Skip to content

Twenty-two ECS and ECR controls, and a role that can only read.

Task definitions are where AWS container security is actually decided — the network mode, the root user, the plaintext secret, the missing log driver. QubeAuditor assesses them directly, scans ECR images through Trivy, and assumes a cross-account role with an ExternalId that has no write permissions at all.

Book a baseline assessment
  • ECS services
  • Task definitions
  • Containers
  • Load balancers
  • IAM roles
  • ECR repositories
  • Account posture

Controls

The 22 Container Assurance Workload controls.

Curated ECS and ECR controls aligned to CIS and the AWS Foundational Security Best Practices, mapped through to NIS2 Article 21 measures. Each control names the exact condition it detects.

IAM · CAW-12 controls
CAW-1.1
Task role with wildcard or admin policy
CAW-1.2
Task exec command enabled — shell access into a running task
Network · CAW-33 controls
CAW-3.1
Service assigns a public IP
CAW-3.2
Security group allows public ingress to the task port
CAW-3.3
Task definition uses host network mode
Transport · CAW-41 control
CAW-4.1
Load balancer listener without TLS
Logging · CAW-52 controls
CAW-5.1
Container without log configuration
CAW-5.2
Cluster Container Insights disabled
Secrets · CAW-62 controls
CAW-6.1
Plaintext secret in an environment variable
CAW-6.2
Secret-shaped variable name without a Secrets Manager reference
Supply chain · CAW-75 controls
CAW-7.1
Image from an unapproved registry
CAW-7.2
Image uses a mutable or latest tag
CAW-7.3
ECR repository scan-on-push disabled
CAW-7.4
ECR repository tag immutability disabled
CAW-7.5
ECR repository without a lifecycle policy
Workload · CAW-87 controls
CAW-8.1
Privileged container
CAW-8.2
Task definition shares the host PID or IPC namespace
CAW-8.3
Container without a read-only root filesystem
CAW-8.4
Container runs as root
CAW-8.5
Container adds Linux capabilities
CAW-8.6
Fargate task on an outdated platform version
CAW-8.7
Container without CPU and memory limits

Images

ECR, scanned properly.

Repository configuration and image content are two different problems, and both get assessed.

Repository posture

Scan-on-push, tag immutability and lifecycle policy. A repository without immutable tags means the image you assessed and the image running in production can differ while carrying the same name.

Image content

ECR images are scanned through Trivy for vulnerabilities, with the affected package, the fixed version where one exists, and which task definitions reference the image.

Provenance

Images pulled from registries outside your approved set are flagged regardless of whether they are vulnerable, because unapproved provenance is a supply-chain finding in its own right under NIS2 21(2)(d).

Access

A cross-account role that cannot change anything.

Onboarding uses role assumption with an ExternalId, and the supplied policy is read-only. There is no remediation path in the agent, so the role cannot be used to modify your account even by the platform itself.

AWS onboardingRead-only
method
cross-account role assumption with an ExternalId
policies
supplied as both Terraform and CloudFormation, kept equivalent
scope
ECS, ECR, IAM read, load balancers, logging configuration, and account posture through Prowler
writes
none
denied
reported as unassessed, never as an implicit pass

Where the supplied role does not carry a permission a check needs, the check is reported as unassessed and the report states what was attempted, what executed and what was denied. Broader Prowler coverage requires a broader profile, and which profile is in use is recorded rather than assumed.

Account posture

The account underneath the cluster.

Prowler assesses AWS account posture alongside the container estate, because several NIS2 measures are only evidenced at account scope.

logging
CloudTrail multi-region logging — the audit trail evidencing incident handling under 21(2)(b)
identity
Root-account MFA and delegated-administrator review — cloud-identity evidence for 21(2)(i) and 21(2)(j)
encryption
Default EBS volume encryption — part of the cryptography evidence under 21(2)(h)

Questions

AWS questions

Or start with something you already have

Bring one recent security report from the vendor operating your estate. We will map how many of its findings have an accountable owner, a verification state, and evidence you could hand to an auditor.

Book a baseline assessment

Contact

Book a baseline assessment

Tell us what you run and who operates it. We will come back with a scope, a timeline and a fixed price for one estate.