Cluster Setup Cluster Setup
15%
- 1.0Use Network security policies to restrict cluster level access
- 1.1Use CIS benchmark to review the security configuration of Kubernetes components (etcd, kubelet, kubedns, kubeapi)
- 1.2Properly set up Ingress with TLS
- 1.3Protect node metadata and endpoints
- 1.4Verify platform binaries before deploying
Cluster Hardening Cluster Hardening
15%
- 2.0Use Role Based Access Controls to minimize exposure
- 2.1Exercise caution in using service accounts e.g. disable defaults, minimize permissions on newly created ones
- 2.2Restrict access to Kubernetes API
- 2.3Upgrade Kubernetes to avoid vulnerabilities
System Hardening System Hardening
10%
- 3.0Minimize host OS footprint (reduce attack surface)
- 3.1Using least-privilege identity and access management
- 3.2Minimize external access to the network
- 3.3Appropriately use kernel hardening tools such as AppArmor, seccomp
Minimize Microservice Vulnerabilities Minimize Microservice Vulnerabilities
20%
- 4.0Use appropriate pod security standards
- 4.1Manage Kubernetes secrets
- 4.2Understand and implement isolation techniques (multi-tenancy, sandboxed containers, etc.)
- 4.3Implement Pod-to-Pod encryption (Cilium, Istio)
Supply Chain Security Supply Chain Security
20%
- 5.0Minimize base image footprint
- 5.1Understand your supply chain (e.g. SBOM, CI/CD, artifact repositories)
- 5.2Secure your supply chain (permitted registries, sign and validate artifacts, etc.)
- 5.3Perform static analysis of user workloads and container images (e.g. Kubesec, KubeLinter)
Monitoring, Logging and Runtime Security Monitoring, Logging and Runtime Security
20%
- 6.0Perform behavioral analytics to detect malicious activities
- 6.1Detect threats within physical infrastructure, apps, networks, data, users and workloads
- 6.2Investigate and identify phases of attack and bad actors within the environment
- 6.3Ensure immutability of containers at runtime
- 6.4Use Kubernetes audit logs to monitor access