Skip to main content
Guidance

Using containerisation

Guidance on how to build and use containerised applications securely.

Page 2 of 4

Building Container Images

iStock.com/lemono
How to ensure that the container images you use are built securely and only include trusted software.

To run a container, you will normally need a container image. You might build this image yourself, acquire it from a third party, or it may be built for you by your cloud provider. Like any software package, if a container image includes malware, known vulnerabilities, or is configured insecurely, then running the container puts your data at risk.

This guidance is designed to help you to ensure that your container images only include the software you expect, and are configured to run securely by default. You will also need to ensure that you run your containers in a secure execution environment, as described in Running containers.







Published

Reviewed

Version

1.0