NIST SP 800-190
Supply Chain

NIST SP 800-190 SP800-190-3.19: Supply Chain Risk for Third Party Images

Treat third party images as supply chain dependencies. Mirror them into an internal registry, scan and approve them before use, and track which workloads consume each external image so that a future vendor compromise can be triaged quickly.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Other controls in Supply Chain

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.