Cloud 101CircleEventsBlog
Master CSA’s Security, Trust, Assurance, and Risk program—download the STAR Prep Kit for essential tools to enhance your assurance!

Download Publication

Challenges in Securing Application Containers and Microservices
Challenges in Securing Application Containers and Microservices

Challenges in Securing Application Containers and Microservices

Release Date: 07/16/2019

Application containers and a microservices architecture are being used to design, develop and deploy applications leveraging agile software development approaches such as Development Operations. Security must be embedded into these software development approaches. This document serves to identify challenges in securing application containers and microservices in the engineering of trustworthy secure systems through the lens of the Developer, Operator and Architect.


This publication is part of a larger series, you can find all the papers in the series here
Download this Resource

Prefer to access this resource without an account? Download it now.

Bookmark
Share
Related resources
Microservices Architecture Pattern
Microservices Architecture Pattern
Best Practices for Implementing a Secure Application Container Architecture - Japanese Translation
Best Practices for Implementing a Secure Applic...
Best Practices in Implementing a Secure Microservices Architecture
Best Practices in Implementing a Secure Microse...
Elevating Application Security Beyond “AppSec in a Box”
Elevating Application Security Beyond “AppSec in a Box”
Published: 10/02/2024
Five Levels of Vulnerability Prioritization: From Basic to Advanced
Five Levels of Vulnerability Prioritization: From Basic to Advanced
Published: 09/04/2024
Bridging the Gap: How to Ensure Seamless Collaboration Between Security & Development Teams
Bridging the Gap: How to Ensure Seamless Collaboration Between Secu...
Published: 07/08/2024
CSPM vs ASPM – What’s the Difference?
CSPM vs ASPM – What’s the Difference?
Published: 06/24/2024

Acknowledgements

Frank Geck Headshot Missing
Frank Geck

Frank Geck

Joshua Daniel Headshot Missing
Joshua Daniel

Joshua Daniel

Michael Roza
Michael Roza
Risk, Audit, Control and Compliance Professional at EVC

Michael Roza

Risk, Audit, Control and Compliance Professional at EVC

Since 2012 Michael has contributed to over 100 CSA projects completed by CSA's Internet of Things, Zero Trust/Software-Defined Perimeter, Top Threats, Cloud Control Matrix, Containers/Microservices, DevSecOps, and other working groups. He has also served as co-chair of CSA's Enterprise Architecture, Top Threats, and Security-as-a-Service working groups while also serving as the Standards Liaison Officer for IoT, ICS, EA, SECaaS, and Cloud K...

Read more

John Kinsella Headshot Missing
John Kinsella

John Kinsella

Atul Chaturvedi Headshot Missing
Atul Chaturvedi

Atul Chaturvedi

Joshua Cuellar Headshot Missing
Joshua Cuellar

Joshua Cuellar

Shyamkant Dhamke Headshot Missing
Shyamkant Dhamke

Shyamkant Dhamke

David Wayland Headshot Missing
David Wayland

David Wayland

John Osborne Headshot Missing
John Osborne

John Osborne

James Yaple Headshot Missing
James Yaple

James Yaple

Hillary Baron
Hillary Baron
Senior Technical Director - Research, CSA

Hillary Baron

Senior Technical Director - Research, CSA

Marina Bregkou
Marina Bregkou
Senior Research Analyst, CSA EMEA

Marina Bregkou

Senior Research Analyst, CSA EMEA

Anil Karmel
Anil Karmel
CEO, C2 Labs

Anil Karmel

CEO, C2 Labs

Anil Karmel is the Co-Founder and CEO of RegScale, which helps organizations start and stay compliant via the world's first real-time GRC platform. Formerly, Anil served as the National Nuclear Security Administration's (NNSA) Deputy Chief Technology Officer. Karmel began his government career as a Technical Staff Member of Los Alamos National Laboratory (LANL) and was responsible for inventing their cloud and collaboration technologies Kar...

Read more

Madhav Chablani Headshot Missing
Madhav Chablani
Consulting CIO, TippingEdge Consulting

Madhav Chablani

Consulting CIO, TippingEdge Consulting

Alex Rebo Headshot Missing
Alex Rebo
Enterprise Security Architect

Alex Rebo

Enterprise Security Architect

20+ year of Information Security / Assurance, Risk Management in private and public sectors.

CEA, PMP, CISSP, CCSP, ITIL, AWS CSA-A

Read more

Randall Brooks Headshot Missing
Randall Brooks

Randall Brooks

Amir Jerbi Headshot Missing
Amir Jerbi

Amir Jerbi

Cem Gurkok Headshot Missing
Cem Gurkok

Cem Gurkok

James McCloskey Headshot Missing
James McCloskey

James McCloskey

Ki-Hong Min Headshot Missing
Ki-Hong Min

Ki-Hong Min

Ken Stavinoha Headshot Missing
Ken Stavinoha

Ken Stavinoha

Shanthi Thomas Headshot Missing
Shanthi Thomas

Shanthi Thomas

Juanita Koilpillai
Juanita Koilpillai
Pioneer of Software Defined Perimeter

Juanita Koilpillai

Pioneer of Software Defined Perimeter

Juanita Koilpillai was Founder and CEO of Waverley Labs, a pioneer in software defined perimeters (SDP) and digital risk reduction solutions. She had 30 years’ experience researching and developing systems in computer security, network management and real-time distributed software. She led the open source software-defined perimeter (SDP) effort for ‘black’ apps in the cl...

Read more

Mark Yanalitis Headshot Missing
Mark Yanalitis

Mark Yanalitis

Michele Drgon Headshot Missing
Michele Drgon

Michele Drgon

John Wrobel Headshot Missing
John Wrobel

John Wrobel

Ramaswamy Chandramouli Headshot Missing
Ramaswamy Chandramouli

Ramaswamy Chandramouli

Yin Lee Headshot Missing
Yin Lee

Yin Lee

Mark Potter Headshot Missing
Mark Potter
CISO at Backblaze, Inc (BLZE)

Mark Potter

CISO at Backblaze, Inc (BLZE)

Ed Santiago Headshot Missing
Ed Santiago

Ed Santiago

Shawn Wells Headshot Missing
Shawn Wells

Shawn Wells

Vishwas Manral
Vishwas Manral
Founder at Precize Inc & Fellow at Cloud Security Alliance

Vishwas Manral

Founder at Precize Inc & Fellow at Cloud Security Alliance

Vishwas is the Founder at Precize Inc, a stealth Cloud and AI security startup. Vishwas is also the co-chair of CSA’s Serverless Working Group and the Chair of Cloud Security Alliance in Silicon Valley. He was the head of Cloud Native security and Chief Technologist at McAfee Enterprise + FireEye. Vishwas joined McAfee Enterprise when his com...

Read more

Jeff Barnes Headshot Missing
Jeff Barnes

Jeff Barnes

Aaron Lippold Headshot Missing
Aaron Lippold

Aaron Lippold

Kina Shah Headshot Missing
Kina Shah

Kina Shah

Shankar Chebrolu
Shankar Chebrolu
Director of Security Architecture at Red Hat and President of CSA Triangle Chapter

Shankar Chebrolu

Director of Security Architecture at Red Hat and President of CSA Triangle Chapter

Ashish Kurmi Headshot Missing
Ashish Kurmi

Ashish Kurmi

Michaela Iorga
Michaela Iorga
Senior Security Technical Lead for Cloud Computing at National Institute of Standards and Technology (NIST/ITL)

Michaela Iorga

Senior Security Technical Lead for Cloud Computing at National Institute of Standards and Technology (NIST/ITL)

Lloyd Osafo Headshot Missing
Lloyd Osafo

Lloyd Osafo

Andrew Wild
Andrew Wild

Andrew Wild

Michael Green Headshot Missing
Michael Green

Michael Green

Are you a research volunteer? Request to have your profile displayed on the website here.

Interested in helping develop research with CSA?

Related Certificates & Training