivy
- DevSecOps
- DevSecOps
- DevSecOps Pipeline
- DevSecOps Best Practices
- DevSecOps vs SecDevOps
- Threat Modeling
- Mean Time to Repair (MTTR)
- eBPF Linux
- Cloud DevOps
- DevOps Tools
- GitOps vs DevOps
- Code Security
- Secure Code Review
- DevOps Security
- Infrastructure as Code (IaC) Security
- Infrastructure as Code DevOps
- Executive Order 14028 (U.S. Cybersecurity Executive Order)
- Open Source Security
- Shift-Left Security
- Shift Right Testing and Security
- What Is SecOps (Security Operations)?
- SecDevOps
- DevSecOps Tools
- Linux Security
- Rocky Linux
- Azure DevOps
- Cloud Security
- Cloud Security
- Cloud Security Challenges
- Cloud Security Tools
- Code to Cloud
- Cloud Protection
- Cloud Security Frameworks
- Cloud Security Standards
- Cloud Security Controls
- Cloud Security Posture Management (CSPM)
- AI Workloads
- Cloud Digital Forensics
- Cloud Computing Security Architecture
- What Is Enterprise Cloud Security?
- Virtualized Security
- CSPM Tools
- Vulnerabilities in Cloud Computing
- Top 7 Risks of Cloud Computing
- Cloud Security Assessment
- Cloud Visibility
- Cloud Governance
- Cloud Security Strategy
- Cloud Security Policy
- DFIR
- Cloud Workloads
- Public Cloud Security
- Private Cloud vs. Public Cloud
- Runtime Security
- Azure Cloud Security
- Azure Security Best Practices
- Azure Security vs. AWS Security
- AWS GovCloud: Basics & How It Compares to Azure & GCP
- S3 Security
- Cloud Misconfiguration
- Terraform Security
- Hybrid Cloud Security
- Multi-Cloud Strategy
- Agentless vs. Agent-Based Security & Monitoring
- Cloud Infrastructure Security
- Gartner CSPM
- Cloud Security Scanner
- AWS CIS Benchmark
- Cloud Configuration Management
- Cloud Workload Protection (CWP)
- Cloud Workload Protection Platforms (CWPP)
- Cloud Workload Security
- Cloud Vulnerabilities and Tools that Can Help
- Google Cloud Security
- Shared Responsibility Model
- AWS Shared Responsibility Model
- AWS Cloud Security
- Multi Cloud Security
- Cloud Compliance
- Kubernetes in Production
- Cloud Detection And Response
Docker CIS Benchmark: Best Practices in Brief
Get the gist of the Docker CIS Benchmark recommendations for host configuration, Docker Daemon configuration and more, and learn to automate security testing.
What is Docker CIS Benchmark?
The Center for Internet Security (CIS) researches best practices for cybersecurity in containerized environments. CIS publishes the Docker CIS Benchmark, a comprehensive list of best practices that can help you secure Docker containers in production.
The Docker CIS Benchmark focuses on ensuring Docker containers runtimes are configured as securely as possible. You can download the full Docker CIS Benchmark for free from the Center for Internet Security.
This post summarizes Docker security best practices in the CIS benchmark, and provides details on three tools that can automatically test for Docker security best practices.
In this article, you will learn:
- Docker CIS Benchmark Best Practices
- Host Configuration
- Docker Daemon Configuration
- Docker Daemon Configuration Files
- Container Images and Build File Configuration
- Container Runtime Configuration
- Docker Security Operations
- Docker Swarm Configuration
- Docker Enterprise Configuration
- Docker Security Benchmark Tools
- Docker Bench for Security
- OpenSCAP Workbench
- Anchore
Docker CIS Benchmark Best Practices
The Docker CIS Benchmark is an extensive document with detailed recommendations about securing Docker in production. Below we provide a summary of the recommendations to help you get a head start on the CIS best practices.
Related content: read our guide to Docker architecture ›
Host Configuration
The CIS benchmark has several recommendations for securing the host on which the Docker engine runs.
| Applies To | Configuration Element | Recommendation |
| All Hosts | Host operating system | Ensure the OS is hardened |
| Docker binary | Ensure Docker version is up to date | |
| Linux Hosts | Disk partitions | Create a separate partition for containers |
| User accounts | Only grant access to Docker daemon to trusted users | |
| Docker files and directories, in particular: Docker.service Docker.socker /etc/default/docker /etc/docker/daemon.json /usr/bin/containerd /usr/sbin/runc | Ensure auditing is configured |
Docker Daemon Configuration
Here are the CIS recommendations for securing the behavior of the Docker daemon, the background process that manages all containers on the Docker host.
| Configuration Element | Recommended Setting |
| Network traffic between containers on default bridge | restricted |
| Logging level | info |
| Docker permission to make changes to iptables | allow |
| Insecure registries | do not use |
| Aufs storage driver | do not use |
| TLS authentication | use and configure correctly |
| Default ulimit | configure as appropriate |
| User namespace support | enabled |
| Default cgroup usage | confirm it is used |
| Base device size | do not change until needed |
| Docker client command authorization | enabled |
| Centralized logging | configured |
| Remote logging | configured |
| Live restore | enabled |
| Userland Proxy | disabled |
| Custom seccomp profile | applied if appropriate |
| Experimental features | do not use in production |
| Container ability to gain new privileges | restricted |
Related content: read our guide to seccomp ›
Docker Daemon Configuration Files
The Docker Daemon configuration files are highly sensitive and can allow an attacker to control all containers on the host. Here are the CIS recommendations for securing these files.
This section covers Docker related files and directory permissions and ownership. Keeping the files and directories, that may contain sensitive parameters, secure is important for correct and secure functioning of Docker daemon.
| File/Directory to Secure | File Permissions | File Ownership |
| docker.service file | as appropriate | root:root |
| docker.socket file | 644 or stricter | root:root |
| /etc/docker directory | 755 or stricter | root:root |
| registry certificate file | 444 or stricter | root:root |
| TLS CA certificate file | 444 or stricter | root:root |
| Docker server certificate file | 444 or stricter | root:root |
| Docker server certificate key file | 400 or stricter | root:root |
| Docker socket file | 660 or stricter | root:docker |
| daemon.json file | 644 or stricter | root:root |
| /etc/default/docker file | 644 or stricter | root:root |
| /etc/sysconfig/docker file | 644 or stricter | root:root |
Container Images and Build File Configuration
Container base images and the build files used to create them dictate what is inside a container and how it operates. Ensure your base images and build files are safe and trusted. Here are CIS recommendations for images.
| Configuration Element | Recommendations |
| Permissions | 1. Create a user for the container 2. Remove setuid and setgid permissions |
| Container content | 1. Avoid unnecessary packages in the container 2. Only install verified packages 3. Define HEALTHCHECK instructions for the container 4. Enable content trust for Docker |
| Images | 1. Only use trusted base images 2. Perform security scans on images 3. Rebuild images to include security patches |
| Dockerfiles | 1. Ensure update instructions are not use alone 2. Use COPY instead of ADD 3. Do not store secrets in Dockerfiles |
Container Runtime Configuration
The way a container is configured to start has a major impact on security. Certain runtime parameters can lead to compromise of the host and the containers running on it. Here are CIS recommendations for container startup and runtime configuration.
| Configuration Element | Recommended Setting |
| AppArmor Profile | enabled (if applicable) |
| SELinux security options | set (if applicable) |
| Linux kernel | access restricted within containers |
| Privileged containers | do not use |
| Sensitive host directories | never mount on a container |
| sshd | never run on a container |
| ports | 1. Do not map privileged ports in containers 2. Only open needed ports |
| Host network namespace, IPC namespace, UTS namespace | do not set to shared |
| Container resource utilization | 1. Limit memory usage 2. Set CPU priority |
| Container root file system | mount as read only |
| Incoming container traffic | restrict to specific host interface |
| ‘on-failure’ restart policy | 5 |
| Host devices | do not expose to containers |
| Default ulimit | overwrite at runtime if needed |
| Mount propagation | do not set to shared |
| Default seccomp profile | do not disable |
| Docker exec commands | 1. Do not use with privileged option 2. Do not use with user=root |
| cgroup | 1. confirm it is used 2. ensure PIDs cgroup limit is used |
| container additional privileges | restrict |
| container health check | always perform at runtime |
| Docker commands | always use latest version of image |
| Docker default bridge “docker0” | do not use |
| Docker socket | never mount inside containers |
Docker Security Operations
Here are two key CIS recommendations with regard to securely operating Docker in production:
- Avoid image sprawl—it is a best practice not to use too many container images on the same host. All images on the host must be tagged. Untagged images or images with old tags may contain vulnerabilities.
- Avoid container sprawl—do not run too many containers on the same host. Having more containers on the host than optimal can expose the Docker host to mishandling, misconfiguration, and fragmentation.
Docker Swarm Configuration
Docker Swarm is Docker’s container orchestrator, which can manage clusters of containers and their lifecycle. Here are CIS recommendations for running Docker Swarm securely.
| Configuration Element | Recommended Setting |
| swarm mode | only enable if needed |
| manager nodes | create as few as possible |
| swarm services | bind to specific host interface |
| swarm overlay networks | encrypt |
| swarm secrets | Use Docker secret management commands |
| swarm manager mode | auto-lock |
| Management plane traffic | separate from data plane traffic |
| swarm manager auto-lock key | periodically rotate |
| Node certificates | |
| CA certificates |
Docker Enterprise Configuration
Docker Enterprise Edition (EE) by Mirantis is Docker’s enterprise-grade container platform for CentOS, RHEL, SUSE Linux Enterprise, Oracle Linux, and Windows Server. Here are CIS recommendations for securely running Docker EE.
| Applies To | Configuration Element | Recommendation |
| Universal Control Plane | LDAP authentication | configure |
| External certificates | use | |
| client certificate bundles for unprivileged users | enforce usage | |
| client role-based access control (RBAC) | enforce usage | |
| signed images | enforce usage | |
| per-user session limit | set to 3 or lower | |
| lifetime minutes | set to 15 or lower | |
| renewal threshold minutes | set to 0 | |
| Docker Trusted Registry | image vulnerability scanning | enable |
Related content: read our guide to container registry scanning ›
Docker Security Benchmark Tools
The Docker CIS Benchmark provides hundreds of detailed recommendations for Docker configuration. It is impractical to manually check all these best practices, especially for large container deployments. Below are three free tools that can help you automatically test that your containers meet the CIS best practices, and provide suggestions for remediation.
Docker Bench for Security
Docker Bench for Security is an open source script that audits containers according to the CIS benchmark’s best practices. It performs tests based on CIS benchmark recommendations, and logs its findings.
For each CIS benchmark recommendation, the tool provides Info (issues found), Warning (container does not meet the recommendation), or Pass (container is compliant). You can run the tool from the Docker host, directly on the host operating system, or clone it with Docker Compose.
OpenSCAP Workbench
OpenSCAP includes multiple open security benchmark guidelines, configuration criteria, and open source tools that can help test for security issues, including the CIS benchmark. It is focused on the NIST-certified Secure Content Automation Protocol (SCAP), which includes many automated security policies.
OpenSCAP goes wider than the CIS recommendations, including many other recommendations, some of which are not specific to a containerized environment. It can be useful for identifying additional security concerns not covered by the CIS guidelines.
Anchore
Anchore Engine is a tool for analyzing container images. It can identify CVE-based vulnerabilities in containers, and also lets users define custom policies and use them to evaluate Docker images. Policies can be based on whitelist, blacklist, credentials, file contents, and configurations.
While anchor does not officially support CIS benchmark guidelines, you can define custom policies to cover all benchmark recommendations. For each policy, Anchore returns a pass or fail result.
Anchor can run as a Docker container image, within Kubernetes, or as a standalone binary. It integrates with popular CI/CD tools like Jenkins and GitLab.
- Top OSS Container Image Scanning Tools
- What Is a Container?
- Docker Images
- What Is Containerization?
- What Is a Virtual Machine (VM)?
- Containerization vs. Virtualization: Key Differences and Use Cases
- Containerized Applications: Components, Use Cases, and Best Practices
- What Are Microservices?
- Registry Scanning: Top 5 Risks and 3 Steps to a Secure Registry
- A Guide to Managing Docker CVEs
- Understand Docker Monitoring – And Its Relationship to Container Security
- Securing Containers with Docker Scanning
- Seccomp
- Docker Alpine
- Docker API
- Docker Tools
- 100 Best Docker Tutorials
- Docker Alternatives
- Docker Swarm
- Docker vs. Virtual Machines: Key Differences
- What Is Docker Architecture?
- What Is Docker Networking? A Practical Guide
- What Is a Docker Registry?
- Docker Orchestration: Swarm vs Kubernetes
- OpenShift vs Docker: Understanding the Difference
- Containers in Cloud Computing: Enabling Portability, Agility and Automation
- Container DevOps: Building Containers into the DevOps Process
- Docker in Production: Getting it Right
- Understanding Container Monitoring: Best Practices and Tools
- Container Advantages: 7 Reasons to Adopt a Containerized Architecture
- Using Docker Hub Responsibly: 4 Security Best Practices
- Show more
Aqua Cloud Native Application Protection Platform (CNAPP)
Go cloud native with the experts!