SlideShare a Scribd company logo
Deep Dive into
Container Security
Shiri Ivtsan, Product Manager
Monolith to Microservice and Container
Container Lifecycle
Build RunShip
Open Source
96.8%
Of the developers rely on
Open Source components
Number of Reported Open Source
Vulnerabilities GREW by 51.2% in 2017
https://www.whitesourcesoftware.com/open-source-vulnerability-management-report
Open Source Challenges
https://www.whitesourcesoftware.com/open-source-vulnerability-management-report
1One challenging area in particular
is pronounced
https://www.whitesourcesoftware.com/open-source-vulnerability-management-report
The Common Way of Handling
Security Vulnerabilities
Security teams analyze
and prioritize
vulnerabilities
Sending emails or
opening issues/tickets
Closing the loop on
resolution is hard
Bridging the Gap is a Must
Security DevOps Developers
How to Bake Security Into
Existing Workflows
Let’s Start With Some Questions
▪ Do you use a private registry?
▪ When using a public registry, are the images
signed?
▪ Do you regularly scan your images?
▪ How quickly are images rebuilt with security
fixes?
CI/CD Gates
Integrate security testing into
your build and CI process DevOps
Build
TestDeploy
CI/CD Gates
Use automated policies to
fail builds with issues
Security Layers
Scan across the lifecycle:
Trusted Sources
Use private registries and sign
images from public registries
Step 3: Don’t Use Defaults
Enable Role-Based Access
Control (RBAC) in your
container orchestration
Step 3: Don’t Use Defaults
Use Namespaces to Establish
Security Boundaries
Manage Deployments
Prevent deployment of images
with known vulnerabilities
Manage Deployments
Prevent deployment of
containers that require root
Manage Deployments
Validate image signatures
Monitor for new vulnerabilities
Manage Deployments
Thank You!

More Related Content

PDF
Open Source Security at Scale- The DevOps Challenge 
PDF
Innocent Vulnerabilities vs. Malicious Backdoors: How to Manage Your Risk
PDF
Taking Open Source Security to the Next Level
PDF
CI/CD pipeline security from start to finish with WhiteSource & CircleCI
PDF
The Challenges of Scaling DevSecOps
PDF
From Zero To Hero: Continuous Container Security in 4 Simple Steps- A WhiteSo...
PDF
The State of Open Source Vulnerabilities Management
PPTX
The Devops Challenge: Open Source Security Throughout the DevOps Pipline- A W...
Open Source Security at Scale- The DevOps Challenge 
Innocent Vulnerabilities vs. Malicious Backdoors: How to Manage Your Risk
Taking Open Source Security to the Next Level
CI/CD pipeline security from start to finish with WhiteSource & CircleCI
The Challenges of Scaling DevSecOps
From Zero To Hero: Continuous Container Security in 4 Simple Steps- A WhiteSo...
The State of Open Source Vulnerabilities Management
The Devops Challenge: Open Source Security Throughout the DevOps Pipline- A W...

What's hot (20)

PDF
Tackling the Risks of Open Source Security: 5 Things You Need to Know
PPTX
Automating Open Source Security: A SANS Review of WhiteSource
PDF
Open Source Security: How to Lay the Groundwork for a Secure Culture
PPTX
DevSecOps outline
PPTX
DevSecOps
PDF
From Zero to DevSecOps: How to Implement Security at the Speed of DevOps
PDF
RoboCop: Bringing Law and Order to CI/CD
PDF
Tackling the Container Iceberg:How to approach security when most of your sof...
PDF
Introducing DevSecOps by Madhu Akula - Software Security Bangalore - May 27 2...
PPTX
DevSecOps Beginners Guide : How to secure process in DevOps with OpenSource
PDF
Getting to Know Security and Devs: Keys to Successful DevSecOps
PDF
PIACERE - DevSecOps Automated
PDF
Container Security: What Enterprises Need to Know
PPTX
Open Source Libraries - Managing Risk in Cloud
PPTX
Secure DevOPS Implementation Guidance
PPTX
SCS DevSecOps Seminar - State of DevSecOps
PPTX
Agile and Secure SDLC
PDF
Empowering Financial Institutions to Use Open Source With Confidence
PPTX
A journey from dev ops to devsecops
PPTX
From Zero to DevSecOps: How to Implement Security at the Speed of DevOps
Tackling the Risks of Open Source Security: 5 Things You Need to Know
Automating Open Source Security: A SANS Review of WhiteSource
Open Source Security: How to Lay the Groundwork for a Secure Culture
DevSecOps outline
DevSecOps
From Zero to DevSecOps: How to Implement Security at the Speed of DevOps
RoboCop: Bringing Law and Order to CI/CD
Tackling the Container Iceberg:How to approach security when most of your sof...
Introducing DevSecOps by Madhu Akula - Software Security Bangalore - May 27 2...
DevSecOps Beginners Guide : How to secure process in DevOps with OpenSource
Getting to Know Security and Devs: Keys to Successful DevSecOps
PIACERE - DevSecOps Automated
Container Security: What Enterprises Need to Know
Open Source Libraries - Managing Risk in Cloud
Secure DevOPS Implementation Guidance
SCS DevSecOps Seminar - State of DevSecOps
Agile and Secure SDLC
Empowering Financial Institutions to Use Open Source With Confidence
A journey from dev ops to devsecops
From Zero to DevSecOps: How to Implement Security at the Speed of DevOps
Ad

Similar to Deep Dive into Container Security (20)

PDF
From Zero to Hero: Continuous Container Security in 4 Simple Steps
PDF
Barriers to Container Security and How to Overcome Them
PPTX
Understanding container security
PDF
DevSecOps: The Open Source Way
PDF
Why Should Developers Care About Container Security?
PDF
ATO 2022 - Why should devs care about container security.pdf
PDF
Container Stranger Danger - Why should devs care about container security
PDF
Python Web Conference 2022 - Why should devs care about container security.pdf
PPTX
Workshop: Hands-On Container Image Security Mastering Sigstore for Unbreachab...
PPTX
A question of trust - understanding Open Source risks
PDF
DevSecOps: The Open Source Way
PPTX
An In-depth look at application containers
PDF
Securing Microservices in Containerized Environments
PDF
DevOpsDaysRiga 2017: Chris Van Tuin - A DevOps State of Mind: Continuous Secu...
PPTX
DevSecCon London 2017: when good containers go bad by Tim Mackey
PPTX
DevSecOps in a cloudnative world
PDF
[muCon2017]DevSecOps: How to Continuously Integrate Security into DevOps
PDF
Security Patterns for Microservice Architectures - SpringOne 2020
PDF
Security Patterns for Microservice Architectures
PDF
Why should developers care about container security?
From Zero to Hero: Continuous Container Security in 4 Simple Steps
Barriers to Container Security and How to Overcome Them
Understanding container security
DevSecOps: The Open Source Way
Why Should Developers Care About Container Security?
ATO 2022 - Why should devs care about container security.pdf
Container Stranger Danger - Why should devs care about container security
Python Web Conference 2022 - Why should devs care about container security.pdf
Workshop: Hands-On Container Image Security Mastering Sigstore for Unbreachab...
A question of trust - understanding Open Source risks
DevSecOps: The Open Source Way
An In-depth look at application containers
Securing Microservices in Containerized Environments
DevOpsDaysRiga 2017: Chris Van Tuin - A DevOps State of Mind: Continuous Secu...
DevSecCon London 2017: when good containers go bad by Tim Mackey
DevSecOps in a cloudnative world
[muCon2017]DevSecOps: How to Continuously Integrate Security into DevOps
Security Patterns for Microservice Architectures - SpringOne 2020
Security Patterns for Microservice Architectures
Why should developers care about container security?
Ad

More from WhiteSource (15)

PDF
Securing Container-Based Applications at the Speed of DevOps
PDF
Fire alarms vs. Fire hoses: Keeping up with Dependencies
PDF
DevSecOps: Closing the Loop from Detection to Remediation
PPTX
5 Things Every CISO Needs To Know About Open Source Security - A WhiteSource ...
PDF
Winning open source vulnerabilities without loosing your deveopers - Azure De...
PDF
SAST (Static Application Security Testing) vs. SCA (Software Composition Anal...
PDF
Top Open Source Licenses Explained
PPTX
WhiteSource Webinar What's New With WhiteSource in December 2018
PPTX
WhiteSource Webinar-New Research Reveals Key Strategy to Manage Open Source S...
PPTX
The State of Open Source Vulnerabilities - A WhiteSource Webinar
PDF
Find Out What's New With WhiteSource September 2018- A WhiteSource Webinar
PPTX
The Top 3 Strategies To Reduce Your Open Source Security Risks - A WhiteSour...
PPTX
Find Out What's New With WhiteSource May 2018- A WhiteSource Webinar
PPTX
Strategies for Improving Enterprise Application Security - a WhiteSource Webinar
PPTX
How temenos manages open source use, the easy way combined
Securing Container-Based Applications at the Speed of DevOps
Fire alarms vs. Fire hoses: Keeping up with Dependencies
DevSecOps: Closing the Loop from Detection to Remediation
5 Things Every CISO Needs To Know About Open Source Security - A WhiteSource ...
Winning open source vulnerabilities without loosing your deveopers - Azure De...
SAST (Static Application Security Testing) vs. SCA (Software Composition Anal...
Top Open Source Licenses Explained
WhiteSource Webinar What's New With WhiteSource in December 2018
WhiteSource Webinar-New Research Reveals Key Strategy to Manage Open Source S...
The State of Open Source Vulnerabilities - A WhiteSource Webinar
Find Out What's New With WhiteSource September 2018- A WhiteSource Webinar
The Top 3 Strategies To Reduce Your Open Source Security Risks - A WhiteSour...
Find Out What's New With WhiteSource May 2018- A WhiteSource Webinar
Strategies for Improving Enterprise Application Security - a WhiteSource Webinar
How temenos manages open source use, the easy way combined

Recently uploaded (20)

PDF
Digital Strategies for Manufacturing Companies
PPTX
Lecture 3: Operating Systems Introduction to Computer Hardware Systems
PDF
How to Migrate SBCGlobal Email to Yahoo Easily
PDF
EN-Survey-Report-SAP-LeanIX-EA-Insights-2025.pdf
PDF
Wondershare Filmora 15 Crack With Activation Key [2025
PDF
Which alternative to Crystal Reports is best for small or large businesses.pdf
PDF
T3DD25 TYPO3 Content Blocks - Deep Dive by André Kraus
PDF
Claude Code: Everyone is a 10x Developer - A Comprehensive AI-Powered CLI Tool
PDF
wealthsignaloriginal-com-DS-text-... (1).pdf
PDF
Digital Systems & Binary Numbers (comprehensive )
PDF
Nekopoi APK 2025 free lastest update
PDF
Odoo Companies in India – Driving Business Transformation.pdf
PPTX
Introduction to Artificial Intelligence
PDF
PTS Company Brochure 2025 (1).pdf.......
PDF
Internet Downloader Manager (IDM) Crack 6.42 Build 42 Updates Latest 2025
PPTX
VVF-Customer-Presentation2025-Ver1.9.pptx
PPTX
Agentic AI Use Case- Contract Lifecycle Management (CLM).pptx
PDF
SAP S4 Hana Brochure 3 (PTS SYSTEMS AND SOLUTIONS)
PDF
Why TechBuilder is the Future of Pickup and Delivery App Development (1).pdf
PPTX
Operating system designcfffgfgggggggvggggggggg
Digital Strategies for Manufacturing Companies
Lecture 3: Operating Systems Introduction to Computer Hardware Systems
How to Migrate SBCGlobal Email to Yahoo Easily
EN-Survey-Report-SAP-LeanIX-EA-Insights-2025.pdf
Wondershare Filmora 15 Crack With Activation Key [2025
Which alternative to Crystal Reports is best for small or large businesses.pdf
T3DD25 TYPO3 Content Blocks - Deep Dive by André Kraus
Claude Code: Everyone is a 10x Developer - A Comprehensive AI-Powered CLI Tool
wealthsignaloriginal-com-DS-text-... (1).pdf
Digital Systems & Binary Numbers (comprehensive )
Nekopoi APK 2025 free lastest update
Odoo Companies in India – Driving Business Transformation.pdf
Introduction to Artificial Intelligence
PTS Company Brochure 2025 (1).pdf.......
Internet Downloader Manager (IDM) Crack 6.42 Build 42 Updates Latest 2025
VVF-Customer-Presentation2025-Ver1.9.pptx
Agentic AI Use Case- Contract Lifecycle Management (CLM).pptx
SAP S4 Hana Brochure 3 (PTS SYSTEMS AND SOLUTIONS)
Why TechBuilder is the Future of Pickup and Delivery App Development (1).pdf
Operating system designcfffgfgggggggvggggggggg

Deep Dive into Container Security