Skip to main content

Devtools / Container Registry / Controls / DEV

Implement Vulnerability Scanning for Artifacts

CCC.CntrReg.CN01 · Orchestration

Ensure that container images and artifacts stored in the container registry are scanned for vulnerabilities to identify and remediate security issues before deployment.

Related Capabilities

IDTitleDescription
CCC.CntrReg.CP05Image ScanningProvides vulnerability scanning for container images (built-in or through integration to scanning services) to detect security issues and generate reports for known CVEs (Common Vulnerabilities and Exposures).

Related Threats

IDTitleDescription
CCC.CntrReg.TH01Vulnerabilities in Artifacts are ExploitedAttackers exploit known vulnerabilities in container images or artifacts stored in the registry, leading to unauthorized access, data breaches, or system compromise.

Assessment Requirements

IDTextApplicability
CCC.CntrReg.CN01.AR01Attempt to push an artifact with known vulnerabilities to the registry and observe if it is flagged or rejected by the vulnerability scanning process.tlp-red, tlp-amber

Guideline Mappings

FrameworkIDRemarks
NIST-CSFID.RA-1
NIST_800_53RA-5
NIST_800_53SI-5