Audit policies, log categories, collection agents, export destinations, or retention settings that omit security-relevant activity may leave required Kubernetes records incomplete or unavailable. Cluster access and configuration changes can then occur without a reliable investigative trail, delaying detection and weakening the integrity and availability of security monitoring and incident response.
Kubernetes Audit Records are Incomplete or Unavailable
CCC.K8S.TH15
Related Capabilities
| ID | Title | Description |
|---|---|---|
| CCC.K8S.CP16 | Kubernetes Audit Logging | The service may be configured to emit Kubernetes API audit and control-plane records to a cloud logging destination for monitoring and investigation. |
| CCC.K8S.CP17 | Cluster Monitoring Integration | The service can send cluster, node, workload, and network activity telemetry to cloud-native or Kubernetes-compatible monitoring components. |
Related Controls
| ID | Title | Description |
|---|---|---|
| CCC.K8S.CN14 | Preserve Kubernetes Audit and Monitoring Records | Maintain complete, externally retained, access-controlled, and monitored records of security-relevant Kubernetes activity and health signals. |