Skip to main content

Restrict Environment Options on MLDE Instances

CCC.MLDE.CN05 · Resource

Limit the virtual machine and container image options available when creating new MLDE instances to approved and secure configurations.

Related Capabilities

IDTitleDescription
CCC.MLDE.CP01Managed Notebook EnvironmentsProvides fully managed notebook instances specifically designed for machine learning development, eliminating the need to manage underlying infrastructure.
CCC.MLDE.CP02Pre-configured Machine Learning LibrariesOffers environments pre-installed with popular machine learning libraries and frameworks such as TensorFlow, PyTorch, and Scikit-learn, optimized for ML tasks.

Related Threats

IDTitleDescription
CCC.MLDE.TH04Outdated or Unapproved Environment Images are ExploitedNotebook instances may be created from arbitrary virtual machine or container images, or left running without scheduled upgrades, so that pre-installed machine learning libraries and runtimes fall behind current security patches. Known vulnerabilities in these components could be exploited to execute code or escalate privileges within the environment. This compromises the confidentiality, integrity, and availability of the development environment and the data it processes.

Assessment Requirements

IDTextApplicability
CCC.MLDE.CN05.AR01Verify that only approved VM and container images can be selected when creating MLDE instances.tlp-red, tlp-amber
CCC.MLDE.CN05.AR02Attempt to create an MLDE instance with an unapproved image and confirm that it is denied.tlp-red

Guideline Mappings

FrameworkIDRemarks
NIST-CSFPR.IP-1
CCMTVM-02
ISO_270012013 A.12.5.1
NIST_800_53CM-2