More Info:

Scan images stored in Google Container Registry (GCR) for vulnerabilities.

Risk Level

Medium

Address

Security, Reliability, Best Practice

Compliance Standards

HITRUST, SOC2, NISTCSF, PCIDSS

Triage and Remediation

Remediation

To remediate the misconfiguration “Ensure Image Vulnerability Scanning Is Performed” for GCP using GCP console, please follow the below steps:

  1. Open the Google Cloud Console and navigate to the Google Container Registry page.

  2. Select the project that contains the image that you want to scan.

  3. In the left-hand menu, select “Container Registry” under “Tools”.

  4. Click on the “Vulnerability scanning” tab.

  5. If vulnerability scanning is not enabled, click on the “Enable scanning” button.

  6. Choose the severity level for the vulnerabilities that you want to be notified about.

  7. Click on the “Save” button to enable vulnerability scanning.

  8. Once vulnerability scanning is enabled, you can view the scan results for all the images in your project.

  9. If any vulnerabilities are detected, you can take appropriate actions to remediate them.

By following these steps, you can ensure that image vulnerability scanning is performed in GCP, and you can remediate any vulnerabilities that are detected.

Additional Reading: