STIGhubSTIGhub
STIGsSearchCompare

STIGhub

A free tool to search and browse the entire DISA STIG library. Saves up to 75% in security compliance research time.

Navigation

  • Browse STIGs
  • Search
  • Compare Versions

Resources

  • About
  • Release Notes
  • VPAT
  • DISA STIG Library
STIGs updated 3 hours ago
Powered by Pylon
© 2026 Beacon Cloud Solutions, Inc. All rights reserved.
← Back to Container Platform Security Requirements Guide

V-233231

CAT II (Medium)

The container platform registry must remove old container images after updating versions have been made available.

Rule ID

SV-233231r961677_rule

STIG

Container Platform Security Requirements Guide

Version

V2R4

CCIs

CCI-002617

Discussion

Obsolete and stale images need to be removed from the registry to ensure the container platform maintains a secure posture. While the storing of these images does not directly pose a threat, they do increase the likelihood of these images being deployed. Removing stale or obsolete images and only keeping the most recent versions of those that are still in use removes any possibility of vulnerable images being deployed.

Check Content

Review container platform registry documentation and configuration to determine if organization-defined images contains latest approved vendor software image version. 

If organization-defined images do not contain the latest approved vendor software image version, this is a finding. 

Review container platform registry documentation and configuration to determine if organization-defined images are removed after updated versions have been installed. 

If organization-defined images are not removed after updated versions have been installed, this is a finding. 

Review container platform runtime documentation and configuration to determine if organization-defined images are executing latest image version from the container registry. 

If container platform runtime is not executing latest organization-defined images from the container platform registry, this is a finding.

Fix Text

Configure the container platform registry to update organization-defined images with current approved vendor version and remove obsolete images after updated versions have been installed. Configure the container platform runtime to execute latest organization-defined images from the container platform registry.