High
ECR
Regional
ECR private repositories should have image scanning configured
NIST
Description
This control checks whether a private Amazon ECR repository has image scanning configured.
Remediation
To configure image scanning for an ECR repository, refer to the Amazon Elastic Container Registry User Guide.
Steps
- Open the Amazon ECR console.
- Choose the repository.
- Under the Image Scanning section, enable 'Scan on push'.
- Save the changes.
Compliance
NIST