Skip to main content

💼 [ECS.4] ECS containers should run as non-privileged

  • Contextual name: 💼 [ECS.4] ECS containers should run as non-privileged
  • ID: /frameworks/aws-fsbp-v1.0.0/ecs/04
  • Located in: 💼 Elastic Container Service (ECS)

Description​

We recommend that you remove elevated privileges from your ECS task definitions. When the privilege parameter is true, the container is given elevated privileges on the host container instance (similar to the root user).

Similar​

Similar Sections (Give Policies To)​

SectionSub SectionsInternal RulesPoliciesFlags
💼 NIST SP 800-53 Revision 5 → 💼 AC-2(1) Account Management _ Automated System Account Management416
💼 NIST SP 800-53 Revision 5 → 💼 AC-3 Access Enforcement15537
💼 NIST SP 800-53 Revision 5 → 💼 AC-3(7) Access Enforcement _ Role-based Access Control14
💼 NIST SP 800-53 Revision 5 → 💼 AC-3(15) Access Enforcement _ Discretionary and Mandatory Access Control11
💼 NIST SP 800-53 Revision 5 → 💼 AC-5 Separation of Duties13
💼 NIST SP 800-53 Revision 5 → 💼 AC-6 Least Privilege102349

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlags