Security standards for building and running containerised applications are formally defined
Sekit's Container security policy is a topic-specific policy under A.5.1 that sets written standards for how container images are built, stored and run.
The container-security policy sets written standards for building and storing container images, a deployment concern beside rather than inside A.8.25's SDLC scope.
Written standards for how container images are built, stored and run set the configuration baseline A.8.9 expects for containerized workloads specifically.