SV-260920r966117_rule
V-260920
SRG-APP-000141-CTR-000315
CNTR-MK-000520
CAT II
10
If not using MKE on Ubuntu host operating system, this is Not Applicable.
If AppArmor is not in use, this is Not Applicable.
This check must be executed on all nodes in a cluster.
Run on all nonprivileged containers using an AppArmor profile:
Via CLI:
Linux: Install AppArmor (if not already installed).
Create/import an AppArmor profile (if not using the "docker-default" profile). Put the profile in "enforcing" model. Execute the following command as a trusted user on the host operating system to run the container using the customized AppArmor profile:
docker run [options] --security-opt="apparmor:[PROFILENAME]" [image] [command]
When using the "docker-default" default profile, run the container using the following command instead:
docker run [options] --security-opt apparmor=docker-default [image] [command]
If MKE is not being used on an Ubuntu host operating system, this is Not Applicable.
If AppArmor is not in use, this is Not Applicable.
This check must be executed on all nodes in a cluster.
Via CLI:
Linux: Execute the following command as a trusted user on the host operating system:
docker ps -a -q | xargs -I {} docker inspect {} --format '{{ .Name }}: AppArmorProfile={{ .AppArmorProfile }}, Privileged={{ .HostConfig.Privileged }}' | grep 'AppArmorProfile=unconfined' | grep 'Privileged=false'
If any output, this is a finding.
V-260920
False
CNTR-MK-000520
If MKE is not being used on an Ubuntu host operating system, this is Not Applicable.
If AppArmor is not in use, this is Not Applicable.
This check must be executed on all nodes in a cluster.
Via CLI:
Linux: Execute the following command as a trusted user on the host operating system:
docker ps -a -q | xargs -I {} docker inspect {} --format '{{ .Name }}: AppArmorProfile={{ .AppArmorProfile }}, Privileged={{ .HostConfig.Privileged }}' | grep 'AppArmorProfile=unconfined' | grep 'Privileged=false'
If any output, this is a finding.
M
5595