Skip to main content

Workload Network Policy

CCC.K8S.CP09

The service may be configured with Kubernetes network policies that enforce ingress and egress boundaries between workloads and external systems.

Related Threats

IDTitleDescription
CCC.K8S.TH06Workload Network Segmentation is Not EnforcedAbsent or ineffective ingress and egress policies may allow traffic to flow between namespaces, workloads, and external systems without an explicit authorization boundary. Network services can then be discovered or reached from unintended sources, exposing data flows, permitting unauthorized interaction, and increasing the risk of workload disruption.