Skip to main content
A Singapore Government Agency Website How to identify
Official website links end with .gov.sg
Government agencies communicate via .gov.sg websites (e.g. go.gov.sg/open). Trusted websites
Secure websites use HTTPS
Look for a lock () or https:// as an added precaution. Share sensitive information only on official, secure websites.

Container Security

Controls to secure container building, distribution, and deployment.

Last updated 24 March 2026

CS-1: Unique Base Container Image Tags

Control Statement

Control Recommendations

Risk Statement

CS-2: Minimal Base Container Images

Control Statement

Control Recommendations

Risk Statement

CS-3: Runtime Container Secrets

Control Statement

Control Recommendations

Risk Statement

CS-4: Non-Privileged Container User

Control Statement

Control Recommendations

Risk Statement

CS-5: Dockerfile Linting

Control Statement

Control Recommendations

Risk Statement

CS-6: Read-Only Container Root Filesystem

Control Statement

Control Recommendations

Risk Statement

CS-7: Container Image Scanning

Control Statement

Control Recommendations

Risk Statement

Parameters

CS-8: Private Container Image Registries

Control Statement

Control Recommendations

Risk Statement

CS-9: Container Orchestrator API Access Control

Control Statement

Control Recommendations

Risk Statement

CS-10: Container Workload Segmentation

Control Statement

Control Recommendations

Risk Statement

CS-11: Container Runtime Security

Control Statement

Control Recommendations

Risk Statement