0309-docker-env-priv-Docker Environment File Permissions Not Set to 644 or More Restrictive¶
Rule ID¶
- 0309-docker-env-priv
Category¶
- container
Level¶
- warn
Compatible Versions¶
- Linux
Description¶
- The Docker daemon uses the Docker environment file to set the runtime environment for the Docker daemon. On machines using systemd to manage services, the file is
/etc/sysconfig/docker. On other systems, the environment file is/etc/default/docker. Verify that the environment file permissions are correctly set to644or more restrictive.
Scan Frequency¶
0 */30 * * *
Rationale¶
- The Docker environment file contains sensitive parameters that may alter the behavior of the Docker daemon at runtime. Therefore, it should be writable only by
rootto maintain file integrity.
Risk Item¶
- Container Security
Audit Method¶
- Execute the following command to verify that the environment file permissions are set to
644or more restrictive:
Remediation¶
- Execute the following command:
This sets the file permissions of the environment file to 644.
Impact¶
- None
Default Value¶
- By default, the file permissions for this file are correctly set to
644.
References¶
CIS Controls¶
- None