WKL-04.1: Baseline images are created using a CI/CD pipeline with integrated security testing. For workloads, this is primarily software composition analysis (SCA) and vulnerability analysis. Commonly called "shift-left" security, this ensures virtual workloads are starting with a good, secure baseline. This may be automatically accessible when using your cloud provider's scanning service or your assessment tool also performs security scanning, but this will more typically need to be manually validated. Just the presence of offline/snapshot/image scanning does not necessarily mean the security testing occurs in the pipeline.
  • Control automation: Manual
  • AWS control specification: none
  • Azure control specification: none
  • GCP control specification: none
  • Third-party (CSPM/CNAPP) control specification: none

Description

  • Control automation: Manual
  • AWS control specification: none
  • Azure control specification: none
  • GCP control specification: none
  • Third-party (CSPM/CNAPP) control specification: none