NIST SP 800-190
Supply Chain

NIST SP 800-190 SP800-190-3.4: Image Trust and Provenance

Sign container images during the build process and verify those signatures at admission to clusters. Track image provenance back to source repository commits and build pipelines that produced them.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Other controls in Supply Chain

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.