---
title: "Docker Image Security: Do It Early, Often, and Continuously"
description: To ensure Docker image security, both DevOps and Security must collaborate and move secure, well-built application stacks through the continuous delivery pipeline.
image: https://blog.aquasec.com/hubfs/Docker_Image_Security-_1.jpg
---

[Aqua Security](https://www.aquasec.com)

- [Products](https://www.aquasec.com/products/aqua-cloud-native-security-platform/)
- [Solutions](https://www.aquasec.com/solutions/kubernetes-container-security/)
- [Resources](https://www.aquasec.com/resources/)
- [Company](https://www.aquasec.com/about-us/)

Search [Sign In](https://cloud.aquasec.com/signin) [Try Aqua](https://www.aquasec.com/demo/)

[Aqua Blog](https://blog.aquasec.com/)

![Docker Image Security: Do It Early, Often, and Continuously](https://blog.aquasec.com/hs-fs/hubfs/Docker_Image_Security-_1.jpg?width=870&height=421&name=Docker_Image_Security-_1.jpg)

[![Picture of Tsvi Korren](https://blog.aquasec.com/hs-fs/hubfs/Aqua%20People/tsvi_korren.jpg?width=48&height=48&name=tsvi_korren.jpg)](https://blog.aquasec.com/author/tsvi-korren)

[Tsvi Korren](https://blog.aquasec.com/author/tsvi-korren)

 August 15, 2016

# Docker Image Security: Do It Early, Often, and Continuously

When producing the Docker images that will run as containers, development organizations find themselves with unprecedented influence over the application security posture of their organization.

Whereas in traditional SDLC a programmer only delivers his or her own code, now a programmer can deliver Docker images that contain, in addition to the application code, elements of the base operating system, supporting components, and built-in configuration. This means that the security of operating systems and server components is no longer determined at time of deployment. It is decided much earlier.

Take, for example, a controlled Server environment, where the operating system is selected carefully, patched frequently and configured according to security best practices. Then, a Docker image is deployed and run as a container. This image is a black box, it is running on a well-configured server, but brings with it a completely different operating system and application stack.

[![Download 'Security for Containers: 5 Things DevOps Need to Do' eBook Today!](https://no-cache.hubspot.com/cta/default/1665891/910e6158-0bd8-4bd2-ab76-2c93a96f640d.png)](https://cta-redirect.hubspot.com/cta/redirect/1665891/910e6158-0bd8-4bd2-ab76-2c93a96f640d)

To put it in real terms: your extremely well-configured CentOS is now essentially running a version of Ubuntu, taken from the Internet, with an unknown configuration. Adding to the risk is the inability to patch in-place, the speed in which images move through the pipeline and the dynamic way containers are deployed.

The separation of duties between Development and Security -- that division between writing the code and securing the runtime platform -- is no longer sustainable. Development and Security must come together and collaborate in a proper way to move secure, well-built application stacks through the continuous delivery pipeline.

There is a series of steps that organizations can take in order to bring Development and Security closer together:

- Establish and communicate clear and consistent lists of approved base images, application components and coding practices.
- Evaluate image security at development and adopt a practice that will fail the build if the image fails to meet vulnerability thresholds and other security standards.
- Continue to evaluate the security of the images at each stage of the CD pipeline.
- Restrict the ability to update existing images at rest, either on the registry or inside the Docker engine.
- Make the security stance of running containers known to all stakeholders: from application owners, to security and developers.

Experience has taught us that relying on humans alone for the rigorous application of security procedures delivers, at best, patchy results. Where possible, procedures should be automated. This has never been truer than in container-rich DevOps environments, where the speed of delivery and the number of changes are greater than ever before.

A solution that automates and tracks Docker image security – from their inception to their instantiation as containers in runtime environments – must span both the development and runtime environments. While there are many solutions out there that can scan Docker images for vulnerabilities (including open-source tools) they fail to provide a continuous, automated solution to the entire lifecycle of the image. This is where Aqua’s solution can help, with its full lifecycle automation, integration with CI/CD tools and image policy enforcement in runtime - we call it  [Continuous Image Assurance](https://www.aquasec.com/use-cases/continuous-image-assurance/)™.

[![Picture of Tsvi Korren](https://blog.aquasec.com/hs-fs/hubfs/Aqua%20People/tsvi_korren.jpg?width=120&height=120&name=tsvi_korren.jpg)](https://blog.aquasec.com/author/tsvi-korren)

#### [Tsvi Korren](https://blog.aquasec.com/author/tsvi-korren)

Tsvi Korren, CISSP, has been an IT security professional for more than 20 years. Tsvi is currently the Field CTO at Aqua, where he leads the effort of enabling organizations to use containers and improve their security through DevSecOps.

<https://www.linkedin.com/in/tsvikorren/>

[Docker Security](https://blog.aquasec.com/topic/docker-security)

<http://www.facebook.com/sharer/sharer.php?u=https://blog.aquasec.com/docker-image-security-do-it-early-often-and-continuously> <http://twitter.com/share?url=https://blog.aquasec.com/docker-image-security-do-it-early-often-and-continuously&text=Docker%20Image%20Security:%20Do%20It%20Early,%20Often,%20and%20Continuously> <https://www.linkedin.com/shareArticle?mini=true&url=https://blog.aquasec.com/docker-image-security-do-it-early-often-and-continuously&title=Docker%20Image%20Security:%20Do%20It%20Early,%20Often,%20and%20Continuously>

### Subscribe to Email Updates

### Popular Posts

### Filter by Topic

- [Security Threats (120)](https://blog.aquasec.com/topic/security-threats)
- [Container Security (118)](https://blog.aquasec.com/topic/container-security)
- [Kubernetes Security (97)](https://blog.aquasec.com/topic/kubernetes-security)
- [Cloud Native Security (84)](https://blog.aquasec.com/topic/cloud-native-security)
- [Aqua Open Source (49)](https://blog.aquasec.com/topic/aqua-open-source)
- [Image Vulnerability Scanning (49)](https://blog.aquasec.com/topic/image-vulnerability-scanning)
- [AWS Security (38)](https://blog.aquasec.com/topic/aws-security)
- [Runtime Security (38)](https://blog.aquasec.com/topic/runtime-security)
- [Aqua Security (37)](https://blog.aquasec.com/topic/aqua-security)
- [Vulnerability Management (36)](https://blog.aquasec.com/topic/vulnerability-management)
- [Docker Security (35)](https://blog.aquasec.com/topic/docker-security)
- [Software Supply Chain Security (29)](https://blog.aquasec.com/topic/software-supply-chain-security)
- [CSPM (28)](https://blog.aquasec.com/topic/cspm)
- [Cloud compliance (25)](https://blog.aquasec.com/topic/cloud-compliance)
- [DevSecOps (25)](https://blog.aquasec.com/topic/devsecops)
- [Container Vulnerability (24)](https://blog.aquasec.com/topic/container-vulnerability)
- [CI/CD (17)](https://blog.aquasec.com/topic/ci-cd)
- [CNAPP (17)](https://blog.aquasec.com/topic/cnapp)
- [Supply Chain Attacks (13)](https://blog.aquasec.com/topic/supply-chain-attacks)
- [Secrets (12)](https://blog.aquasec.com/topic/secrets)
- [Application Security (11)](https://blog.aquasec.com/topic/application-security)
- [Serverless-Security (11)](https://blog.aquasec.com/topic/serverless-security)
- [Kubernetes (10)](https://blog.aquasec.com/topic/kubernetes)
- [ebpf (10)](https://blog.aquasec.com/topic/ebpf)
- [Cloud security (9)](https://blog.aquasec.com/topic/cloud-security)
- [Host Security (9)](https://blog.aquasec.com/topic/host-security)
- [Advanced malware protection (8)](https://blog.aquasec.com/topic/advanced-malware-protection)
- [Cloud security conferences (8)](https://blog.aquasec.com/topic/cloud-security-conferences)
- [Fargate (8)](https://blog.aquasec.com/topic/fargate)
- [Hybrid Cloud Security (8)](https://blog.aquasec.com/topic/hybrid-cloud-security)
- [Malware Attacks (8)](https://blog.aquasec.com/topic/malware-attacks)
- [Cloud Workload Protection Platform CWPP (7)](https://blog.aquasec.com/topic/cloud-workload-protection-platform-cwpp)
- [Attack Vector (6)](https://blog.aquasec.com/topic/attack-vector)
- [Container platforms (6)](https://blog.aquasec.com/topic/container-platforms)
- [Google cloud security (6)](https://blog.aquasec.com/topic/google-cloud-security)
- [OpenShift (6)](https://blog.aquasec.com/topic/openshift)
- [SBOMs (6)](https://blog.aquasec.com/topic/sboms)
- [Secure VM (6)](https://blog.aquasec.com/topic/secure-vm)
- [Security Policy (6)](https://blog.aquasec.com/topic/security-policy)
- [Infrastructure-as-Code (IaC) (5)](https://blog.aquasec.com/topic/infrastructure-as-code-iac)
- [Security Automation (5)](https://blog.aquasec.com/topic/security-automation)
- [Windows Containers (5)](https://blog.aquasec.com/topic/windows-containers)
- [Azure security (4)](https://blog.aquasec.com/topic/azure-security)
- [Docker containers (4)](https://blog.aquasec.com/topic/docker-containers)
- [Kubernetes RBAC (4)](https://blog.aquasec.com/topic/kubernetes-rbac)
- [Service Mesh (4)](https://blog.aquasec.com/topic/service-mesh)
- [Container Deployment (3)](https://blog.aquasec.com/topic/container-deployment)
- [IBM Cloud (3)](https://blog.aquasec.com/topic/ibm-cloud)
- [Microservices (3)](https://blog.aquasec.com/topic/microservices)
- [Nano-Segmentation (3)](https://blog.aquasec.com/topic/nano-segmentation)
- [Agentless Security (2)](https://blog.aquasec.com/topic/agentless-security)
- [FaaS (2)](https://blog.aquasec.com/topic/faas)
- [Network Firewall (2)](https://blog.aquasec.com/topic/network-firewall)
- [VMware Tanzu (2)](https://blog.aquasec.com/topic/vmware-tanzu)
- [code security (2)](https://blog.aquasec.com/topic/code-security)
- [Advanced Threat Mitigation (1)](https://blog.aquasec.com/topic/advanced-threat-mitigation)
- [Cloud VM (1)](https://blog.aquasec.com/topic/cloud-vm)
- [Customer Support (1)](https://blog.aquasec.com/topic/customer-support)
- [Drift Prevention (1)](https://blog.aquasec.com/topic/drift-prevention)
- [Kubernetes Authorization (1)](https://blog.aquasec.com/topic/kubernetes-authorization)
- [Network (1)](https://blog.aquasec.com/topic/network)
- [shift Left security (1)](https://blog.aquasec.com/topic/shift-left-security)

Show more...

[Aqua Container Security](https://www.aquasec.com)

<https://www.facebook.com/AquaSecTeam> <https://twitter.com/AquaSecTeam> <https://www.linkedin.com/company/aquasecteam> <https://www.youtube.com/c/AquasecTeam>

Copyright © 2023 Aqua Security Software Ltd.

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Tsvi Korren",
    "url" : "https://blog.aquasec.com/author/tsvi-korren"
  },
  "dateModified" : "2019-01-01T17:01:37.728Z",
  "datePublished" : "2016-08-15T12:23:27.000Z",
  "headline" : "Docker Image Security: Do It Early, Often, and Continuously",
  "image" : [ "https://blog.aquasec.com/hubfs/Docker_Image_Security-_1.jpg" ],
  "mainEntityOfPage" : {
    "@id" : "https://blog.aquasec.com/docker-image-security-do-it-early-often-and-continuously",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://blog.aquasec.com/hubfs/SVG__2020%20Aqua%20Logo%20Color.svg"
    },
    "name" : "Aqua Security"
  }
}
```

```json
{
  "@context" : "http://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Tsvi Korren"
  },
  "dateModified" : "August 15, 2016, 12:23:28 PM",
  "datePublished" : "2016-08-15 12:23:27",
  "description" : "To ensure Docker image security, both DevOps and Security must collaborate and move secure, well-built application stacks through the continuous delivery pipeline.",
  "headline" : "Docker Image Security: Do It Early, Often, and Continuously",
  "image" : {
    "@type" : "ImageObject",
    "url" : "http://cdn2.hubspot.net/hubfs/1665891/Docker_Image_Security-_1.jpg"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://f.hubspotusercontent40.net/hubfs/1665891/SVG__2020%20Aqua%20Logo%20Color.svg"
    },
    "name" : "Aqua Security"
  }
}
```