A collaboration between the U.S. federal government, IBM, Red Hat, and Intel shows how to automate security in containerized environments.
Greater efficiency. More adaptability. Limitless scalability. The benefits of modernizing an IT infrastructure and containerizing applications are well established, and all organizations like the sound of these results.
When it comes to regulated or sensitive workloads and data, however, organizations may resist the move to cloud in favor of on-premises security. This presents an important challenge for IT in all regulated industries—if you want to containerize sensitive data for a hybrid cloud or multicloud infrastructure, how can you verify that the containers run only on secure systems?
The National Institute of Standards and Technology (NIST) has an answer.
Modernized IT, with trust built in
A division of the U.S. Department of Commerce, NIST supports U.S. innovation and industrial competitiveness by advancing measurement science, standards, and technology. Essentially, it helps establish standards and best practices for U.S. industry.
As part of an ongoing collaboration, NIST, IBM, Red Hat, and Intel have defined a Trusted Container Platform for regulated applications and data. The platform provides an innovative solution, with policy-based governance, for automating processes to secure containerized workloads—so organizations handling such workloads can verify security and regulatory compliance.
NIST has posted the first in a series of blogs detailing the Trusted Container Platform. While the initial post provides an overview of the platform’s architecture, subsequent posts will delve into greater detail and provide steps for establishing the Trusted Container Platform.
What is trust made of?
The Trusted Container Platform comprises three technologies, as outlined by NIST:
- Intel Security Libraries for Data Center (Intel SecL – DC) is hardware root-of-trust technology to engage hardware-level security features and integrate them with cloud orchestration and services.
- IBM Cloud Pak for Multicloud Management on Red Hat OpenShift orchestrates containerized workloads across platforms and clouds, with unified visibility into and control over security policy and governance.
- Encrypted Container Images is a technology developed by IBM Research to allow encryption and decryption of containerized workloads, securing their content as they are ported between trusted systems.
Together, these technologies allow:
- Organizations to encrypt their own container images, independent of MSPs or cloud vendors.
- Decryption of container images only on secure, trusted systems.
- Enforcement of these policies across managed clusters, on any cloud.
By building security from the hardware up and enabling centralized policy governance, the Trusted Container Platform is a viable way for organizations to gain the efficiencies of containerization while complying with security regulations.
The full NIST blog, including a video demo of the Trusted Container Platform, can be viewed on the NIST website.
You can also check out a blog post from IBM Developer: “Policy-based governance in a trusted container platform.”