💼 [ECR.2] ECR private repositories should have tag immutability configured
- ID:
/frameworks/aws-fsbp-v1.0.0/ecr/02
Description
Amazon ECR Tag Immutability enables customers to rely on the descriptive tags
of an image as a reliable mechanism to track and uniquely identify images.
An immutable tag is static, which means each tag refers to a unique image.
This improves reliability and scalability as the use of a static tag will always
result in the same image being deployed. When configured, tag immutability prevents
the tags from being overridden, which reduces the attack surface.
Similar
- AWS Security Hub
- Internal
Similar Sections (Give Policies To)
Sub Sections
Section | Sub Sections | Internal Rules | Policies | Flags | Compliance |
---|
Policies (1)
Internal Rules
Rule | Policies | Flags |
---|
✉️ dec-x-767cce1f | 1 | |