Skip to main content

πŸ’Ό [ECR.2] ECR private repositories should have tag immutability configured

  • Contextual name: πŸ’Ό [ECR.2] ECR private repositories should have tag immutability configured
  • ID: /frameworks/aws-fsbp-v1.0.0/ecr/02
  • Located in: πŸ’Ό Elastic Container Registry (ECR)

Description​

Amazon ECR Tag Immutability enables customers to rely on the descriptive tags of an image as a reliable mechanism to track and uniquely identify images. An immutable tag is static, which means each tag refers to a unique image. This improves reliability and scalability as the use of a static tag will always result in the same image being deployed. When configured, tag immutability prevents the tags from being overridden, which reduces the attack surface.

Similar​

Similar Sections (Give Policies To)​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό NIST SP 800-53 Revision 5 β†’ πŸ’Ό CA-9(1) Internal System Connections _ Compliance Checks15
πŸ’Ό NIST SP 800-53 Revision 5 β†’ πŸ’Ό CM-2 Baseline Configuration713
πŸ’Ό NIST SP 800-53 Revision 5 β†’ πŸ’Ό CM-8(1) System Component Inventory _ Updates During Installation and Removal

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlags