NIST SP 800-190
Runtime

NIST SP 800-190 SP800-190-3.15: Container File System Integrity

Run containers with read only root file systems where the application supports it. Use tmpfs or volumes for paths that need to be writable so that an attacker cannot persist modifications inside a running container.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Other controls in Runtime

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.