WKL-04.1: Baseline images are created using a CI/CD pipeline with integrated security testing. For workloads, this is primarily software composition analysis (SCA) and vulnerability analysis. Commonly called "shift-left" security, this ensures virtual workloads are starting with a good, secure baseline.
This may be automatically accessible when using your cloud provider's scanning service or your assessment tool also performs security scanning, but this will more typically need to be manually validated. Just the presence of offline/snapshot/image scanning does not necessarily mean the security testing occurs in the pipeline.
Control automation: Manual
AWS control specification: none
Azure control specification: none
GCP control specification: none
Third-party (CSPM/CNAPP) control specification: none
Description
Control automation: Manual
AWS control specification: none
Azure control specification: none
GCP control specification: none
Third-party (CSPM/CNAPP) control specification: none