Skip to main content

πŸ’Ό [Inspector.2] Amazon Inspector ECR scanning should be enabled

  • Contextual name: πŸ’Ό [Inspector.2] Amazon Inspector ECR scanning should be enabled
  • ID: /frameworks/aws-fsbp-v1.0.0/inspector/02
  • Located in: πŸ’Ό Inspector

Description​

Amazon Inspector scans container images stored in Amazon Elastic Container Registry (Amazon ECR) for software vulnerabilities to generate package vulnerability findings. When you activate Amazon Inspector scans for Amazon ECR, you set Amazon Inspector as your preferred scanning service for your private registry. This replaces basic scanning, which is provided at no charge by Amazon ECR, with enhanced scanning, which is provided and billed through Amazon Inspector. Enhanced scanning gives you the benefit of vulnerability scanning for both operating system and programming language packages at the registry level. You can review findings discovered using enhanced scanning at the image level, for each layer of the image, on the Amazon ECR console. Additionally, you can review and work with these findings in other services not available for basic scanning findings, including AWS Security Hub and Amazon EventBridge.

Similar​

Similar Sections (Give Policies To)​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό PCI DSS v4.0.1 β†’ πŸ’Ό 11.3.1 Internal vulnerability scans are performed.3

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlags