1.6.2 Create Pod Security Policies for your cluster

Information

Create and enforce Pod Security Policies for your cluster.

Rationale:

A Pod Security Policy is a cluster-level resource that controls the actions that a pod can perform and what it has the ability to access. The 'PodSecurityPolicy' objects define a set of conditions that a pod must run with in order to be accepted into the system. Pod Security Policies are comprised of settings and strategies that control the security features a pod has access to and hence this must be used to control pod access permissions.

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

Follow the documentation and create and enforce Pod Security Policies for your cluster. Additionally, you could refer the 'CIS Security Benchmark for Docker' and follow the suggested Pod Security Policies for your environment.

Impact:

Pods must align with the Pod Security Policies enforced on the cluster.

See Also

https://workbench.cisecurity.org/files/1788

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CSCv6|3

Plugin: Unix

Control ID: 8a1ad340ad83bd25d2541ed64f7110651d2e86c22a1afc29fce8141246b855e5