Bidda Sovereign Intelligence · 10,085 Verified Nodes · 39 Sovereign Pillars

NIST SP 800-190 (Containers)

Compliance with NIST SP 800-190 guidance for application container security necessitates a multi-layered control framework that addresses risks across the…

What NIST SP 800-190 (Containers) requires

Compliance with NIST SP 800-190 guidance for application container security necessitates a multi-layered control framework that addresses risks across the entire lifecycle. This node enforces critical security postures, beginning with the image build process where each image_uses_trusted_base is mandatory, ensuring builds originate from approved, signed sources. A comprehensive vulnerability assessment must pass, reflected by the image_vulnerability_scan_passed status, which strictly adheres to a max_critical_vulnerabilities_allowed threshold of zero. The node also mandates that secrets_managed_externally, injected via a secure orchestrator mechanism to avoid their insecure embedding within images. Supply chain integrity is maintained by verifying registry_requires_authentication for all operations. In the orchestration layer, access control is paramount; therefore, orchestrator_rbac_enabled is required to enforce least privilege. Default-deny network communication is enforced through active network_policies_enforced, isolating workloads. At runtime, the security posture is hardened by mandating that a container_runs_as_non_root and that a runtime_security_profile_applied, like Seccomp or AppArmor, restricts system call privileges. The container's integrity is further protected when an immutable_filesystem_enabled configuration prevents unauthorized modifications. Finally, the underlying host infrastructure must be demonstrably secure, requiring that the host_os_hardened against a standard like a CIS benchmark and that all host_access_audited to maintain a verifiable log of administrative actions.

Pillar: Cloud & SaaS · Authority: NIST (National Institute of Standards and Technology) · Version: 1.1.0 · Last updated:

Primary source: https://doi.org/10.6028/NIST.SP.800-190

SHA-256 integrity: 910698a248edb1f339ac8f6d1894280d292787abc0baa4c0bc98cf2bf279913b

Primary Citations — 6 traced to source

  • {"citation":"NIST Special Publication 800-190, Application Container Security Guide","url":"https://csrc.nist.gov/publications/detail/sp/800-190/final","description":"The primary source document that establishes the operational framework and security concerns for container technologies, defining the five major risk areas."}
  • {"citation":"NIST Special Publication 800-53 Rev. 5, Security and Privacy Controls for Information Systems and Organizations","url":"https://csrc.nist.gov/publications/detail/sp/800-53/rev-5/final","description":"Provides the underlying catalog of security controls (e.g., Access Control, Configuration Management, System Integrity) that SP 800-190 recommendations help implement within a containerized environment."}

+ 4 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.

Access

⚠ Important: Human Verification Required

Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.