• Container Orchestration Security Audit Form

    Use this form to document a security audit of a container orchestration environment, including scope, access controls, network and workload protections, secrets handling, logging, recovery, findings, and remediation.
  • Audit Scope and Environment

  • Orchestration Platform Type*
  • Access, Identity, and Policy Controls

  • Is role-based access control enabled in the cluster?*
  • Which access and identity controls are enforced?*
  • Which policy enforcement tools or mechanisms are in place?
  • Network and Workload Security

  • Network segmentation controls in place*
  • Ingress and egress restrictions enforced*
  • Pod security settings applied*
  • Image provenance and signing checks used*
  • Runtime hardening and privileged container restrictions*
  • Control maturity rating by area*
    Rows
  • Secrets, Logging, Monitoring, and Recovery

  • How are application and cluster secrets stored and injected?*
  • Are secrets encrypted at rest in the primary storage location?*
  • Which logging and audit trail sources are in place?*
  • Which monitoring and alerting capabilities are enabled?*
  • Rate readiness for the following control areas*
    Rows
  • Supporting evidence links or file references
  • Findings, Risk, and Remediation

  • Target completion date
     - -
    2 digit month, 2 digit day, 4 digit year
  • Reviewer Information

  • Review Date*
     - -
    2 digit month, 2 digit day, 4 digit year
  • Overall Audit Outcome*
  • Should be Empty:
Select theme: