Skip to main content

TAG Security and Compliance

TAG Security and Compliance addresses security and compliance concerns in cloud native systems through best practices, assessments, tooling, policy-as-code, threat modeling, and secure software supply chain practices.

Mission Statement​

Security Hygiene, Policy-as-Code, Compliance, Auditing, Threat Modeling, Secure Software Supply Chain

Leadership​

Chairs​

NameGitHubOrganizationTerm
Evan Anderson@evankandersonCustcodian2026-06-09 to 2028-06-30
John Kjell@jkjellControl-Plane.io2025-07-02 to 2027-06-30
Marina Moore@mnm678Edera2025-07-01 to 2027-06-30

Tech Leads​

NameGitHubOrganizationTerm
Andrew McNamara@arewmRed Hat2026-07-07 to 2028-07-06
Justin Cappos@JustinCapposNew York University2025-07-02 to 2027-06-30
Maxime Coquerel@zigmax-2026-07-07 to 2028-07-06
Sherine Khoury@sherine-k-2026-07-07 to 2028-07-06
Shuting Zhao@realshutingNirmata2026-07-07 to 2028-07-06
Yoshiyuki Tabata@y-tabataHitachi2026-07-07 to 2028-07-06

TOC Liaisons​

Meetings​

TAG Security and Compliance Meetings

All meetings are open to the public. No registration required - simply join the meeting from the calendar link.

Communication Channels​

Slack​

Join the CNCF Slack workspace and connect with the TAG:

Mailing List​

Focus Areas​

TAG Security and Compliance works on several key security domains:

Security Hygiene​

Best practices for maintaining secure cloud native systems:

  • Security Posture: Assessing and improving security baseline
  • Vulnerability Management: Identifying and remediating vulnerabilities
  • Patch Management: Keeping systems updated and secure
  • Configuration Security: Hardening configurations across the stack
  • Access Control: Identity, authentication, and authorization

Policy-as-Code​

Defining and enforcing policies programmatically:

  • Policy Languages: OPA/Rego, Kyverno, and other policy frameworks
  • Admission Control: Enforcing policies at deployment time
  • Runtime Policies: Enforcing policies during execution
  • Policy Libraries: Reusable policy templates and best practices
  • Policy Testing: Validating policies before deployment

Compliance​

Meeting regulatory and industry requirements:

  • Compliance Frameworks: NIST, PCI-DSS, HIPAA, SOC2, etc.
  • Compliance Automation: Automated compliance checking and reporting
  • Audit Trails: Maintaining comprehensive audit logs
  • Compliance as Code: Managing compliance requirements programmatically
  • Continuous Compliance: Ongoing compliance monitoring

Auditing​

Monitoring and recording security-relevant activities:

  • Audit Logging: Comprehensive logging of security events
  • Log Analysis: Detecting anomalies and security incidents
  • Forensics: Investigating security incidents
  • Compliance Audits: Supporting external audit requirements
  • Audit Tools: Tooling for audit collection and analysis

Threat Modeling​

Identifying and mitigating security threats:

  • Attack Surface Analysis: Understanding potential attack vectors
  • Threat Intelligence: Staying informed about emerging threats
  • Risk Assessment: Evaluating and prioritizing security risks
  • Mitigation Strategies: Implementing controls to reduce risks
  • Security Architecture: Designing secure systems from the ground up

Secure Software Supply Chain​

Protecting the software supply chain:

  • SBOM: Software Bill of Materials generation and management
  • Artifact Signing: Cryptographic signing of software artifacts
  • Provenance: Tracking the origin and build process of software
  • Dependency Security: Managing third-party dependencies securely
  • Build Security: Securing the software build pipeline

Subprojects​

Security Assessments​

The TAG-Security Security Assessment Subproject is designed to accelerate the adoption of cloud native technologies based on the below goals and assumptions:

  1. Reduce risk across the ecosystem

    The primary goal is to minimize the risk of malicious attacks and accidental privacy breaches. This process achieves this in two ways:

    • Improve detection and resolution of vulnerabilities through a clear communication process.
    • Enhance domain expertise in participating projects via collaborative assessments.
  2. Accelerate adoption of cloud native technologies

    Security assessments are essential but time-intensive processes that each company, organization, and project must perform to meet their unique commitments to users and stakeholders. In open source, finding security-related information can be overwhelmingly difficult and time-consuming. The CNCF TAG-Security Security Assessment Process, hereafter “TSSA” Process, aims to enhance the discovery of security information and streamline internal and external assessments in multiple ways:

    • Consistent documentation to reduce assessment time.
    • Baseline of security information to minimize Q&A.
    • A clear security profile rubric for organizations to align their risk profiles with the project’s and allocate resources effectively (for assessment and needed project contribution).
    • Structured metadata for navigation, grouping, and cross-linking.

This process is expected to raise awareness of how open source projects impact cloud native security; however, separate activities may be needed to achieve that purpose using materials generated by the TSSA, known as artifacts or the TSSA package.

Learn more about Security Assessments

Initiatives​

View current and past initiatives:

Publications​

TAG Security and Compliance produces various publications to help the community:

Getting Involved​

We welcome contributions from anyone interested in cloud native security:

Attend Meetings​

Join our regular meetings to hear about ongoing work and participate in discussions. Check the meeting calendar for details.

Contribute to Initiatives​

Browse active initiatives and volunteer to help with specific deliverables.

Security Assessments​

Help conduct security assessments of CNCF projects:

  • Join assessment teams
  • Review security documentation
  • Contribute threat models
  • Provide security expertise

Share Your Experience​

  • Present security use cases or lessons learned at TAG meetings
  • Write blog posts about security practices and implementations
  • Contribute to white papers and best practices documents

Join the Conversation​

Resources​