Misconfigured persistent-volume claims, storage classes, or workload authorization may allow a volume to be mounted outside its intended ownership boundary. Data stored on the volume can then be read, modified, or deleted through the unauthorized workload, directly reducing its confidentiality, integrity, and availability.
Persistent Volumes are Bound to Unauthorized Workloads
CCC.K8S.TH11
Related Capabilities
| ID | Title | Description |
|---|---|---|
| CCC.K8S.CP13 | Kubernetes Storage Provisioning | The service can dynamically provision ephemeral and persistent workload storage through Kubernetes container storage interface integrations. |
Related Controls
| ID | Title | Description |
|---|---|---|
| CCC.K8S.CN10 | Restrict Persistent Volume Access | Confine persistent storage provisioning and mounts to their approved namespace, workload, access mode, and ownership boundary. |