Ensure that image vulnerability scanning is enabled for your Azure Kubernetes Service (AKS) clusters to help detect vulnerabilities in container images, ensure compliance with security standards, and protect your clusters from potential threats. Enabling Microsoft Defender for Cloud for containers (i.e., Microsoft Defender for Containers) adds a critical layer of security by proactively identifying vulnerabilities in the foundation of your containerized applications. This helps prevent attacks before they can occur.
Enabling image vulnerability scanning for Azure Kubernetes Service (AKS) clusters helps proactively identify and address security vulnerabilities in your container images and language packages, reducing the risk of exploitation and protecting your applications. When you enable Microsoft Defender for Containers, it integrates security features across your containerized environments, including AKS clusters.
Audit
To determine if image vulnerability scanning is enabled for your Azure Kubernetes Service (AKS) clusters, perform the following operations:
Remediation / Resolution
To enable image vulnerability scanning for your Microsoft Azure Kubernetes Service (AKS) clusters, perform the following operations:
References
- Azure Official Documentation
- Vulnerability assessments for supported environments
- Security Control V2: Posture and Vulnerability Management
- Microsoft Defender for Cloud overview
- Microsoft Defender for Cloud pricing
- Azure PowerShell Documentation
- az account list
- az account set
- az security pricing show
- az security pricing create