| 1.1 · Cloud, cluster, container and code layers |
01 Security Layers and Shared Responsibility |
| 1.2 · Provider and infrastructure responsibilities |
01 Security Layers and Shared Responsibility |
| 1.3 · Preventive, detective and corrective controls |
01 Security Layers and Shared Responsibility, 09 Compliance, Frameworks and Automated Evidence |
| 1.4 · Isolation mechanisms and their limits |
01 Security Layers and Shared Responsibility, 04 Node, Runtime, Pod and Storage Boundaries, 06 Pod Standards, Admission and Network Segmentation |
| 1.5 · Repository and container artifact assurance |
02 Images, Registries and the Software Supply Chain |
| 1.6 · Application and workload protection |
01 Security Layers and Shared Responsibility, 02 Images, Registries and the Software Supply Chain |
| 2.1 · API access and request processing |
03 Control Plane, Etcd and Client Trust, 05 Identity, RBAC, Secrets and Audit Evidence |
| 2.2 · Controller identities and reconciliation |
03 Control Plane, Etcd and Client Trust |
| 2.3 · Scheduler configuration and access |
03 Control Plane, Etcd and Client Trust |
| 2.4 · Kubelet endpoint protection |
04 Node, Runtime, Pod and Storage Boundaries |
| 2.5 · Runtime and host attack surface |
04 Node, Runtime, Pod and Storage Boundaries |
| 2.6 · Service proxy trust and exposure |
04 Node, Runtime, Pod and Storage Boundaries |
| 2.7 · Pod boundaries and host access |
04 Node, Runtime, Pod and Storage Boundaries, 06 Pod Standards, Admission and Network Segmentation |
| 2.8 · Etcd access, encryption and backups |
03 Control Plane, Etcd and Client Trust |
| 2.9 · Container network implementation |
04 Node, Runtime, Pod and Storage Boundaries, 06 Pod Standards, Admission and Network Segmentation |
| 2.10 · Client credentials and kubeconfig trust |
03 Control Plane, Etcd and Client Trust |
| 2.11 · Persistent data and storage permissions |
04 Node, Runtime, Pod and Storage Boundaries |
| 3.1 · Pod security levels |
06 Pod Standards, Admission and Network Segmentation |
| 3.2 · Pod security admission modes |
06 Pod Standards, Admission and Network Segmentation |
| 3.3 · Identity verification |
05 Identity, RBAC, Secrets and Audit Evidence |
| 3.4 · Permission grants and RBAC scope |
05 Identity, RBAC, Secrets and Audit Evidence |
| 3.5 · Secret handling and encryption |
05 Identity, RBAC, Secrets and Audit Evidence |
| 3.6 · Tenant and workload segmentation |
06 Pod Standards, Admission and Network Segmentation |
| 3.7 · API audit evidence |
05 Identity, RBAC, Secrets and Audit Evidence |
| 3.8 · Directional network access rules |
06 Pod Standards, Admission and Network Segmentation |
| 4.1 · Trust boundaries and information movement |
07 Threat Modeling and Attack Paths |
| 4.2 · Attacker persistence paths |
07 Threat Modeling and Attack Paths |
| 4.3 · Resource exhaustion and availability attacks |
07 Threat Modeling and Attack Paths |
| 4.4 · Compromised code and container execution |
07 Threat Modeling and Attack Paths |
| 4.5 · Network interception and lateral movement |
07 Threat Modeling and Attack Paths |
| 4.6 · Sensitive information exposure |
07 Threat Modeling and Attack Paths |
| 4.7 · Escalation from workload to platform privileges |
07 Threat Modeling and Attack Paths |
| 5.1 · Build integrity and artifact provenance |
02 Images, Registries and the Software Supply Chain |
| 5.2 · Registry trust and repository access |
02 Images, Registries and the Software Supply Chain |
| 5.3 · Metrics, logs, traces and runtime signals |
08 Observability, PKI and Secure Connectivity |
| 5.4 · Mesh workload identity and traffic policy |
08 Observability, PKI and Secure Connectivity |
| 5.5 · Certificate chains and key protection |
08 Observability, PKI and Secure Connectivity |
| 5.6 · Private connectivity, ingress and egress |
08 Observability, PKI and Secure Connectivity |
| 5.7 · Mutation, validation and policy enforcement |
06 Pod Standards, Admission and Network Segmentation |
| 6.1 · Organizational standards and configuration baselines |
09 Compliance, Frameworks and Automated Evidence |
| 6.2 · Structured threat analysis |
07 Threat Modeling and Attack Paths, 09 Compliance, Frameworks and Automated Evidence |
| 6.3 · Dependency evidence and release governance |
02 Images, Registries and the Software Supply Chain, 09 Compliance, Frameworks and Automated Evidence |
| 6.4 · Repeatable checks and policy automation |
09 Compliance, Frameworks and Automated Evidence |