| CCC.K8S.CN01 | Restrict Kubernetes API Network Access | Limit Kubernetes API reachability to explicitly approved networks and private management paths to reduce administrative exposure. | Access | 4 | 2 | 2 |
| CCC.K8S.CN02 | Enforce Least-Privilege Cluster Authorization | Apply least privilege across cloud and Kubernetes authorization so identities receive only the permissions required for their cluster responsibilities. | Access | 3 | 2 | 2 |
| CCC.K8S.CN03 | Use Federated Identities for Workloads | Replace stored cloud credentials with narrowly scoped, short-lived federated identity for workload access to cloud services. | Access | 3 | 2 | 2 |
| CCC.K8S.CN04 | Admit Only Trusted Container Images | Prevent unapproved, mutable, unverifiable, or critically vulnerable container images from entering the workload environment. | Resource | 1 | 3 | 3 |
| CCC.K8S.CN05 | Enforce Restricted Workload Security | Minimize workload privilege and block unnecessary access to host-level resources that could defeat container isolation. | Compute | 2 | 2 | 2 |
| CCC.K8S.CN06 | Enforce Default-Deny Workload Network Policies | Confine workload communication to flows permitted by explicit, least-privilege network policies, with all other traffic denied by default. | Networking | 2 | 2 | 2 |
| CCC.K8S.CN07 | Protect Workload Secrets | Protect workload secrets through encrypted handling, narrow authorization, and removal from images and non-secret configuration objects. | Access | 2 | 3 | 2 |
| CCC.K8S.CN08 | Allowlist CSP-Provided Cluster Add-ons and Extensions | Restrict enabled CSP-provided cluster add-ons, extensions, and managed features to an organization-controlled allowlist. | Orchestration | 1 | 2 | 1 |
| CCC.K8S.CN09 | Maintain Supported Cluster Components | Keep control-plane, worker, runtime, and extension components within supported and vulnerability-managed release lifecycles. | Resource | 1 | 2 | 3 |
| CCC.K8S.CN10 | Restrict Persistent Volume Access | Confine persistent storage provisioning and mounts to their approved namespace, workload, access mode, and ownership boundary. | Data | 1 | 2 | 2 |
| CCC.K8S.CN11 | Protect Admission Control Enforcement | Apply mandatory cluster security policy to every workload path and prevent its scope or enforcement configuration from being bypassed or modified without authorization. | Access | 2 | 3 | 3 |
| CCC.K8S.CN12 | Restrict Node Administrative Access | Block untrusted or unauthenticated paths to worker-node administration, kubelet interfaces, and instance metadata. | Access | 1 | 3 | 3 |
| CCC.K8S.CN13 | Bound Workload Resource Consumption | Bound resource requests, namespace consumption, and autoscaling so workloads cannot exhaust cluster or cloud capacity. | Resource | 1 | 1 | 3 |
| CCC.K8S.CN14 | Preserve Kubernetes Audit and Monitoring Records | Maintain complete, externally retained, access-controlled, and monitored records of security-relevant Kubernetes activity and health signals. | Observability | 7 | 4 | 3 |
| CCC.K8S.CN15 | Protect Resource Metadata | Preserve the completeness and accuracy of policy-relevant cloud tags and Kubernetes labels by limiting modification to authorized identities. | Resource | 1 | 3 | 2 |
| CCC.K8S.CN16 | Enforce Managed Cluster Authentication | Bind human access to the Kubernetes API and cluster resources to identities that can be centrally governed, monitored, and revoked. | Access | 2 | 3 | 2 |
| CCC.K8S.CN17 | Restrict Cluster Infrastructure Identities | Limit cloud access by cluster infrastructure to the permissions and resources required for each platform responsibility. | Access | 2 | 2 | 2 |
| CCC.K8S.CN18 | Protect Worker Node Integrity | Prevent untrusted or altered worker-node software from operating beneath Kubernetes workloads. | Compute | 3 | 3 | 2 |