What NIST SP 800-190 (Containers) requires
Compliance with NIST SP 800-190 guidance for application container security necessitates a multi-layered control framework that addresses risks across the entire lifecycle. This node enforces critical security postures, beginning with the image build process where each image_uses_trusted_base is mandatory, ensuring builds originate from approved, signed sources. A comprehensive vulnerability assessment must pass, reflected by the image_vulnerability_scan_passed status, which strictly adheres to a max_critical_vulnerabilities_allowed threshold of zero. The node also mandates that secrets_managed_externally, injected via a secure orchestrator mechanism to avoid their insecure embedding within images. Supply chain integrity is maintained by verifying registry_requires_authentication for all operations. In the orchestration layer, access control is paramount; therefore, orchestrator_rbac_enabled is required to enforce least privilege. Default-deny network communication is enforced through active network_policies_enforced, isolating workloads. At runtime, the security posture is hardened by mandating that a container_runs_as_non_root and that a runtime_security_profile_applied, like Seccomp or AppArmor, restricts system call privileges. The container's integrity is further protected when an immutable_filesystem_enabled configuration prevents unauthorized modifications. Finally, the underlying host infrastructure must be demonstrably secure, requiring that the host_os_hardened against a standard like a CIS benchmark and that all host_access_audited to maintain a verifiable log of administrative actions.
Pillar: Cloud & SaaS · Authority: NIST (National Institute of Standards and Technology) · Version: 1.1.0 · Last updated:
Primary source: https://doi.org/10.6028/NIST.SP.800-190
SHA-256 integrity: 910698a248edb1f339ac8f6d1894280d292787abc0baa4c0bc98cf2bf279913b
Primary Citations — 6 traced to source
- {"citation":"NIST Special Publication 800-190, Application Container Security Guide","url":"https://csrc.nist.gov/publications/detail/sp/800-190/final","description":"The primary source document that establishes the operational framework and security concerns for container technologies, defining the five major risk areas."}
- {"citation":"NIST Special Publication 800-53 Rev. 5, Security and Privacy Controls for Information Systems and Organizations","url":"https://csrc.nist.gov/publications/detail/sp/800-53/rev-5/final","description":"Provides the underlying catalog of security controls (e.g., Access Control, Configuration Management, System Integrity) that SP 800-190 recommendations help implement within a containerized environment."}
+ 4 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
- Discovery (free): /api/v1/nodes/nist-800-190-container.json — 6-field metadata
- Vault (full node): /api/v1/vault/nodes/nist-800-190-container.json — full 13-key payload, $0.01 USDC (L402/Skyfire/Direct Base)
- Canonical URL: https://bidda.com/intelligence/nist-800-190-container
- Back to registry: Browse all 10,085 compliance nodes