Container Security
What is Container Security?
The practice of protecting containerised applications throughout their lifecycle, from image creation to runtime. Container security addresses image scanning, runtime protection, network policies, and orchestration platform security.
Terms that appear alongside container security
Each of these is named in at least one of the same controls as container security. The number is how many controls name both.
- isolation 5 shared controls
- compliance 5 shared controls
- hardening 5 shared controls
- integrity 4 shared controls
- authentication 4 shared controls
- configuration management 4 shared controls
- vulnerability 4 shared controls
- security posture 4 shared controls
Frameworks that govern container security
What the standards actually require on container security
Requirements naming container security across 6 standards, quoted from the control text.
Secure the O-Cloud platform + containers + secure configuration + patching per O-RAN WG11 Security Requirements + O-Cloud security profile.
ORANWG11-5 · O-Cloud, Container Security, Secure Configuration, Patching →Implement Acquisition Development Maintenance + Supplier Relationships + Vulnerability Management per MTCS SS 584. Acquisition Development and Maintenance (ISO 27001 Annex A.14) - secure coding standards (OWASP Top 10 + OWASP ASVS + CWE Top 25 + CERT Secure Co...
MTCS-Acquisition-Development-Maintenance-Supplier-Vulnerability-DevSecOps-SBOM-SDLC-SCA-API-Container · MTCS Acquisition + Development + Maintenance + Supplier + Vulnerability + DevSecOps + SBOM + SDLC + SCA →All parties maintain cargo and container integrity by using modern technology, conforming at a minimum to the requirements of the applicable international agreements on container security and sealing.
P2-S4 · Technology →Apply the applicable cloud-computing SRG and virtualization/container STIGs, covering hypervisor and virtual-machine hardening, container security, cloud identity and access management, and cloud network/data protection.
STIG-SRG-CLD · Cloud, virtualization and container STIG →ISMAP Cloud Infrastructure controls cover the underlying compute + network + storage + management plane. (1) Virtual Network Segmentation: VPC Virtual Private Cloud isolation + subnets + security groups + NACLs + microsegmentation + service mesh (Istio + Linke...
ISMAP-CloudInfrastructure-NetworkSegmentation-Container-Serverless-WorkloadProtection-Hardening-ConfigManagement · ISMAP Cloud Infrastructure - VPC Network Segmentation + Container/Serverless Security + Cloud Workload Protection (CWPP) + Image/Template Hardening + CIS Benchmarks + Configuration Management + IaC →Security Layer 1 Infrastructure per X.805 Clause 7.1: The Infrastructure Security Layer consists of network facilities (transmission facilities and network elements) protected by the security measures.
X805-Layer1-Infrastructure-Security-Transmission-Facilities-Network-Elements-Lines-Routers-Switches · ITU-T X.805 Security Layer 1 - Infrastructure Security + Transmission Facilities + Network Elements + Routers + Switches + Lines + Physical + Datacenter + Optical + Radio Access + Wireless + Wireline + Edge →Questions people ask about container security
What is Container Security?
Why is Container Security important for compliance?
Which compliance frameworks address Container Security?
Where can I learn more about Container Security?
See how Container Security applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.