ASSESSMENT FOCUS
What this checklist covers
- Cluster API and RBAC exposure
- Pod Security Standards and workload isolation
- Image provenance and vulnerability management
- Secrets, service accounts, and admission policies
- NetworkPolicy, audit logging, and runtime defense
REFERENCE BASELINE
Standards and guidance
- CIS Kubernetes Benchmark
- NSA/CISA Kubernetes Hardening
- MITRE ATT&CK for Containers
Tailor every control to the system's architecture, data classification, threat model, and written scope.
Open the interactive checklist
Search controls, filter by severity, expand technical guidance, and keep progress in your browser.
How to use it professionally
Before testing
Confirm authorization, scope, exclusions, test windows, data handling, emergency contacts, and stop conditions.
During testing
Record the asset, request, expected control, observed result, evidence, and any cleanup action. Avoid destructive proof when a safer validation demonstrates the same issue.
After testing
Deduplicate related symptoms, identify the root cause, assign risk in business context, provide actionable remediation, and retest the final implementation.