Project 03 — Enterprise CIS Kubernetes Audit
Project Overview
Section titled “Project Overview”Welcome to Project 03 — Enterprise CIS Kubernetes Audit.
In this project you will act as a Kubernetes Security Auditor performing an enterprise security audit against the CIS Kubernetes Benchmark.
Unlike the previous project, which focused on identifying general security weaknesses, this project measures the Kubernetes platform against an internationally recognised security benchmark.
Your responsibility is to determine whether the Kubernetes environment complies with security best practices, document evidence for every control, identify deviations, assign risk ratings and produce a professional audit report.
This project closely resembles the type of audit performed by:
- Internal Security Teams
- Cloud Security Consultants
- PCI DSS Assessors
- ISO 27001 Auditors
- Financial Services Security Teams
- Government Security Assessors
- Enterprise Compliance Teams
CIS Benchmark
↓
Control Assessment
↓
Evidence Collection
↓
Compliance Validation
↓
Gap Analysis
↓
Audit Report
↓
Remediation PlanProject Mission
Section titled “Project Mission”CloudNova Technologies is preparing for an external compliance review.
Before the external auditors arrive, the organisation wants an internal CIS Kubernetes Benchmark assessment.
Your objectives are to:
- Review every applicable CIS Kubernetes Benchmark control.
- Collect technical evidence.
- Determine compliance status.
- Document exceptions.
- Identify risks.
- Recommend remediation.
- Produce executive and technical audit reports.
- Establish a repeatable audit process.
Business Scenario
Section titled “Business Scenario”CloudNova Technologies operates several production Amazon EKS clusters supporting:
- Customer Applications
- Payment Systems
- Internal Business Platforms
- Security Monitoring Services
- Shared Platform Components
Management requires assurance that Kubernetes security controls align with recognised industry standards.
The organisation needs answers to questions such as:
- Are administrator permissions properly controlled?
- Is audit logging enabled?
- Are worker nodes securely configured?
- Are workloads following security best practices?
- Are Network Policies implemented?
- Is the cluster configured according to CIS recommendations?
- Can evidence be presented during external audits?
Business Outcome
Section titled “Business Outcome”At the end of the project CloudNova Technologies should have:
- Complete CIS Benchmark assessment
- Compliance score
- Executive dashboard
- Technical evidence
- Risk register
- Exception register
- Remediation roadmap
- Audit package ready for external review
Project Objectives
Section titled “Project Objectives”By completing this project you will learn how to:
- Perform enterprise Kubernetes compliance audits
- Interpret CIS Kubernetes Benchmark controls
- Validate technical configurations
- Collect audit-quality evidence
- Review control-plane configuration
- Assess worker-node security
- Validate authentication and RBAC
- Assess workload hardening
- Review network security
- Validate logging and monitoring
- Assess backup and recovery readiness
- Produce professional audit reports
- Present findings to executives and technical stakeholders
Project Difficulty
Section titled “Project Difficulty”Level: Advanced
Estimated Time
Section titled “Estimated Time”12–18 Hours
Project Type
Section titled “Project Type”- Security Audit
- Compliance Assessment
- Technical Review
- Evidence Collection
- Risk Assessment
- Enterprise Portfolio Project
Applicable Standards
Section titled “Applicable Standards”This audit references:
- CIS Kubernetes Benchmark
- CIS Amazon EKS Benchmark (where applicable)
- CIS AWS Foundations Benchmark
- NIST Cybersecurity Framework
- NIST SP 800-53
- ISO 27001
- PCI DSS
- Internal Security Standards
Recommended Tools
Section titled “Recommended Tools”- kubectl
- kube-bench
- Kubescape
- kubeaudit
- Trivy
- AWS CLI
- jq
- yq
- Helm
- Terraform
- AWS Config
- AWS Security Hub
- CloudTrail
- CloudWatch
- Excel / Markdown Findings Register
Audit Scope
Section titled “Audit Scope”The audit includes:
- AWS Accounts
- IAM
- Amazon EKS
- VPC
- Security Groups
- CloudTrail
- GuardDuty
- Security Hub
- AWS Config
- Amazon ECR
Kubernetes
Section titled “Kubernetes”- Control Plane
- Nodes
- RBAC
- Service Accounts
- Namespaces
- Pods
- Secrets
- ConfigMaps
- Network Policies
- Ingress
- Storage
- Logging
- Monitoring
- Backup
Audit Methodology
Section titled “Audit Methodology”Planning
↓
Benchmark Selection
↓
Discovery
↓
Control Validation
↓
Evidence Collection
↓
Compliance Review
↓
Risk Analysis
↓
Reporting
↓
Management Review
↓
Remediation TrackingDeliverables
Section titled “Deliverables”Technical
Section titled “Technical”- Cluster Inventory
- Benchmark Results
- kube-bench Reports
- kubectl Evidence
- Configuration Review
- RBAC Assessment
- Network Review
- Logging Review
Compliance
Section titled “Compliance”- CIS Scorecard
- Compliance Matrix
- Exception Register
- Audit Evidence
Management
Section titled “Management”- Executive Report
- Audit Report
- Remediation Roadmap
- Presentation Slides
Project Folder Structure
Section titled “Project Folder Structure”03-enterprise-cis-kubernetes-audit/
├── README.md├── 01-planning/├── 02-discovery/├── 03-benchmark/├── 04-control-review/├── 05-evidence/├── 06-findings/├── 07-risk-register/├── 08-exceptions/├── 09-remediation/└── 10-report/Phase 1 — Audit Planning
Section titled “Phase 1 — Audit Planning”Task 1.1 Define Scope
Section titled “Task 1.1 Define Scope”Document:
- Cluster Name
- Environment
- Region
- Business Owner
- Security Owner
- Audit Dates
- Auditor
- Benchmark Version
Task 1.2 Review Applicable Controls
Section titled “Task 1.2 Review Applicable Controls”Categorise controls into:
- Control Plane
- Worker Nodes
- Authentication
- Authorization
- Logging
- Secrets
- Workloads
- Networking
- Governance
Task 1.3 Prepare Audit Checklist
Section titled “Task 1.3 Prepare Audit Checklist”Create an enterprise checklist for every CIS control including:
- Control ID
- Description
- Validation Method
- Evidence Required
- Pass / Fail
- Risk
- Comments
Phase 2 — Cluster Discovery
Section titled “Phase 2 — Cluster Discovery”Collect:
kubectl versionkubectl cluster-infokubectl get nodes -o widekubectl get namespaceskubectl get all -ADocument:
- Kubernetes Version
- Node Count
- Runtime
- Operating System
- Namespace Count
- Workload Count
Phase 3 — Run CIS Benchmark
Section titled “Phase 3 — Run CIS Benchmark”Execute:
kube-bench runor
kube-bench --targets nodeor
kube-bench --targets masterCapture:
- Passed Controls
- Failed Controls
- Warnings
- Manual Checks
Save results as:
kube-bench-results.jsonPhase 4 — Control Review
Section titled “Phase 4 — Control Review”Review every CIS control category.
Authentication
Section titled “Authentication”Validate:
- Anonymous access disabled
- Strong authentication
- MFA for administrators
- Short-lived credentials
Authorization
Section titled “Authorization”Review:
- RBAC enabled
- cluster-admin assignments
- Wildcard permissions
- Least privilege
Worker Nodes
Section titled “Worker Nodes”Validate:
- Private nodes
- Secure kubelet configuration
- IMDSv2
- Encryption
- Patch level
- Runtime
Workloads
Section titled “Workloads”Review:
- Non-root
- Read-only filesystem
- Security Context
- Seccomp
- Capabilities
- Resource limits
- HostPath
- Privileged Pods
Networking
Section titled “Networking”Validate:
- Network Policies
- TLS
- Ingress Security
- Service Exposure
- Egress Controls
Logging
Section titled “Logging”Confirm:
- Audit Logs
- CloudTrail
- CloudWatch
- Runtime Monitoring
Secrets
Section titled “Secrets”Review:
- Encryption
- External Secrets
- Access Control
- Rotation
Phase 5 — Evidence Collection
Section titled “Phase 5 — Evidence Collection”Evidence should include:
- Command Outputs
- Screenshots
- YAML Files
- Configuration Files
- kube-bench Reports
- Logs
- AWS Configuration
- IAM Policies
Example:
Evidence ID:
CIS-001
Control:
1.2.1
Command:
kubectl get clusterrolebindings
Result:
PASS
Evidence:
clusterrolebindings.yamlPhase 6 — Compliance Scoring
Section titled “Phase 6 — Compliance Scoring”Example Scorecard
| Domain | Score |
|---|---|
| Control Plane | 95% |
| Worker Nodes | 88% |
| Authentication | 92% |
| RBAC | 80% |
| Workloads | 76% |
| Networking | 84% |
| Logging | 90% |
| Secrets | 85% |
Overall Compliance:
87%Phase 7 — Findings
Section titled “Phase 7 — Findings”Each finding should contain:
Finding ID
CIS Control
Severity
Evidence
Risk
Recommendation
Owner
Target Date
StatusExample:
Finding:
CIS-07
Control:
5.2.5
Severity:
High
Issue:
Privileged containers detected in production namespace.
Recommendation:
Remove privileged mode and apply Pod Security Admission Restricted profile.Phase 8 — Exception Register
Section titled “Phase 8 — Exception Register”Some controls may require business approval.
Document:
- Control ID
- Reason
- Risk
- Approver
- Expiry Date
Phase 9 — Remediation Roadmap
Section titled “Phase 9 — Remediation Roadmap”Immediate
Section titled “Immediate”- Remove privileged Pods
- Fix RBAC
- Enable Audit Logging
Short Term
Section titled “Short Term”- Apply Network Policies
- Harden Nodes
- Rotate Secrets
Medium Term
Section titled “Medium Term”- Automate Compliance
- Continuous CIS Scanning
- Policy-as-Code
Phase 10 — Executive Report
Section titled “Phase 10 — Executive Report”Include:
- Executive Summary
- Scope
- Methodology
- Compliance Score
- High Risk Findings
- Strengths
- Weaknesses
- Recommendations
- Remediation Timeline
- Final Conclusion
Audit Dashboard
Section titled “Audit Dashboard”| Metric | Result |
|---|---|
| Total Controls | 210 |
| Passed | 183 |
| Failed | 17 |
| Manual Review | 10 |
| Compliance | 87% |
Knowledge Check
Section titled “Knowledge Check”1. Why is the CIS Kubernetes Benchmark important?
Section titled “1. Why is the CIS Kubernetes Benchmark important?”Answer: It provides industry-recognised security best practices that help organisations consistently assess and improve Kubernetes security.
2. Why should audit evidence be collected for every control?
Section titled “2. Why should audit evidence be collected for every control?”Answer: Evidence demonstrates that conclusions are based on verifiable technical data and supports internal and external compliance audits.
3. Why are failed controls prioritised by risk?
Section titled “3. Why are failed controls prioritised by risk?”Answer: Risk-based prioritisation ensures that the most critical weaknesses affecting confidentiality, integrity and availability are addressed first.
4. Why should exception registers be maintained?
Section titled “4. Why should exception registers be maintained?”Answer: Some controls may have valid business or technical reasons for temporary non-compliance, and these exceptions must be documented, approved and reviewed.
5. Why should CIS audits be repeated regularly?
Section titled “5. Why should CIS audits be repeated regularly?”Answer: Kubernetes environments change frequently. Regular audits help identify configuration drift, new risks and ensure continued compliance.
Project Success Criteria
Section titled “Project Success Criteria”- Audit scope approved
- Benchmark executed
- All applicable CIS controls reviewed
- Evidence collected
- Compliance score calculated
- Findings documented
- Risk register completed
- Exception register created
- Remediation roadmap approved
- Executive report completed
Portfolio Outcome
Section titled “Portfolio Outcome”Upon completion of this project, you will have demonstrated the ability to:
- Perform enterprise Kubernetes compliance audits
- Interpret CIS Benchmark requirements
- Collect professional audit evidence
- Assess Kubernetes security posture
- Produce executive-ready compliance reports
- Recommend risk-based remediation plans
- Support organisations preparing for regulatory and external security audits
➡️ Next Project: Project 04 — Secure Multi-Tenant Kubernetes Cluster