- Orchestration Platform Type*
- Is role-based access control enabled in the cluster?*
- Which access and identity controls are enforced?*
- Which policy enforcement tools or mechanisms are in place?
- Network segmentation controls in place*
- Ingress and egress restrictions enforced*
- Pod security settings applied*
- Image provenance and signing checks used*
- Runtime hardening and privileged container restrictions*
- How are application and cluster secrets stored and injected?*
- Are secrets encrypted at rest in the primary storage location?*
- Which logging and audit trail sources are in place?*
- Which monitoring and alerting capabilities are enabled?*
- Target completion date
- Review Date*
- Overall Audit Outcome*
- Should be Empty: