Skip to main content

Restrict Persistent Volume Access

CCC.K8S.CN10 · Data

Confine persistent storage provisioning and mounts to their approved namespace, workload, access mode, and ownership boundary.

Related Capabilities

IDTitleDescription
CCC.K8S.CP13Kubernetes Storage ProvisioningThe service can dynamically provision ephemeral and persistent workload storage through Kubernetes container storage interface integrations.

Related Threats

IDTitleDescription
CCC.K8S.TH11Persistent Volumes are Bound to Unauthorized WorkloadsMisconfigured persistent-volume claims, storage classes, or workload authorization may allow a volume to be mounted outside its intended ownership boundary. Data stored on the volume can then be read, modified, or deleted through the unauthorized workload, directly reducing its confidentiality, integrity, and availability.

Assessment Requirements

IDTextApplicability
CCC.K8S.CN10.AR01When a persistent volume claim is created, its namespace, storage class, access mode, and requesting service account MUST match an approved workload storage policy.tlp-clear, tlp-green, tlp-amber, tlp-red
CCC.K8S.CN10.AR02When a persistent volume is statically provisioned or rebound, its underlying storage identity and prior ownership MUST be verified before it is mounted by a different workload.tlp-green, tlp-amber, tlp-red

Guideline Mappings

FrameworkIDRemarks
NIST_800_53AC-3Access Enforcement
NIST_800_53AC-4Information Flow Enforcement