| 4.1.8 Avoid binding RBAC roles to unauthenticated users and groups | ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION |
| 4.3.1 Use NetworkPolicy with built in GKE Dataplane V2 enforcement | SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION |
| 4.4.1 Use Secret Manager for external workload secret storage | SYSTEM AND COMMUNICATIONS PROTECTION |
| 4.5.1 Enforce image provenance using Binary Authorization for GKE | CONFIGURATION MANAGEMENT, MAINTENANCE |
| 4.6.2 Rely on Autopilot RuntimeDefault seccomp; custom profiles are unsupported | CONFIGURATION MANAGEMENT |
| 4.6.3 Require hardened security contexts for all workload Pods and containers | CONFIGURATION MANAGEMENT |
| 4.6.4 Avoid deploying workloads in the default namespace | CONFIGURATION MANAGEMENT, CONTINGENCY PLANNING, PLANNING, PROGRAM MANAGEMENT, SYSTEM AND SERVICES ACQUISITION, SYSTEM AND COMMUNICATIONS PROTECTION |
| 5.1.1 Enable Artifact Analysis scanning for Artifact Registry container images | RISK ASSESSMENT |
| 5.1.2 Grant least privilege IAM access to Artifact Registry repositories | ACCESS CONTROL, MEDIA PROTECTION |
| 5.1.3 Enforce Binary Authorization for trusted GKE container image deployments | CONFIGURATION MANAGEMENT |
| 5.2.1 Use a custom least privilege node service account for GKE Autopilot | IDENTIFICATION AND AUTHENTICATION |
| 5.3.1 Enable application-layer Secrets encryption with Cloud KMS keys | IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION |
| 5.4.2 Restrict GKE control plane access with authorized networks | ACCESS CONTROL, MEDIA PROTECTION |
| 5.4.3 Use DNS based access or private GKE control plane endpoints | SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION |
| 5.4.4 Ensure private GKE nodes are configured without external IP addresses | SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION |
| 5.4.5 Use Google managed SSL certificates for GKE Ingress TLS | ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION |
| 5.5.1 Use Google Groups to centrally manage Kubernetes RBAC access for GKE clusters | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY |
| 5.6.1 Use CMEK protected StorageClasses for GKE Persistent Disk volumes | IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION |
| 5.7.1 Enable the GKE security posture dashboard for cluster security insights | CONFIGURATION MANAGEMENT |