|
+OPS-34.01AC |
1. ÜbersichtOPS-34.01ACThe policies and procedures additionally describe measures along the life cycle of containers that address at least the following aspects:1. Container images are cryptographically signed and the signing key securely stored (cf. CRY-10) to ensure their authenticity and integrity; 2. Container behaviour is monitored and restricted using runtime security controls; and 3. Software products used for the provision of container images are, where possible, regularly scanned for known vulnerabilities or malicious components in container images and dependencies. In case of third-party and open source software products used for the provision of container images, scanning procedures comply with the policies and procedures defined in DEV-14.
1.1 Referenzen1.2 Identifizierte Anforderungen1.2 Related Regulation2. Identifizierte Anforderungen
3. Related Regulations
|