5.3.1 Ensure that the CNI in use supports Network Policies

Information

There are a variety of CNI plugins available for Kubernetes. If the CNI in use does not support Network Policies it may not be possible to effectively restrict traffic in the cluster.

Rationale:

Kubernetes network policies are enforced by the CNI plugin in use. As such it is important to ensure that the CNI plugin supports both Ingress and Egress network policies.

Impact:

None

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

None required.

Default Value:

This will depend on the CNI plugin in use.

See Also

https://workbench.cisecurity.org/benchmarks/14166

Item Details

Category: SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|CA-9, 800-53|SC-7, 800-53|SC-7(5), CSCv7|9.5

Plugin: OpenShift

Control ID: e9f2edc6446c58976437294c74cba3042cbf0dc2f6d2ec79117737e56dfbd9ac