High
ECS
Regional
ECS task definitions should not share the host's process namespace
NISTISO 27001
Description
Checks if Amazon ECS task definitions are configured to share a host's process namespace with its containers. The control fails if the task definition shares the host's process namespace.
Remediation
To configure the pidMode on a task definition, update the task definition to not share the host's process namespace.
Steps
- Open the Amazon ECS console.
- Navigate to the 'Task Definitions' tab.
- Select the task definition to update.
- Edit the task definition and ensure 'pidMode' is not set to 'host'.
- Update the task definition.
Compliance
NISTISO 27001