Posture Control (ZPC)
Adding a Vulnerability Scanning Rule for Container Registries
You can add a vulnerability scanning rule and set up a schedule for the scan to run at regular intervals. ZPC scans the container images within the selected container registries based on the schedule and displays the scan results on the Vulnerability Management page. To learn more, see About Vulnerability Management. You can also get detailed insights of the findings on the vulnerability dashboard.
Prerequisites
You must first onboard your Amazon Web Services (AWS), Microsoft Azure, or Google Cloud Platform (GCP) cloud accounts. To learn more, see About Onboarding Cloud Accounts. After onboarding the accounts, you must configure the vulnerability integration for the required accounts before adding a scanning rule. To learn more, see About Vulnerability Integrations.
Adding a Vulnerability Scanning Rule for Container Registries
To add a scanning rule:
- Go to Cloud Posture > Vulnerability Management.
- On the Vulnerability Management page, select the Scanning Rules tab.
- Click Create Scan Rule.
- Under General:
- For Scan Rule Name, enter a unique name for the rule.
- For Vulnerability Scanning Type, select Cloud Container Registries.
- For Cloud Type, select Amazon Web Services, Microsoft Azure, or Google Cloud Platform.
- Click Next.
- Under Resource Scope:
- Select the Age of the Images for Scan from the drop-down menu.
The repositories contain several image tags. You can select specific images that were added or updated during a particular duration (1 month, 3 months, 6 months, 12 months) so the scanning is triggered for images within that duration.
- Select the Registry from the drop-down menu.
- Select the Repository from the drop-down menu.
- (Optional) Enter any additional Image Tags that must be included for scanning.
- Click Next.
The Scope Test Result window displays the number of container images or workloads that are included for vulnerability scanning.
- Click Accept and Proceed.
- Under Scan Schedule, select Daily or Weekly to schedule the scan every day or once a week.
- Select the time when the scan must be triggered.
- Click Next.
- Review the scan rule. Click the Edit icon if you want to make any changes.
- Click Finish.
You can view the newly added scan rule on the Vulnerability Management page under Scanning Rules.