Skip to content

Project 03 — Enterprise CIS Kubernetes Audit

Welcome to Project 03 — Enterprise CIS Kubernetes Audit.

In this project you will act as a Kubernetes Security Auditor performing an enterprise security audit against the CIS Kubernetes Benchmark.

Unlike the previous project, which focused on identifying general security weaknesses, this project measures the Kubernetes platform against an internationally recognised security benchmark.

Your responsibility is to determine whether the Kubernetes environment complies with security best practices, document evidence for every control, identify deviations, assign risk ratings and produce a professional audit report.

This project closely resembles the type of audit performed by:

  • Internal Security Teams
  • Cloud Security Consultants
  • PCI DSS Assessors
  • ISO 27001 Auditors
  • Financial Services Security Teams
  • Government Security Assessors
  • Enterprise Compliance Teams
CIS Benchmark
Control Assessment
Evidence Collection
Compliance Validation
Gap Analysis
Audit Report
Remediation Plan

CloudNova Technologies is preparing for an external compliance review.

Before the external auditors arrive, the organisation wants an internal CIS Kubernetes Benchmark assessment.

Your objectives are to:

  1. Review every applicable CIS Kubernetes Benchmark control.
  2. Collect technical evidence.
  3. Determine compliance status.
  4. Document exceptions.
  5. Identify risks.
  6. Recommend remediation.
  7. Produce executive and technical audit reports.
  8. Establish a repeatable audit process.

CloudNova Technologies operates several production Amazon EKS clusters supporting:

  • Customer Applications
  • Payment Systems
  • Internal Business Platforms
  • Security Monitoring Services
  • Shared Platform Components

Management requires assurance that Kubernetes security controls align with recognised industry standards.

The organisation needs answers to questions such as:

  • Are administrator permissions properly controlled?
  • Is audit logging enabled?
  • Are worker nodes securely configured?
  • Are workloads following security best practices?
  • Are Network Policies implemented?
  • Is the cluster configured according to CIS recommendations?
  • Can evidence be presented during external audits?

At the end of the project CloudNova Technologies should have:

  • Complete CIS Benchmark assessment
  • Compliance score
  • Executive dashboard
  • Technical evidence
  • Risk register
  • Exception register
  • Remediation roadmap
  • Audit package ready for external review

By completing this project you will learn how to:

  • Perform enterprise Kubernetes compliance audits
  • Interpret CIS Kubernetes Benchmark controls
  • Validate technical configurations
  • Collect audit-quality evidence
  • Review control-plane configuration
  • Assess worker-node security
  • Validate authentication and RBAC
  • Assess workload hardening
  • Review network security
  • Validate logging and monitoring
  • Assess backup and recovery readiness
  • Produce professional audit reports
  • Present findings to executives and technical stakeholders

Level: Advanced


12–18 Hours


  • Security Audit
  • Compliance Assessment
  • Technical Review
  • Evidence Collection
  • Risk Assessment
  • Enterprise Portfolio Project

This audit references:

  • CIS Kubernetes Benchmark
  • CIS Amazon EKS Benchmark (where applicable)
  • CIS AWS Foundations Benchmark
  • NIST Cybersecurity Framework
  • NIST SP 800-53
  • ISO 27001
  • PCI DSS
  • Internal Security Standards

  • kubectl
  • kube-bench
  • Kubescape
  • kubeaudit
  • Trivy
  • AWS CLI
  • jq
  • yq
  • Helm
  • Terraform
  • AWS Config
  • AWS Security Hub
  • CloudTrail
  • CloudWatch
  • Excel / Markdown Findings Register

The audit includes:

  • AWS Accounts
  • IAM
  • Amazon EKS
  • VPC
  • Security Groups
  • CloudTrail
  • GuardDuty
  • Security Hub
  • AWS Config
  • Amazon ECR
  • Control Plane
  • Nodes
  • RBAC
  • Service Accounts
  • Namespaces
  • Pods
  • Secrets
  • ConfigMaps
  • Network Policies
  • Ingress
  • Storage
  • Logging
  • Monitoring
  • Backup

Planning
Benchmark Selection
Discovery
Control Validation
Evidence Collection
Compliance Review
Risk Analysis
Reporting
Management Review
Remediation Tracking

  • Cluster Inventory
  • Benchmark Results
  • kube-bench Reports
  • kubectl Evidence
  • Configuration Review
  • RBAC Assessment
  • Network Review
  • Logging Review
  • CIS Scorecard
  • Compliance Matrix
  • Exception Register
  • Audit Evidence
  • Executive Report
  • Audit Report
  • Remediation Roadmap
  • Presentation Slides

03-enterprise-cis-kubernetes-audit/
├── README.md
├── 01-planning/
├── 02-discovery/
├── 03-benchmark/
├── 04-control-review/
├── 05-evidence/
├── 06-findings/
├── 07-risk-register/
├── 08-exceptions/
├── 09-remediation/
└── 10-report/

Document:

  • Cluster Name
  • Environment
  • Region
  • Business Owner
  • Security Owner
  • Audit Dates
  • Auditor
  • Benchmark Version

Categorise controls into:

  • Control Plane
  • Worker Nodes
  • Authentication
  • Authorization
  • Logging
  • Secrets
  • Workloads
  • Networking
  • Governance

Create an enterprise checklist for every CIS control including:

  • Control ID
  • Description
  • Validation Method
  • Evidence Required
  • Pass / Fail
  • Risk
  • Comments

Collect:

Terminal window
kubectl version
Terminal window
kubectl cluster-info
Terminal window
kubectl get nodes -o wide
Terminal window
kubectl get namespaces
Terminal window
kubectl get all -A

Document:

  • Kubernetes Version
  • Node Count
  • Runtime
  • Operating System
  • Namespace Count
  • Workload Count

Execute:

Terminal window
kube-bench run

or

Terminal window
kube-bench --targets node

or

Terminal window
kube-bench --targets master

Capture:

  • Passed Controls
  • Failed Controls
  • Warnings
  • Manual Checks

Save results as:

kube-bench-results.json

Review every CIS control category.

Validate:

  • Anonymous access disabled
  • Strong authentication
  • MFA for administrators
  • Short-lived credentials

Review:

  • RBAC enabled
  • cluster-admin assignments
  • Wildcard permissions
  • Least privilege

Validate:

  • Private nodes
  • Secure kubelet configuration
  • IMDSv2
  • Encryption
  • Patch level
  • Runtime

Review:

  • Non-root
  • Read-only filesystem
  • Security Context
  • Seccomp
  • Capabilities
  • Resource limits
  • HostPath
  • Privileged Pods

Validate:

  • Network Policies
  • TLS
  • Ingress Security
  • Service Exposure
  • Egress Controls

Confirm:

  • Audit Logs
  • CloudTrail
  • CloudWatch
  • Runtime Monitoring

Review:

  • Encryption
  • External Secrets
  • Access Control
  • Rotation

Evidence should include:

  • Command Outputs
  • Screenshots
  • YAML Files
  • Configuration Files
  • kube-bench Reports
  • Logs
  • AWS Configuration
  • IAM Policies

Example:

Evidence ID:
CIS-001
Control:
1.2.1
Command:
kubectl get clusterrolebindings
Result:
PASS
Evidence:
clusterrolebindings.yaml

Example Scorecard

Domain Score
Control Plane 95%
Worker Nodes 88%
Authentication 92%
RBAC 80%
Workloads 76%
Networking 84%
Logging 90%
Secrets 85%

Overall Compliance:

87%

Each finding should contain:

Finding ID
CIS Control
Severity
Evidence
Risk
Recommendation
Owner
Target Date
Status

Example:

Finding:
CIS-07
Control:
5.2.5
Severity:
High
Issue:
Privileged containers detected in production namespace.
Recommendation:
Remove privileged mode and apply Pod Security Admission Restricted profile.

Some controls may require business approval.

Document:

  • Control ID
  • Reason
  • Risk
  • Approver
  • Expiry Date

  • Remove privileged Pods
  • Fix RBAC
  • Enable Audit Logging
  • Apply Network Policies
  • Harden Nodes
  • Rotate Secrets
  • Automate Compliance
  • Continuous CIS Scanning
  • Policy-as-Code

Include:

  1. Executive Summary
  2. Scope
  3. Methodology
  4. Compliance Score
  5. High Risk Findings
  6. Strengths
  7. Weaknesses
  8. Recommendations
  9. Remediation Timeline
  10. Final Conclusion

Metric Result
Total Controls 210
Passed 183
Failed 17
Manual Review 10
Compliance 87%

1. Why is the CIS Kubernetes Benchmark important?

Section titled “1. Why is the CIS Kubernetes Benchmark important?”

Answer: It provides industry-recognised security best practices that help organisations consistently assess and improve Kubernetes security.

2. Why should audit evidence be collected for every control?

Section titled “2. Why should audit evidence be collected for every control?”

Answer: Evidence demonstrates that conclusions are based on verifiable technical data and supports internal and external compliance audits.

3. Why are failed controls prioritised by risk?

Section titled “3. Why are failed controls prioritised by risk?”

Answer: Risk-based prioritisation ensures that the most critical weaknesses affecting confidentiality, integrity and availability are addressed first.

4. Why should exception registers be maintained?

Section titled “4. Why should exception registers be maintained?”

Answer: Some controls may have valid business or technical reasons for temporary non-compliance, and these exceptions must be documented, approved and reviewed.

5. Why should CIS audits be repeated regularly?

Section titled “5. Why should CIS audits be repeated regularly?”

Answer: Kubernetes environments change frequently. Regular audits help identify configuration drift, new risks and ensure continued compliance.


  • Audit scope approved
  • Benchmark executed
  • All applicable CIS controls reviewed
  • Evidence collected
  • Compliance score calculated
  • Findings documented
  • Risk register completed
  • Exception register created
  • Remediation roadmap approved
  • Executive report completed

Upon completion of this project, you will have demonstrated the ability to:

  • Perform enterprise Kubernetes compliance audits
  • Interpret CIS Benchmark requirements
  • Collect professional audit evidence
  • Assess Kubernetes security posture
  • Produce executive-ready compliance reports
  • Recommend risk-based remediation plans
  • Support organisations preparing for regulatory and external security audits

➡️ Next Project: Project 04 — Secure Multi-Tenant Kubernetes Cluster