Alert icon Keyboard navigation enabled.
Alert icon TAB or Shift+TAB to navigate across. Down ↓ to open menu. ESC to close menu.
Alert icon Down ↓ to select section. Right → to activate. Up ↑ / Down ↓ / Tab to traverse all. ESC to exit.
BeyondTrust
Skip to content Use space or enter to skip.

What can we help you find today?

Instant Results
  • Website Results
  • Technical Documentation

Filter Options

Focus your search

Filtering by

Your recent searches:

Contact Us Chat with Sales Get Support
  • English
  • Deutsch
  • français
  • español
  • 한국어
  • português
  • Home
  • Resources
  • Blog
  • Continuous Container Security – Is it Mission Impossible? current page
Link copied

Continuous Container Security – Is it Mission Impossible?

Dec 20, 2018
Author:
Ben Rothke Bio Pic
Ben Rothke
Senior Security Consultant, Nettitude
Blog banner default
Continuous Container Security – Is it Mission Impossible?
Ben Rothke Bio Pic
Ben Rothke
Senior Security Consultant, Nettitude

This blog compliments my November 20th webinar, Virtualization and Container Security. Is it ‘Mission: Impossible’?, which you can watch on-demand here.

While containers have only recently become pervasive, the initial notion of a container goes all the way back to 1979 with the chroot command in Version 7 Unix. Chroot changes the apparent root directory for the current running process and its children. In 2005, Sun Microsystems introduced Solaris Containers. And the technology world was forever changed (for the better) a decade ago with Linux Containers (LXC), which evolved into Docker.

Some of the benefits of containers over regular applications include:

  • smaller codebases
  • quicker to be instantiated
  • greater modularity
  • enable an order of magnitude speedup of workload start-up, thereby enabling greater agility in the development process

But if an enterprise’s underlying security is weak and plagued with vulnerabilities, it is unlikely to reap much benefit from containerization. Furthermore, the primary goal of abstraction technologies, such as virtualization and containers, is to optimize resource efficiency and provide agility. Security is not the main consideration. But this does not necessarily mean that virtualization and container technologies can’t be secure. In fact, they can be quite secure.

Perhaps the most important key for success with using containers is to create a container platform strategy. This strategy should define the baseline requirements for security controls, monitoring, logging, data persistence, networking (and much more), and lifecycle management of containers that are prerequisites for production environments.

Some of the core elements that need to be built into the strategy include (but are by no means limited to):

  • Host isolation
  • Access control
  • Operating system hardening
  • Container image Scanning
  • Logging
  • Monitoring
  • Incident response
  • Signing
  • Encryption

Containers provide isolation for applications from their host and from each other, while minimizing use of resources of the underlying infrastructure and reducing the surface area of the host itself. Containers and virtual machines (VMs) can be deployed together to provide additional layers of isolation and security for selected services. Docker is the largest containerization vendor, and it provides the most complete set of security capabilities with strong defaults in container technology.

While applications packaged in containers are fundamentally more secure by default, the key to achieving and maintaining these higher levels of security is to ensure that all of the necessary security controls are formalized and baked into your container environment.

To learn more insights into how to more effectively improve container and virtualization security, watch my on-demand webinar: Virtualization and Container Security. Is it ‘Mission: Impossible’?

Latest Posts
  • The Most Common & Most Dangerous Types of Shadow IT
    Jun 5, 2026 The Most Common & Most Dangerous Types of Shadow IT
    Blog
    19m
  • 14 Password Management Best Practices
    May 28, 2026 14 Password Management Best Practices
    Blog
    12m
  • A Security Researcher’s Guide to Understanding Copilot Studio AI Agents
    May 26, 2026 A Security Researcher’s Guide to Understanding Copilot Studio AI Agents
    Blog
    3m
  • How to Secure Cloud-Native Infrastructure at Scale and Speed: A Conversation with Madhu Adireddi
    May 21, 2026 How to Secure Cloud-Native Infrastructure at Scale and Speed: A Conversation with Madhu Adireddi
    Blog
    5m
  • Cybersecurity as a Boardroom Priority for Major African TelCos
    May 12, 2026 Cybersecurity as a Boardroom Priority for Major African TelCos
    Blog
    8m
Related
  • BeyondTrust’s Privileged Access Management Solutions Recognized in Two Prestigious Middle East Awards
    Dec 16, 2020 BeyondTrust’s Privileged Access Management Solutions Recognized in Two Prestigious Middle East Awards
    Blog
    1m
  • What is IT Support? Technical Support Tools & Service Desk Explained
    Mar 18, 2026 What is IT Support? Technical Support Tools & Service Desk Explained
    Blog
    22m
Share this Article
  • Link
Stay up to Date
Get the latest news, ideas, and tactics from BeyondTrust. You may unsubscribe at any time.

Keep up with BeyondTrust

Customer Support Get Started
  • LinkedIn
  • X
  • Facebook
  • Instagram
  • Add BeyondTrust as a preferred source on Google
  • Privacy
  • Security
  • Manage Cookies
  • Do Not Sell My Data
  • WEEE Compliance

Copyright © 2003 — 2026 BeyondTrust Corporation. All rights reserved. Other trademarks identified on this page are owned by their respective owners. BeyondTrust Corporation is not a chartered bank or trust company, or depository institution. It is not authorized to accept deposits or trust accounts and is not licensed or regulated by any state or federal banking authority.

Prefers reduced motion setting detected. Animations will now be reduced as a result.