This is the multi-page printable view of this section. Click here to print.

Return to the regular view of this page.

DoD

The DoD policy packs map the DISA Container Image Creation and Deployment Guide and the Platform One IronBank requirements to checks that the Anchore Enterprise policy engine can evaluate against container images.

Current IronBank policy pack version: Anchore DoD Iron Bank v2026.1

Current DISA policy pack version: Anchore DISA Image Creation and Hardening Guide v20241001

Introduction

Anchore Enterprise provides two DoD policies:

  • DISA Image Creation and Deployment Guide: provided by the Defense Information Systems Agency (DISA), the agency that supplies IT and communications support to the U.S. government and federal organizations. This policy provides security and compliance checks that align with specific NIST 800-53 and NIST 800-190 controls as described in the DoD Container Image Creation and Deployment Guide.
  • IronBank: validates images against DoD security and compliance requirements in alignment with U.S. Air Force security standards at Platform One and IronBank, written in accordance with DoD Enterprise DevSecOps Reference Design documentation.

DISA

Anchore Enterprise checks for the following control specifications in the DISA policy. Rule sets marked Required in the Configuration column must be configured for your environment before the policy is used. See Configure Rule Sets.

ControlCheckConfiguration
AC-6(10)Container image must have permissions removed from executables that allow a user to execute software at higher privileges
CM-6(b)Confidential data checksRequired
CM-7(1b)Network port exposure checksRequired
CM-7(a)Container image build content checksRequired
IA-5(2a)Base image checks
IA-5(7)Embedded credentials
RA-5Software vulnerability checks
SC-5Image checks
SC-8(2)Base image checks
SI-2(6)Image software update and layer checks

IronBank

The IronBank policy includes checks across the following areas:

AreaChecks
Image build and contentDockerfile, User, File, Software, Transfer Protocol
Application and platform componentsIstio, Node.js, Etcd, Snort, Jenkins, Grafana, UBI7, Chef, Sonarqube, Prometheus, Postgres, Nginx, OpenJDK, Twistlock, Keycloak, Fluentd, Elasticsearch, Kibana, Redis, Apache HTTP, Apache Tomcat

Use the Pack

Import the pack like any other policy. See Manage Policies for the GUI, AnchoreCTL, and API workflows. Once imported, scope it to the registries and repositories it should apply to through Policy Mappings, then activate it as the account’s default policy.

Configure Rule Sets

The IronBank policy does not require rule set configuration. The DISA policy, however, requires configuration for the control specifications marked Required in the DISA table above. The control specifications are represented by rule sets, edited from the policy’s Edit action in the Anchore Enterprise GUI (see Manage Policies).