NIST SP 800-190
Runtime

NIST SP 800-190 SP800-190-3.12: Container Runtime Hardening

Configure the container runtime to reduce kernel level attack surface using seccomp profiles, AppArmor or SELinux, and capability dropping. Ensure these controls apply to every container, not just hand picked services.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Other controls in Runtime

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.