Compliance Node Overview
MITRE D3FEND D3-CIA (Container Image Analysis) is a Model defensive technique. Analyzing a Container Image with respect to a set of policies. Container images are standalone collections of the executable code and content that are used to populate a container environment. They are usually created by either building a container from scratch or by building on top of an existing image pulled from a repository. Throughout the container build workflow, images should be scanned to identify: - outdated libraries, - known vulnerabilities, - or misconfigurations, such as insecure ports or permissions. In the D3FEND model it analyzes the container image. It counters ATT&CK technique T1525. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls AC-02, AC-03, AC-05, AC-06, CM-02, CM-05, CM-06, CM-07.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://d3fend.mitre.org/technique/d3f:ContainerImageAnalysis/
SHA-256 integrity: 152da2c0952bf5bfe917bc8e3e3b3e462b9f7136fc367a4b2eb9c4297b09032b
Primary Citations — 7 traced to source
- MITRE D3FEND Defensive Technique D3-CIA: Container Image Analysis (https://d3fend.mitre.org/technique/d3f:ContainerImageAnalysis/)
- MITRE D3FEND Model Tactic (https://d3fend.mitre.org/tactic/d3f:Model/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access