CIS Google Kubernetes Engine GKE Autopilot v2.0.0 L2

Audit Details

Name: CIS Google Kubernetes Engine GKE Autopilot v2.0.0 L2

Updated: 9/15/2026

Authority: CIS

Plugin: GCP

Revision: 1.0

Estimated Item Count: 19

File Details

Filename: CIS_Google_Kubernetes_Engine_GKE_Autopilot_v2.0.0_L2.audit

Size: 86.9 kB

MD5: bb5363218b8ebde85c1d11e9a28a4337
SHA256: 11ba12ba0bdd14a2001ef994d38ed06e2709c4dc2c4c23e8e6f883afd8725679

Audit Items

DescriptionCategories
4.1.8 Avoid binding RBAC roles to unauthenticated users and groups

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION

4.3.1 Use NetworkPolicy with built in GKE Dataplane V2 enforcement

SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

4.4.1 Use Secret Manager for external workload secret storage

SYSTEM AND COMMUNICATIONS PROTECTION

4.5.1 Enforce image provenance using Binary Authorization for GKE

CONFIGURATION MANAGEMENT, MAINTENANCE

4.6.2 Rely on Autopilot RuntimeDefault seccomp; custom profiles are unsupported

CONFIGURATION MANAGEMENT

4.6.3 Require hardened security contexts for all workload Pods and containers

CONFIGURATION MANAGEMENT

4.6.4 Avoid deploying workloads in the default namespace

CONFIGURATION MANAGEMENT, CONTINGENCY PLANNING, PLANNING, PROGRAM MANAGEMENT, SYSTEM AND SERVICES ACQUISITION, SYSTEM AND COMMUNICATIONS PROTECTION

5.1.1 Enable Artifact Analysis scanning for Artifact Registry container images

RISK ASSESSMENT

5.1.2 Grant least privilege IAM access to Artifact Registry repositories

ACCESS CONTROL, MEDIA PROTECTION

5.1.3 Enforce Binary Authorization for trusted GKE container image deployments

CONFIGURATION MANAGEMENT

5.2.1 Use a custom least privilege node service account for GKE Autopilot

IDENTIFICATION AND AUTHENTICATION

5.3.1 Enable application-layer Secrets encryption with Cloud KMS keys

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

5.4.2 Restrict GKE control plane access with authorized networks

ACCESS CONTROL, MEDIA PROTECTION

5.4.3 Use DNS based access or private GKE control plane endpoints

SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

5.4.4 Ensure private GKE nodes are configured without external IP addresses

SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

5.4.5 Use Google managed SSL certificates for GKE Ingress TLS

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

5.5.1 Use Google Groups to centrally manage Kubernetes RBAC access for GKE clusters

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

5.6.1 Use CMEK protected StorageClasses for GKE Persistent Disk volumes

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

5.7.1 Enable the GKE security posture dashboard for cluster security insights

CONFIGURATION MANAGEMENT