SIG Lite
Control TVM-09
Extractive Review Standard
How to answer 'Are container images scanned for vulnerabilities before deployment?' on a SIG Lite
Reviewer Guidance & Pitfalls
Explain how container base images and application containers are scanned in the container registry (e.g., ECR/GCR/Trivy) and deployed as immutable images.
Example Answer Passing Enterprise Audit
Compliant Response Template
Yes. All Docker container images are automatically scanned for OS and package vulnerabilities upon push to our container registry; images with unpatched critical CVEs cannot be deployed (SOC 2, CC7.1).
Filling out a CAIQ or SIG Lite right now?
QuietQuestionnaire automatically drafts answers with citations from your own SOC 2 report, catches contradictions reviewers reject, and locks exports behind cryptographic human sign-off.
Zero spam. 100% confidential. No credit card required.