1.0 Overview of Cloud Native Security
14%
- 1.1The 4Cs of Cloud Native Security
- 1.2Cloud Provider and Infrastructure Security
- 1.3Controls and Frameworks
- 1.4Isolation Techniques
- 1.5Artifact Repository and Image Security
- 1.6Workload and Application Code Security
2.0 Kubernetes Cluster Component Security
22%
- 2.1API Server
- 2.2Controller Manager
- 2.3Scheduler
- 2.4Kubelet
- 2.5Container Runtime
- 2.6KubeProxy
- 2.7Pod
- 2.8Etcd
- 2.9Container Networking
- 2.10Client Security
- 2.11Storage
3.0 Kubernetes Security Fundamentals
22%
- 3.1Pod Security Standards
- 3.2Pod Security Admissions
- 3.3Authentication
- 3.4Authorization
- 3.5Secrets
- 3.6Isolation and Segmentation
- 3.7Audit Logging
- 3.8Network Policy
4.0 Kubernetes Threat Model
16%
- 4.1Kubernetes Trust Boundaries and Data Flow
- 4.2Persistence
- 4.3Denial of Service
- 4.4Malicious Code Execution and Compromised Applications in Containers
- 4.5Attacker on the Network
- 4.6Access to Sensitive Data
- 4.7Privilege Escalation
5.0 Platform Security
16%
- 5.1Supply Chain Security
- 5.2Image Repository
- 5.3Observability
- 5.4Service Mesh
- 5.5PKI
- 5.6Connectivity
- 5.7Admission Control
6.0 Compliance and Security Frameworks
10%
- 6.1Compliance Frameworks
- 6.2Threat Modelling Frameworks
- 6.3Supply Chain Compliance