Skip to content
Back to skills

Cis Docker 2.14

ASecurity

Ensure centralized and remote logging is configured

  • 2,182 stars
  • 0 votes
  • 0 copies
  • 2 views
  • Added September 3, 2026
securitygobashdockersecuritydocumentation

Security analysis

A100/100

Scanned September 3, 2026

npx -y skills add CyberStrikeus/CyberStrike --skill cis-docker-2.14 --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Cis Docker 2.14?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Cis Docker 2.14
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/cyberstrikeus-cis-docker-2-14/badge)](https://www.skillsdirectory.com/skills/cyberstrikeus-cis-docker-2-14)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: cis-docker-2.14
description: "Ensure centralized and remote logging is configured"
category: cis-docker
version: "1.8.0"
author: cyberstrike-official
tags: [cis, docker, linux, containers, daemon-configuration, logging, siem]
cis_id: "2.14"
cis_benchmark: "CIS Docker Benchmark v1.8.0"
tech_stack: [linux, docker]
cwe_ids: []
chains_with: []
prerequisites: []
severity_boost: {}
---

# Ensure centralized and remote logging is configured (Manual)

## Profile Applicability

• Level 2 - Docker - Linux

## Description

Docker supports various logging mechanisms. A preferable method for storing logs is one that supports centralized and remote management.

## Rationale

Centralized and remote logging ensures that all important log records are safe even in the event of a major data availability issue. Docker supports various logging methods and you should use the one that best corresponds to your IT security policy.

## Impact

None.

## Audit Procedure

Run `docker info` and ensure that the `Logging Driver` property set as appropriate.

```bash
docker info --format '{{ .LoggingDriver }}'
```

Alternatively, the below command would give you the `--log-driver` setting. If configured you should ensure that it is set appropriately.

```bash
grep "--log-driver" /etc/docker/daemon.json
```

The contents of `/etc/docker/daemon.json` should also be reviewed for this setting.

## Remediation

**Step 1:** Set up the desired log driver following its documentation.

**Step 2:** Start the docker daemon using that logging driver.

For example:

```bash
dockerd --log-driver=syslog --log-opt syslog-address=tcp://192.xxx.xxx.xxx
```

## Default Value

By default, container logs are maintained as json files

## References

1. https://docs.docker.com/config/containers/logging/configure/

## CIS Controls

**Controls Version:** v8

**Control:** 8.1 Establish and Maintain an Audit Log Management Process

Establish and maintain an audit log management process that defines the enterprise's logging requirements. At a minimum, address the collection, review, and retention of audit logs for enterprise assets. Review and update documentation annually, or when significant enterprise changes occur that could impact this Safeguard.

**IG 1:** ●
**IG 2:** ●
**IG 3:** ●

---

**Control:** 8.9 Centralize Audit Logs

Centralize, to the extent possible, audit log collection and retention across enterprise assets.

**IG 1:**
**IG 2:** ●
**IG 3:** ●

---

**Controls Version:** v7

**Control:** 6.6 Deploy SIEM or Log Analytic tool

Deploy Security Information and Event Management (SIEM) or log analytic tool for log correlation and analysis.

**IG 1:**
**IG 2:** ●
**IG 3:** ●

---

**Control:** 6.8 Regularly Tune SIEM

On a regular basis, tune your SIEM system to better identify actionable events and decrease event noise.

**IG 1:**
**IG 2:**
**IG 3:** ●

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…