Skip to main content

💼 [ECR.2] ECR private repositories should have tag immutability configured

  • ID: /frameworks/aws-fsbp-v1.0.0/ecr/02

Description

Amazon ECR Tag Immutability enables customers to rely on the descriptive tags of an image as a reliable mechanism to track and uniquely identify images. An immutable tag is static, which means each tag refers to a unique image. This improves reliability and scalability as the use of a static tag will always result in the same image being deployed. When configured, tag immutability prevents the tags from being overridden, which reduces the attack surface.

Similar

Similar Sections (Give Policies To)

SectionSub SectionsInternal RulesPoliciesFlagsCompliance
💼 NIST SP 800-53 Revision 5 → 💼 CA-9(1) Internal System Connections _ Compliance Checks23no data
💼 NIST SP 800-53 Revision 5 → 💼 CM-2 Baseline Configuration727no data
💼 NIST SP 800-53 Revision 5 → 💼 CM-8(1) System Component Inventory _ Updates During Installation and Removal2no data

Sub Sections

SectionSub SectionsInternal RulesPoliciesFlagsCompliance

Policies (1)

PolicyLogic CountFlagsCompliance
🛡️ AWS ECR Repository Image Tag Mutability is set to Mutable🟢1🟢 x6no data

Internal Rules

RulePoliciesFlags
✉️ dec-x-767cce1f1