Skip to main content

Workload Network Segmentation is Not Enforced

CCC.K8S.TH06

Absent or ineffective ingress and egress policies may allow traffic to flow between namespaces, workloads, and external systems without an explicit authorization boundary. Network services can then be discovered or reached from unintended sources, exposing data flows, permitting unauthorized interaction, and increasing the risk of workload disruption.

Related Capabilities

IDTitleDescription
CCC.K8S.CP07Cluster Network IntegrationThe service can attach cluster, node, pod, and service connectivity to a user-configured cloud virtual network.
CCC.K8S.CP09Workload Network PolicyThe service may be configured with Kubernetes network policies that enforce ingress and egress boundaries between workloads and external systems.

Related Controls

IDTitleDescription
CCC.K8S.CN06Enforce Default-Deny Workload Network PoliciesConfine workload communication to flows permitted by explicit, least-privilege network policies, with all other traffic denied by default.

External Mappings

FrameworkIDRelationshipRemarks
CWECWE-284relates-toImproper Access Control
MITRE-ATT&CKT1046relates-toNetwork Service Discovery
MITRE-ATT&CKT1686.001relates-toDisable or Modify System Firewall - Cloud Firewall