Control: 9.1 Ensure alerts are enabled for vulnerabilities discovered in container images in Container Registry
Description
With IBM CloudTM Security Advisor, you can instantly view the security posture of your IBM Cloud services through a single, centralized dashboard. The service receives security information from various sources and displays any security alerts or vulnerabilities that require your attention in the service dashboard. Out of the box, there are several pre-populated cards in your dashboard. These findings are from security services in IBM Cloud, but you can also add cards or custom partner solutions so that all of your security tools can be accessed from the same location.
Through pre-integrated findings, you can monitor:
- Certificates that you manage with IBM Cloud Certificate Manager
- Vulnerabilities in container images that are stored in IBM Cloud Container Registry
Remediation
All remediation steps must be applied to the vulnerability in the container image by image owners.
Console:
- Log in to IBM Cloud at https://cloud.ibm.com.
- Click Menu icon > Security and Compliance.
- In the Gain insight section of the navigation, click Configure-->Alerts.
- Click Create channel.
- Provide a Name, optional Description, and Channel endpoint.
- Under Severity for notifications, Select Critical, High, and Medium
- Click Save.
Usage
Run the control in your terminal:
powerpipe control run ibm_compliance.control.cis_v100_9_1
Snapshot and share results via Turbot Pipes:
powerpipe loginpowerpipe control run ibm_compliance.control.cis_v100_9_1 --share
SQL
This control uses a named query:
manual_control