Medium
ECR
Regional
ECR private repositories should have tag immutability configured
NIST
Description
This control checks whether a private ECR repository has tag immutability enabled.
Remediation
To configure tag immutability for an ECR repository, refer to the Amazon Elastic Container Registry User Guide.
Steps
- Open the Amazon ECR console.
- Choose the repository.
- Under the Image Tag Mutability section, select 'Immutable'.
- Save the changes.
Compliance
NIST