High ECR Regional

ECR private repositories should have image scanning configured

NIST

Description

This control checks whether a private Amazon ECR repository has image scanning configured.


Remediation

To configure image scanning for an ECR repository, refer to the Amazon Elastic Container Registry User Guide.

Steps

  1. Open the Amazon ECR console.
  2. Choose the repository.
  3. Under the Image Scanning section, enable 'Scan on push'.
  4. Save the changes.

Compliance

NIST