Sekit CSF · Application Security · Technical
RCF-0141Container security
Technical tools scan container images and enforce runtime security policies automatically
Mapping at a glance
RCF-0141Container securityApplication Security · Technical
RCF-0141 maps to 9 controls across the published frameworks. +4 more in the table below. Open in the full graph →
Maps to ISO/IEC 27001:2022
Curated mapping with the reasoning, not just the codes.
A.8.7Protection against malwaresupportsContainer images are scanned before deployment and runtime restrictions enforced, extending A.8.7's malware protection into containerized workloads rather than only traditional endpoints.A.8.9Configuration managementsupportsScanning container images automatically before deployment and enforcing runtime restrictions is the technical enforcement A.8.9 expects, scoped to containers.A.8.29Security testing in development and acceptancesupportsThis Sekit technical control scans container images before they deploy and keeps enforcing restrictions once containers are running, catching drift that a pre-release scan alone would not see.
Maps to NIST CSF 2.0
Curated mapping with the reasoning, not just the codes.
PR.PS-01Configuration management appliedPR.PS-02Software maintainedPR.PS-04Logs generated for monitoring
Maps to Cyber Essentials
Curated mapping with the reasoning, not just the codes.
CE3.2Apply critical updates within 14 daysCE5.1Operate a malware protection mechanismCE5.2Restrict execution to approved software
Evidence that proves this control
What an auditor, or Sekit's evidence engine, asks for.
CI/CD pipeline security
The security controls in the automated build-and-deploy process, including containers and infrastructure-as-code.
From the Sekit evidence catalog
This topic through the other lenses
All Application Security controls
Ask Sekura: “What evidence proves RCF-0141?”
Also via MCP, free with account