/performing-kubernetes-cis-benchmark-with-kube-bench
Assess Kubernetes cluster security posture against CIS benchmark controls using kube-bench.
Assess Kubernetes cluster security posture against CIS benchmark controls using kube-bench and produce remediation-prioritized evidence for hardening programs.
Category
Security
Execution
6 steps, sequential + gated
Goal
Assess Kubernetes cluster security posture against CIS benchmark controls using kube-bench and produce remediation-prioritized evidence for hardening programs.
Scope
Applies to
- +Run Kubernetes CIS benchmark
- +Assess cluster hardening with kube-bench
- +Generate compliance evidence for Kubernetes security controls
Does not cover
- −Trivial changes outside the workflow domain
Triggers
"Run Kubernetes CIS benchmark""Assess cluster hardening with kube-bench""Generate compliance evidence for Kubernetes security controls""Track benchmark drift over time"
Inputs
- →Context: environment/system affected
- →Scope: change boundary
- →Constraints: policy or hard rules
Invariants
- 01Benchmark profile must match cluster platform/version context.
- 02Results must be preserved in machine-readable format for trend analysis.
- 03FAIL findings are prioritized before WARN findings unless justified.
- 04Remediation recommendations must map to specific CIS control IDs.
Procedure
- Step 1Step 1 — **Prepare benchmark run**
- Step 2Step 2 — **Execute kube-bench**
- Step 3Step 3 — **Classify findings**
- Step 4Step 4 — **Prioritize remediation**
- Step 5Step 5 — **Validate remediations**
- Step 6Step 6 — **Operationalize continuous assessment**
Outputs
- ▸kube-bench result artifacts (text/JSON/JUnit as configured).
- ▸CIS findings summary with FAIL/WARN prioritization.
- ▸Remediation plan mapped to control IDs.
- ▸Re-test evidence for resolved controls.
Review Gate
- [ ]Benchmark profile aligns with platform/version.
- [ ]Structured report artifacts are generated and retained.
- [ ]FAIL findings have remediation owner and plan.
- [ ]Re-validation confirms critical fixes are effective.
- [ ]Continuous benchmark cadence is defined.