Preserve the completeness and accuracy of policy-relevant cloud tags and Kubernetes labels by limiting modification to authorized identities.
Protect Resource Metadata
CCC.K8S.CN15 · Resource
Related Capabilities
| ID | Title | Description |
|---|---|---|
| CCC.Core.CP20 | Resource Tagging | The service provides users with the ability to tag a child resource with metadata that can be reviewed or queried. |
Related Threats
| ID | Title | Description |
|---|---|---|
| CCC.Core.TH13 | Resource Tags are Manipulated | When resource tags are altered, it can lead to misclassification or mismanagement of resources. This can reduce the efficacy of organizational policies, billing rules, or network access rules. Such changes could cause compromised confidentiality, integrity, or availability of the system and its data. |
Assessment Requirements
| ID | Text | Applicability |
|---|---|---|
| CCC.K8S.CN15.AR01 | When a cluster, node pool, namespace, or governed workload is created, all organization-required ownership, environment, data-classification, and policy metadata MUST be present with approved values. | tlp-clear, tlp-green, tlp-amber, tlp-red |
| CCC.K8S.CN15.AR02 | When metadata controls authorization, network policy, admission, billing, or data handling, modification of that metadata MUST be restricted to a dedicated role and MUST produce an externally retained audit record. | tlp-clear, tlp-green, tlp-amber, tlp-red |