Inventory - Container Checksum #1026
Labels
constraint: completeness
enhancement
New feature or request
model: ssp
scope: constraints
type: task
Constraint Task
Consistent with issue #813, these constraints focus on ensuring that container and operating system images MUST have a checksum FedRAMP Extension. Images are always represented as "software" components with an "image" asset type.
This is a FedRAMP extension.
NOTE - These constraints are
level="ERROR"
Intended Outcome
Container image checksums are used to verify the integrity of a container image and ensure it has not been tampered with or corrupted. Additionally, many container image vulnerability scanner outputs will reference container images by checksum, so this information is needed in the inventory to cross-reference reported vulnerabilities against the inventory of (container) images.
Syntax Type
This is a FedRAMP constraint in the FedRAMP-specific namespace.
Allowed Values
There are no relevant allowed values.
Metapath(s) to Content
Purpose of the OSCAL Content
No response
Dependencies
No response
Acceptance Criteria
oscal-cli metaschema metapath eval -e "expression"
.Other information
No response
The text was updated successfully, but these errors were encountered: