• Container Orchestration Security Audit Form

    Use this form to document a security audit of a container orchestration environment, including scope, access controls, network and workload protections, secrets handling, logging, recovery, findings, and remediation.
  • Audit Scope and Environment

  • Orchestration Platform Type*
  • Access, Identity, and Policy Controls

  • Is role-based access control enabled in the cluster?*
  • Which access and identity controls are enforced?*
  • Which policy enforcement tools or mechanisms are in place?
  • Network and Workload Security

  • Network segmentation controls in place*
  • Ingress and egress restrictions enforced*
  • Pod security settings applied*
  • Image provenance and signing checks used*
  • Runtime hardening and privileged container restrictions*
  • Rows
  • Secrets, Logging, Monitoring, and Recovery

  • How are application and cluster secrets stored and injected?*
  • Are secrets encrypted at rest in the primary storage location?*
  • Which logging and audit trail sources are in place?*
  • Which monitoring and alerting capabilities are enabled?*
  • Rows
  • Findings, Risk, and Remediation

  • Target completion date
     - -
  • Reviewer Information

  • Review Date*
     - -
  • Overall Audit Outcome*
  • Should be Empty:
Select theme:
  • Default
  • Blue
  • Red
  • Brown
  • Green
  • Black
  • Pink
  • Dark Blue
  • Purple