NIST SP 800-190
Image Security

NIST SP 800-190 SP800-190-3.3: Embedded Secrets in Images

Prevent secrets, API tokens, private keys, and credentials from being baked into container images at build time. Use a runtime secrets manager and scan images for secrets before they are pushed to the registry.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Other controls in Image Security

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.