The Docker Bench for Security
github.com
github.com
If you choose to engage Cavirin or use its solution, be sure to do a full POC and make sure your use case and scale are fully covered and the product is reliable, I know there were many quality issues in the past (full disclosure, I worked there for a while). I'm sure there are other vendors or open source projects that can do a much better job in a Docker-specific environment. The CIS content itself probably is golden, the implementation I'd be skeptical about.
The CIS website (look under the "Docker" category) at https://www.cisecurity.org/cis-benchmarks seems to list a few vendor solutions.
https://iase.disa.mil/stigs/Pages/index.aspx
https://www.open-scap.org/resources/documentation/security-c...
Either way, blindly taking these policies, or from a vendor like Calvirin, who I'm sure are good, is a recipe for disaster when you and/or fellow admins do not review all hundreds of controls and know your environment very well, if previous life experience taught me anything.