The service may be configured to emit Kubernetes API audit and control-plane records to a cloud logging destination for monitoring and investigation.
Kubernetes Audit Logging
CCC.K8S.CP16
Related Threats
| ID | Title | Description |
|---|---|---|
| CCC.K8S.TH15 | Kubernetes Audit Records are Incomplete or Unavailable | Audit policies, log categories, collection agents, export destinations, or retention settings that omit security-relevant activity may leave required Kubernetes records incomplete or unavailable. Cluster access and configuration changes can then occur without a reliable investigative trail, delaying detection and weakening the integrity and availability of security monitoring and incident response. |