- CAW-1.1
- Task role with wildcard or admin policy
- CAW-1.2
- Task exec command enabled — shell access into a running task
Assessed
- ECS services
- Task definitions
- Containers
- Load balancers
- IAM roles
- ECR repositories
- Account posture
Twenty-two ECS and ECR controls, and a role that can only read.
Task definitions are where AWS container security is actually decided — the network mode, the root user, the plaintext secret, the missing log driver. QubeAuditor assesses them directly, scans ECR images through Trivy, and assumes a cross-account role with an ExternalId that has no write permissions at all.
Book a baseline assessment- ECS services
- Task definitions
- Containers
- Load balancers
- IAM roles
- ECR repositories
- Account posture
Controls
The 22 Container Assurance Workload controls.
Curated ECS and ECR controls aligned to CIS and the AWS Foundational Security Best Practices, mapped through to NIS2 Article 21 measures. Each control names the exact condition it detects.
- CAW-3.1
- Service assigns a public IP
- CAW-3.2
- Security group allows public ingress to the task port
- CAW-3.3
- Task definition uses host network mode
- CAW-4.1
- Load balancer listener without TLS
- CAW-5.1
- Container without log configuration
- CAW-5.2
- Cluster Container Insights disabled
- CAW-6.1
- Plaintext secret in an environment variable
- CAW-6.2
- Secret-shaped variable name without a Secrets Manager reference
- CAW-7.1
- Image from an unapproved registry
- CAW-7.2
- Image uses a mutable or latest tag
- CAW-7.3
- ECR repository scan-on-push disabled
- CAW-7.4
- ECR repository tag immutability disabled
- CAW-7.5
- ECR repository without a lifecycle policy
- CAW-8.1
- Privileged container
- CAW-8.2
- Task definition shares the host PID or IPC namespace
- CAW-8.3
- Container without a read-only root filesystem
- CAW-8.4
- Container runs as root
- CAW-8.5
- Container adds Linux capabilities
- CAW-8.6
- Fargate task on an outdated platform version
- CAW-8.7
- Container without CPU and memory limits
Images
ECR, scanned properly.
Repository configuration and image content are two different problems, and both get assessed.
Repository posture
Scan-on-push, tag immutability and lifecycle policy. A repository without immutable tags means the image you assessed and the image running in production can differ while carrying the same name.
Image content
ECR images are scanned through Trivy for vulnerabilities, with the affected package, the fixed version where one exists, and which task definitions reference the image.
Provenance
Images pulled from registries outside your approved set are flagged regardless of whether they are vulnerable, because unapproved provenance is a supply-chain finding in its own right under NIS2 21(2)(d).
Access
A cross-account role that cannot change anything.
Onboarding uses role assumption with an ExternalId, and the supplied policy is read-only. There is no remediation path in the agent, so the role cannot be used to modify your account even by the platform itself.
- method
- cross-account role assumption with an ExternalId
- policies
- supplied as both Terraform and CloudFormation, kept equivalent
- scope
- ECS, ECR, IAM read, load balancers, logging configuration, and account posture through Prowler
- writes
- none
- denied
- reported as unassessed, never as an implicit pass
Where the supplied role does not carry a permission a check needs, the check is reported as unassessed and the report states what was attempted, what executed and what was denied. Broader Prowler coverage requires a broader profile, and which profile is in use is recorded rather than assumed.
Account posture
The account underneath the cluster.
Prowler assesses AWS account posture alongside the container estate, because several NIS2 measures are only evidenced at account scope.
- logging
- CloudTrail multi-region logging — the audit trail evidencing incident handling under 21(2)(b)
- identity
- Root-account MFA and delegated-administrator review — cloud-identity evidence for 21(2)(i) and 21(2)(j)
- encryption
- Default EBS volume encryption — part of the cryptography evidence under 21(2)(h)
Questions
AWS questions
Or start with something you already have
Bring one recent security report from the vendor operating your estate. We will map how many of its findings have an accountable owner, a verification state, and evidence you could hand to an auditor.
Book a baseline assessmentContact
Book a baseline assessment
Tell us what you run and who operates it. We will come back with a scope, a timeline and a fixed price for one estate.