It's something certain developers I've encountered seem to ignore, even when creating something that might handle health or financial information.
Did you have to build your docker images from scratch, or did the security audit folks certify upstream images? What about updates?