💼 [ECS.5] ECS containers should be limited to read-only access to root filesystems
- ID:
/frameworks/aws-fsbp-v1.0.0/ecs/05
Description​
If the readonlyRootFilesystem parameter is set to true in an Amazon ECS task
definition, the ECS container is given read-only access to its root file system.
This reduces security attack vectors because the container instance's root
file system can't be tampered with or written to without explicit volume mounts
that have read-write permissions for file system folders and directories.
Enabling this option also adheres to the principle of least privilege.
Similar​
- AWS Security Hub
- Internal
Similar Sections (Give Policies To)​
Sub Sections​
| Section | Sub Sections | Internal Rules | Policies | Flags | Compliance |
|---|