WKL-03.1: Containers use the orchestration platform delivered as a service from the cloud provider. This reduces complexity and attack surface compared to building your own container management in the cloud. Because automation can't necessarily detect if self-hosted automation is in place, the automated checks will need manual validation. Alternatively, the automation can look for standard container management ports (e.g., 6443 for Kubernetes) in security groups to identify if containerization is in place.
  • Control automation: Either
  • AWS control specification: * ECS or EKS in use (pass)
  • Kubernetes Ports 6443, 10250, 10259, 10257 in use but no EKS in use (fail)
  • OpenShift ports 8444 (fail)
  • Azure control specification: none
  • GCP control specification: none
  • Third-party (CSPM/CNAPP) control specification: none

Description

  • Control automation: Either
  • AWS control specification: * ECS or EKS in use (pass)
  • Kubernetes Ports 6443, 10250, 10259, 10257 in use but no EKS in use (fail)
  • OpenShift ports 8444 (fail)
  • Azure control specification: none
  • GCP control specification: none
  • Third-party (CSPM/CNAPP) control specification: none