SV-235824r627599_rule
V-235824
SRG-APP-000176
DKER-EE-002410
CAT II
10
Update the SSP so that it includes documented processes for using Docker secrets commands to manage sensitive data that can be stored in key/value pairs. Examples include API tokens, database connection strings and credentials, SSL certificates, and the like. Follow docker secret documentation and use it to manage secrets effectively. This documentation can be found at https://docs.docker.com/engine/swarm/secrets/.
Ensure Docker's secret management commands are used for managing secrets in a Swarm cluster.
Refer to the System Security Plan (SSP) and verify that it includes documented processes for using Docker secrets commands to manage sensitive data that can be stored in key/value pairs. Examples include API tokens, database connection strings and credentials, SSL certificates, and the like.
If the SSP does not have this documented, then this is a finding.
V-235824
False
DKER-EE-002410
Ensure Docker's secret management commands are used for managing secrets in a Swarm cluster.
Refer to the System Security Plan (SSP) and verify that it includes documented processes for using Docker secrets commands to manage sensitive data that can be stored in key/value pairs. Examples include API tokens, database connection strings and credentials, SSL certificates, and the like.
If the SSP does not have this documented, then this is a finding.
M
5281