CNSC-1 | relates-to | IA-5(7) | Runtime Secret Injection (CNSC-1) · NIST IA-5(7) — Runtime injection prevents static authenticators from being embedded in application code or container images |
CNSC-2 | relates-to | IA-9 | Mutual Authentication (CNSC-2) · NIST IA-9 — Mutual authentication between workloads establishes bidirectional identity verification before service communication |
CNSC-3 | relates-to | SC-12 | Cryptographic Key Management (CNSC-3) · NIST SC-12 — Key rotation is a key management lifecycle activity addressed by SC-12 |
CNSC-4 | relates-to | SC-12 | Cryptographic Key Lifecycle Management (CNSC-4) · NIST SC-12 — Short key lifespan is a key management lifecycle policy addressed by SC-12 |
CNSC-5 | relates-to | SA-9
SC-12 | Sensitive Credential Management (CNSC-5) · NIST SA-9 — Independent credential management addresses risk from reliance on external cloud provider services Sensitive Credential Management (CNSC-5) · NIST SC-12 — Generation and management of credentials is a key management lifecycle activity |
CNSC-6 | relates-to | IA-13
AC-3 | Identification and Authentication (CNSC-6) · NIST IA-13 — Independent authentication and authorization map to the separation of identity providers from authorization servers Identification and Authentication (CNSC-6) · NIST AC-3 — Authorization decisions are enforced as a distinct process from identity authentication |
CNSC-7 | relates-to | AC-3 | Authentication and Authorization Enforcement (CNSC-7) · NIST AC-3 — Independent enforcement of authorization is distinct from the authentication mechanism that establishes identity |
CNSC-8 | relates-to | SI-4(2) | Continuous System Monitoring (CNSC-8) · NIST SI-4(2) — Real-time access control and permission updates require automated monitoring to detect and respond to changes |
CNSC-9 | relates-to | AC-3(13)
AC-3(7) | Privileged-based Authorization (CNSC-9) · NIST AC-3(13) — Workload authorization based on pre-assigned attributes aligns with attribute-based access control enforcement Privileged-based Authorization (CNSC-9) · NIST AC-3(7) — Workload authorization based on pre-assigned roles and permissions aligns with role-based access control enforcement |
CNSC-10 | relates-to | AC-3(13)
AC-3(7) | ABAC and RBAC (CNSC-10) · NIST AC-3(13) — ABAC enforces access decisions based on workload and environmental attributes ABAC and RBAC (CNSC-10) · NIST AC-3(7) — RBAC enforces access decisions based on pre-defined role assignments |
CNSC-11 | relates-to | AC-24 | Authorization and Identity Management (CNSC-11) · NIST AC-24 — Forwarded identity context enables dynamic authorization decisions at each service boundary |
CNSC-12 | relates-to | IA-2 | Cluster Authentication Management (CNSC-12) · NIST IA-2 — Cluster and workload operators are organizational users requiring unique identification and authentication |
CNSC-13 | relates-to | AC-3 | Authentication Policy Management (CNSC-13) · NIST AC-3 — Operator actions are evaluated against access control policies governing context, purpose, and output |
CNSC-14 | relates-to | IA-2(1)
IA-2(2) | Multi-factor Authentication (CNSC-14) · NIST IA-2(1) — Identity federation requiring MFA applies to privileged account access Multi-factor Authentication (CNSC-14) · NIST IA-2(2) — Identity federation requiring MFA applies to non-privileged account access |
CNSC-15 | relates-to | SC-12(1)
SC-3(1) | HSMs Protection of Cryptographic Secrets (CNSC-15) · NIST SC-12(1) — HSMs provide hardware-based key storage and management for cryptographic secret protection HSMs Protection of Cryptographic Secrets (CNSC-15) · NIST SC-3(1) — HSMs enforce hardware separation of cryptographic security functions from the general-purpose environment |
CNSC-16 | relates-to | SI-12 | Secrets Management (CNSC-16) · NIST SI-12 — Short expiration periods enforce timely disposal of secrets as a retention lifecycle policy |
CNSC-17 | relates-to | IA-5 | Secrets Lifecycle Management (CNSC-17) · NIST IA-5 — Verification of secret expiration and TTL prevents reuse of stale authenticators |
CNSC-18 | relates-to | SC-12(1) | Secrets Management System (CNSC-18) · NIST SC-12(1) — Secrets management system availability ensures continuous access to cryptographic key infrastructure |
CNSC-19 | relates-to | IA-5 | Secrets Rotation Management (CNSC-19) · NIST IA-5 — Periodic rotation and revocation of long-lived secrets is an authenticator management lifecycle activity |
CNSC-20 | relates-to | SC-8 | Secrets Protection (CNSC-20) · NIST SC-8 — Secrets distributed through communication channels require transmission confidentiality and integrity proportional to sensitivity |
CNSC-21 | relates-to | AU-9 | Secret Injection Lifecycle (CNSC-21) · NIST AU-9 — Runtime secrets are masked or excluded to protect audit information from credential exposure |
CNSC-22 | relates-to | SI-7(9) | Compute Bootstrapping Verification (CNSC-22) · NIST SI-7(9) — Bootstrapping verification of compute location is a boot process integrity check |
CNSC-23 | relates-to | SC-39
SC-7(21) | Boundary Management (CNSC-23) · NIST SC-39 — Workloads with different data sensitivity classifications require separate kernel-level execution domains Boundary Management (CNSC-23) · NIST SC-7(21) — Isolation of workload components based on data sensitivity classification |
CNSC-24 | relates-to | CM-2(2)
CM-3(7) | Runtime Configuration Monitoring (CNSC-24) · NIST CM-2(2) — Automated detection of runtime configuration drift from the established baseline Runtime Configuration Monitoring (CNSC-24) · NIST CM-3(7) — Runtime configuration changes are reviewed and correlated against authorized modifications |
CNSC-25 | relates-to | AU-2 | API Auditing Implementation (CNSC-25) · NIST AU-2 — Filtered API auditing defines the specific events and verbs captured for logging |
CNSC-26 | relates-to | CM-2
CM-7 | Operating System Configuration (CNSC-26) · NIST CM-2 — Container-specific operating systems establish a purpose-built hardened baseline Operating System Configuration (CNSC-26) · NIST CM-7 — Container-specific operating systems remove unnecessary services and functionality by design |
CNSC-27 | relates-to | SI-7 | Trust Implementation (CNSC-27) · NIST SI-7 — TPM and vTPM provide a hardware root of trust for software and firmware integrity verification |
CNSC-28 | relates-to | AC-6 | Least Privilege (CNSC-28) · NIST AC-6 — Minimizing administrative access to the control plane applies the principle of least privilege |
CNSC-29 | relates-to | SC-6
SC-39 | Resource Control Management (CNSC-29) · NIST SC-6 — Cgroup resource requests and limits enforce allocation boundaries to prevent resource exhaustion Resource Control Management (CNSC-29) · NIST SC-39 — Cgroups provide process-level isolation of resource consumption between workloads |
CNSC-30 | relates-to | SI-4(13) | System Alert Monitoring (CNSC-30) · NIST SI-4(13) — Alert tuning for false positives refines traffic and event pattern analysis effectiveness |
CNSC-31 | relates-to | IA-9
SC-12 | Control Plane Configuration (CNSC-31) · NIST IA-9 — Control plane components use mutual authentication and certificate validation to verify service identity Control Plane Configuration (CNSC-31) · NIST SC-12 — Periodic certificate rotation for control plane communication is a key management lifecycle activity |
CNSC-32 | relates-to | CM-2
CM-7 | Baseline Configured Functionality (CNSC-32) · NIST CM-2 — Seccomp filters define a baseline of sanctioned system calls for container execution Baseline Configured Functionality (CNSC-32) · NIST CM-7 — Restricting container capabilities and system calls enforces least functionality |
CNSC-33 | relates-to | CM-5 | Critical Change Management (CNSC-33) · NIST CM-5 — Protecting critical mount points and files from unauthorized modification is an access restriction for change |
CNSC-34 | relates-to | CM-5 | Runtime Configuration for Change Management (CNSC-34) · NIST CM-5 — Runtime immutability of binaries, certificates, and remote access configurations restricts unauthorized change |
CNSC-35 | relates-to | SC-7 | Runtime Boundary Protection Management (CNSC-35) · NIST SC-7 — Container-level ingress and egress restrictions enforce network boundary protection at runtime |
CNSC-36 | relates-to | SC-7 | Boundary Protection Management (CNSC-36) · NIST SC-7 — Microservice communication allow-listing is application-layer network segmentation |
CNSC-37 | relates-to | CM-14 | Policy Enforcement Management (CNSC-37) · NIST CM-14 — Policy agents enforcing image signatures validate that only signed components are admitted |
CNSC-38 | relates-to | SR-4(3) | Policy Enforcement Management (CNSC-38) · NIST SR-4(3) — Policy agents enforce provenance validation to confirm workload origin and integrity |
CNSC-39 | relates-to | SC-8 | Data Trust Management (CNSC-39) · NIST SC-8 — Service mesh encryption of data in transit protects transmission confidentiality and integrity |
CNSC-40 | relates-to | SI-4 | System Monitoring Components (CNSC-40) · NIST SI-4 — Container-level observation of system calls and network traffic implements system monitoring |
CNSC-41 | relates-to | SI-3 | Dynamic Workload Scanning (CNSC-41) · NIST SI-3 — Dynamic behavioral scanning detects zero-day and previously unknown malicious activity in running workloads |
CNSC-42 | relates-to | RA-5 | Continuous Monitoring and Scanning (CNSC-42) · NIST RA-5 — Continuous environment scanning for workload vulnerabilities is a vulnerability monitoring activity |
CNSC-43 | relates-to | AU-3 | Audit Event Logging (CNSC-43) · NIST AU-3 — Sufficient audit record content is a prerequisite for log correlation and incident response decision-making |
CNSC-44 | relates-to | AC-6
AC-5 | Privilege Management (CNSC-44) · NIST AC-6 — Least privilege limits workload and operator permissions to the minimum required Privilege Management (CNSC-44) · NIST AC-5 — Segregation of duties prevents any single actor from controlling an entire critical function |
CNSC-45 | relates-to | SI-7 | Information Integrity (CNSC-45) · NIST SI-7 — Policy-based violation detection verifies system state integrity against organizational rules |
CNSC-46 | relates-to | SC-12 | Key Management Storage (CNSC-46) · NIST SC-12 — External KMS integration for native secret store encryption is a key management infrastructure decision |
CNSC-47 | relates-to | SC-28(1) | Secret Storage Configuration (CNSC-47) · NIST SC-28(1) — Secret stores must use cryptographic protection rather than encoding for data at rest |
CNSC-48 | relates-to | SI-4 | System Monitoring (CNSC-48) · NIST SI-4 — Detection and denial of traffic to malicious domains is network-level system monitoring |
CNSC-49 | relates-to | SC-28 | Sensitive Data Encryption (CNSC-49) · NIST SC-28 — Encrypted containers protect sensitive data at rest within container images and filesystems |
CNSC-50 | relates-to | CM-8 | SBOM Management (CNSC-50) · NIST CM-8 — SBOMs serve as a machine-readable component inventory for identifying vulnerable dependencies |
CNSC-51 | relates-to | CM-2
CM-7 | Functionality Management (CNSC-51) · NIST CM-2 — Function allow-listing defines a baseline of permitted process execution Functionality Management (CNSC-51) · NIST CM-7 — Restricting processes to explicitly allowed functions enforces least functionality |
CNSC-52 | relates-to | CM-5 | Access and Change Restrictions (CNSC-52) · NIST CM-5 — Preventing function-level modifications to critical filesystem mount points is an access restriction for change |
CNSC-53 | relates-to | AC-3 | Access Configuration (CNSC-53) · NIST AC-3 — Restricting function access to sanctioned services enforces service-level access control |
CNSC-54 | relates-to | SI-4 | System Monitoring (CNSC-54) · NIST SI-4 — Egress monitoring for command and control traffic detects compromised workload communication |
CNSC-55 | relates-to | SI-4 | System Monitoring Management (CNSC-55) · NIST SI-4 — Ingress inspection for malicious payloads and commands is inbound network monitoring |
CNSC-56 | relates-to | SC-7(21) | System Component Isolation (CNSC-56) · NIST SC-7(21) — Tenant-based isolation of serverless functions by data classification implements component isolation |
CNSC-57 | relates-to | SR-4(3)
SR-4(4) | Trust Confirmation (CNSC-57) · NIST SR-4(3) — Image signature verification confirms the artifact is genuine and unaltered Trust Confirmation (CNSC-57) · NIST SR-4(4) — Validating the signature source traces the artifact back to an authorized origin |
CNSC-58 | relates-to | CM-4 | Runtime Policy Enforcement (CNSC-58) · NIST CM-4 — Pre-deployment policy enforcement gates image admission on integrity and trust criteria |
CNSC-59 | relates-to | SR-4(3)
SR-4(4) | Image Integrity Verification (CNSC-59) · NIST SR-4(3) — Pre-deployment integrity verification confirms the image has not been altered Image Integrity Verification (CNSC-59) · NIST SR-4(4) — Pre-deployment signature verification traces the image to its authorized build origin |
CNSC-60 | relates-to | AU-2
AU-3 | Application Logging (CNSC-60) · NIST AU-2 — Authentication, authorization, action, and failure events are identified for application logging Application Logging (CNSC-60) · NIST AU-3 — Application logs include authentication, authorization, action, and failure content |
CNSC-62 | relates-to | SI-3 | Behavioral Analysis (CNSC-62) · NIST SI-3 — AI/ML-based heuristic analysis extends malicious code detection beyond signature-based methods |
CNSC-63 | relates-to | SA-3(1) | Production Environment (CNSC-63) · NIST SA-3(1) — A dedicated production environment implies managed separation from preproduction stages |
CNSC-64 | relates-to | SA-8(31) | Dynamic Deployments (CNSC-64) · NIST SA-8(31) — Dynamic deployment strategies (canary, blue-green, rolling) are secure system modification techniques |
CNSC-65 | relates-to | SA-11(1) | Early Vulnerability Scanning (CNSC-65) · NIST SA-11(1) — IDE and pull request scanning shifts static analysis to the earliest point in the development lifecycle |
CNSC-66 | relates-to | SA-15 | Environment Segregation (CNSC-66) · NIST SA-15 — Segregation of development, testing, and production environments is a development process standard |
CNSC-67 | relates-to | SA-11 | Business-Critical Code Testing (CNSC-67) · NIST SA-11 — Testing business-critical code is a developer evaluation activity |
CNSC-68 | relates-to | SA-11 | Infrastructure Testing (CNSC-68) · NIST SA-11 — Testing business-critical infrastructure is a developer evaluation activity |
CNSC-69 | relates-to | SA-11 | Local Test Execution (CNSC-69) · NIST SA-11 — Local test execution enables developer evaluation before code integration |
CNSC-70 | relates-to | SA-11 | Shared Test Execution (CNSC-70) · NIST SA-11 — Shared test environments enable collaborative developer evaluation |
CNSC-71 | relates-to | SA-11(4) | Code Review Requirements (CNSC-71) · NIST SA-11(4) — Non-author code review is a manual evaluation gate prior to integration |
CNSC-73 | relates-to | SA-11 | Full Infrastructure Testing (CNSC-73) · NIST SA-11 — Full infrastructure testing validates the complete deployment target |
CNSC-74 | relates-to | SA-11 | Regression Testing (CNSC-74) · NIST SA-11 — Regression testing verifies existing functionality is preserved after changes |
CNSC-75 | relates-to | SA-11 | Security Regression Testing (CNSC-75) · NIST SA-11 — Security regression tests evolve developer evaluation against emerging threats |
CNSC-76 | relates-to | SA-3(1) | Testing Environment (CNSC-76) · NIST SA-3(1) — A dedicated testing environment is a managed preproduction stage in the development lifecycle |
CNSC-77 | relates-to | SC-39 | CI Server Isolation (CNSC-77) · NIST SC-39 — CI server isolation prevents build processes from affecting or being affected by other workloads |
CNSC-78 | relates-to | SA-11(2) | Threat-Informed Test Development (CNSC-78) · NIST SA-11(2) — Threat model results inform test development priorities and investment decisions |
CNSC-85 | relates-to | RA-5 | Manifest Scanning (CNSC-85) · NIST RA-5 — Manifest scanning in CI detects vulnerabilities in declared dependencies before deployment |
CNSC-86 | relates-to | SC-39 | CI Server Isolation (CNSC-86) · NIST SC-39 — Isolating CI servers for sensitive workloads prevents cross-contamination of build processes |
CNSC-87 | relates-to | SC-39 | Privileged Build Isolation (CNSC-87) · NIST SC-39 — Dedicating servers for privileged builds isolates elevated-privilege execution from other processes |
CNSC-88 | relates-to | SA-1 | Build Policy Enforcement (CNSC-88) · NIST SA-1 — Build policy enforcement establishes CI pipeline governance procedures |
CNSC-89 | relates-to | SI-7 | Pipeline Metadata Signing (CNSC-89) · NIST SI-7 — Signed pipeline metadata ensures integrity of build process records |
CNSC-90 | relates-to | SI-7 | Build Stage Verification (CNSC-90) · NIST SI-7 — Stage-gate verification ensures integrity is maintained between build phases |
CNSC-91 | relates-to | RA-5 | CI Pipeline Scanning (CNSC-91) · NIST RA-5 — CI pipeline image scanning detects vulnerabilities before artifacts leave the build process |
CNSC-92 | relates-to | SA-1 | Pipeline Compliance Integration (CNSC-92) · NIST SA-1 — Coupling vulnerability scans with compliance rules integrates security into pipeline procedures |
CNSC-93 | relates-to | SA-11(8) | Dynamic Application Security Testing (CNSC-93) · NIST SA-11(8) — DAST validates application security through runtime interaction testing |
CNSC-94 | relates-to | SI-4 | Application Instrumentation (CNSC-94) · NIST SI-4 — Application instrumentation provides runtime observability for system monitoring |
CNSC-97 | relates-to | SI-4 | Security Health Verification (CNSC-97) · NIST SI-4 — Build and deploy-time security health checks are automated monitoring gates |
CNSC-99 | relates-to | CA-8
SA-11 | Automated Security Testing (CNSC-99) · NIST CA-8 — Automated security testing includes penetration testing techniques Automated Security Testing (CNSC-99) · NIST SA-11 — Automation of security testing ensures consistent developer evaluation |
CNSC-100 | relates-to | IA-3(1) | Registry Authentication (CNSC-100) · NIST IA-3(1) — Mutual TLS for registry connections requires cryptographic bidirectional device authentication |
CNSC-101 | relates-to | SI-7 | Image Signing (CNSC-101) · NIST SI-7 — Signing images and metadata provides integrity verification for distributed artifacts |
CNSC-102 | relates-to | SI-7 | Configuration Signing (CNSC-102) · NIST SI-7 — Signed configuration prevents unauthorized modification of workload settings |
CNSC-103 | relates-to | SI-7 | Package Signing (CNSC-103) · NIST SI-7 — Signed packages provide integrity verification for distributed software |
CNSC-104 | relates-to | SI-7 | Image Integrity Validation (CNSC-104) · NIST SI-7 — Image integrity validation detects unauthorized modification of container artifacts |
CNSC-105 | relates-to | RA-5
SA-3 | Image Vulnerability Scanning (CNSC-105) · NIST RA-5 — Image scanning detects known vulnerabilities and malware in container artifacts Image Vulnerability Scanning (CNSC-105) · NIST SA-3 — Vulnerability scanning of images is integrated into the development lifecycle |
CNSC-106 | relates-to | SC-12 | Key Revocation (CNSC-106) · NIST SC-12 — Key revocation invalidates trust in artifacts signed by compromised keys |
CNSC-107 | relates-to | SI-2(3) | Security Update Prioritization (CNSC-107) · NIST SI-2(3) — Prioritizing security updates is a flaw remediation scheduling activity |
CNSC-108 | relates-to | SC-12(3) | Credential Protection (CNSC-108) · NIST SC-12(3) — HSMs provide asymmetric key infrastructure for credential protection |
CNSC-109 | relates-to | SI-2(3) | Scanning Remediation (CNSC-109) · NIST SI-2(3) — Acting on container image scanning findings is flaw remediation |
CNSC-110 | relates-to | PL-1 | Compliance Enforcement (CNSC-110) · NIST PL-1 — Enforcing organizational compliance rules is a planning and policy activity |
CNSC-112 | relates-to | AC-6(3) | Public Registry Access Control (CNSC-112) · NIST AC-6(3) — Restricting public registry pulls to authorized engineers enforces network access to privileged commands |
CNSC-113 | relates-to | SC-12(2)
SC-12(3) | Image Encryption Management (CNSC-113) · NIST SC-12(2) — Image encryption uses symmetric keys for bulk data protection Image Encryption Management (CNSC-113) · NIST SC-12(3) — Key attestation and credential distribution use asymmetric keys for authorization |
CNSC-114 | relates-to | SI-2(3) | Risk-Based Remediation Prioritization (CNSC-114) · NIST SI-2(3) — Risk-based prioritization using exploit maturity and vulnerable paths refines flaw remediation scheduling |
CNSC-115 | relates-to | AC-6(3) | East-West Network Policy (CNSC-115) · NIST AC-6(3) — East-west network policies restrict lateral communication to authorized network-level privileged commands |
CNSC-116 | relates-to | CA-7
IR-4
IR-4(5) | Incident Response (CNSC-116) · NIST CA-7 — Cloud native incident response requires continuous monitoring of workload behavior Incident Response (CNSC-116) · NIST IR-4 — Incident handling processes must account for cloud native workload dynamics Incident Response (CNSC-116) · NIST IR-4(5) — Automated disabling of compromised cloud native workloads |
CNSC-117 | relates-to | IR-5(1) | Incident Monitoring (CNSC-117) · NIST IR-5(1) — Evidence handling and collection for cloud native workloads requires automated tracking and data collection |
CNSC-120 | relates-to | AC-3(3) | Mandatory Access Controls (CNSC-120) · NIST AC-3(3) — MAC implementations enforce mandatory access control policies |
CNSC-121 | relates-to | SA-11(2) | Threat Modeling and Vulnerability Analysis (CNSC-121) · NIST SA-11(2) — Threat modeling of code and infrastructure informs vulnerability analysis |
CNSC-122 | relates-to | IA-9 | Authentication Management (CNSC-122) · NIST IA-9 — Independent authentication of entity identities is service-level identification and authentication |
CNSC-123 | relates-to | IA-9 | Identity Management (CNSC-123) · NIST IA-9 — Proof of identity creation enables service identification and authentication |
CNSC-124 | relates-to | CM-14 | Trusted Components (CNSC-124) · NIST CM-14 — Trusted OS and BIOS for orchestrators requires signed and verified system components |
CNSC-125 | relates-to | SI-6 | Security Verification (CNSC-125) · NIST SI-6 — Verifying container claims is a security function verification activity |
CNSC-127 | relates-to | SC-8 | Control Plane Authentication (CNSC-127) · NIST SC-8 — Mutual authentication and TLS for control plane connections protects transmission confidentiality and integrity |
CNSC-128 | relates-to | SI-13 | Data Availability Mechanism (CNSC-128) · NIST SI-13 — Parity, mirroring, and replicas are predictable failure prevention mechanisms for data availability |
CNSC-129 | relates-to | CM-7
SI-7 | Integrity Validation (CNSC-129) · NIST CM-7 — Checksums constrain storage to validated data, supporting least functionality Integrity Validation (CNSC-129) · NIST SI-7 — Hashing and checksums verify data integrity |
CNSC-130 | relates-to | SA-9 | Data Source Storage Management (CNSC-130) · NIST SA-9 — Backup locations with equivalent security controls are managed as external system services |
CNSC-131 | relates-to | CP-9
MP-6 | System Backup (CNSC-131) · NIST CP-9 — Data is backed up before device disposition System Backup (CNSC-131) · NIST MP-6 — OPAL-standard erasure of returned devices is media sanitization |
CNSC-132 | relates-to | SC-28 | Encryption of Data at Rest (CNSC-132) · NIST SC-28 — Data-at-rest encryption decisions based on access patterns align with protection of information at rest |
CNSC-135 | relates-to | CM-6
SA-8
SC-7 | Security Policy Management (CNSC-135) · NIST CM-6 — Volume mount access restrictions are configuration settings Security Policy Management (CNSC-135) · NIST SA-8 — Volume access restrictions implement security engineering isolation principles Security Policy Management (CNSC-135) · NIST SC-7 — Preventing container access to worker node volumes is boundary protection |
CNSC-136 | relates-to | CM-6
SA-8
SC-7 | Security Policy Enforcement (CNSC-136) · NIST CM-6 — Enforced volume access policies are configuration settings Security Policy Enforcement (CNSC-136) · NIST SA-8 — Authorized volume access enforcement applies security engineering principles Security Policy Enforcement (CNSC-136) · NIST SC-7 — Worker node volume access restrictions enforce boundary protection |
CNSC-137 | relates-to | AC-16
AC-4
SI-7 | Information Flow Management (CNSC-137) · NIST AC-16 — Volume UID/GID are security attributes controlling access scope Information Flow Management (CNSC-137) · NIST AC-4 — Restricting UID/GID access enforces information flow between containers and volumes Information Flow Management (CNSC-137) · NIST SI-7 — Protecting volume UID/GID from container access preserves file system integrity |
CNSC-139 | relates-to | CM-14 | Signed Artifact Support (CNSC-139) · NIST CM-14 — Registry support for signed artifacts enables component signature verification |
CNSC-140 | relates-to | AU-10
CM-6 | Artifact Registry Policy Verification (CNSC-140) · NIST AU-10 — Policy-based artifact verification provides a non-repudiation mechanism Artifact Registry Policy Verification (CNSC-140) · NIST CM-6 — Organizational artifact policies are configuration settings enforced by the registry |
CNSC-141 | relates-to | SI-1
SI-7 | Build Process Attestation (CNSC-141) · NIST SI-1 — Build process attestation establishes integrity policy for each pipeline stage Build Process Attestation (CNSC-141) · NIST SI-7 — Signing each build step provides verifiable integrity of the build process |
CNSC-142 | relates-to | SI-1
SI-7 | Build Signature Verification (CNSC-142) · NIST SI-1 — Verifying signatures at each build step enforces integrity policy compliance Build Signature Verification (CNSC-142) · NIST SI-7 — Signature verification at each stage detects unauthorized modification of build artifacts |
CNSC-143 | relates-to | IA-5 | Artifact Signing Framework (CNSC-143) · NIST IA-5 — The signing framework manages cryptographic authenticators for artifact identity |
CNSC-144 | relates-to | AC-4(6) | Attestation Store (CNSC-144) · NIST AC-4(6) — Attestation metadata controls information flow decisions about artifact provenance |
CNSC-145 | relates-to | AC-6 | Certification Authorization (CNSC-145) · NIST AC-6 — Limiting certification authority applies the principle of least privilege to artifact signing |
CNSC-146 | relates-to | SC-12 | Key Rotation and Revocation (CNSC-146) · NIST SC-12 — Private key rotation and revocation are key management lifecycle activities |
CNSC-148 | relates-to | IA-5
SC-12
SC-13
SC-28(1)
SC-8 | Artifact Encryption (CNSC-148) · NIST IA-5 — Decryption capabilities are managed as platform authenticators Artifact Encryption (CNSC-148) · NIST SC-12 — Encryption keys require lifecycle management Artifact Encryption (CNSC-148) · NIST SC-13 — Artifact encryption uses approved cryptographic mechanisms Artifact Encryption (CNSC-148) · NIST SC-28(1) — Encrypted artifacts at rest use cryptographic protection Artifact Encryption (CNSC-148) · NIST SC-8 — Encrypted distribution protects artifact confidentiality and integrity in transit |
CNSC-149 | relates-to | CM-3(6) | Cryptographic Policy Guarantee (CNSC-149) · NIST CM-3(6) — Cryptographic guarantees of policy adherence provide tamper-evident configuration change control |
CNSC-150 | relates-to | CM-3(2) | Environment and Dependency Validation (CNSC-150) · NIST CM-3(2) — Validating environments and dependencies before usage tests configuration changes for impact |
CNSC-151 | relates-to | CM-3(4) | Build Worker Runtime Security (CNSC-151) · NIST CM-3(4) — Build worker runtime security validation is an automated security response to configuration changes |
CNSC-152 | relates-to | CM-3(4) | Reproducible Builds (CNSC-152) · NIST CM-3(4) — Reproducible builds provide automated verification of configuration change outcomes |
CNSC-153 | relates-to | CM-3(2) | External Requirement Verification (CNSC-153) · NIST CM-3(2) — Locking and verifying external requirements tests configuration changes for impact before execution |
CNSC-155 | relates-to | CM-3(1) | Build Environment Recording (CNSC-155) · NIST CM-3(1) — Recording the build environment provides automated documentation of configuration changes |
CNSC-156 | relates-to | CM-3(3) | Build Environment Automation (CNSC-156) · NIST CM-3(3) — Automated build environment creation implements automated change implementation mechanisms |
CNSC-157 | relates-to | CM-3(3) | Build Distribution (CNSC-157) · NIST CM-3(3) — Distributing builds across infrastructure uses automated change mechanisms to reduce single points of failure |
CNSC-158 | relates-to | SA-3 | Pipeline as Code (CNSC-158) · NIST SA-3 — Pipeline-as-code defines the system development lifecycle for build automation |
CNSC-161 | relates-to | AC-2 | Single-Use Build Workers (CNSC-161) · NIST AC-2 — Single-use build workers enforce ephemeral account management for build processes |
CNSC-162 | relates-to | SC-7(3) | Software Factory Network Isolation (CNSC-162) · NIST SC-7(3) — Minimal network connectivity for the software factory restricts access points as boundary protection |
CNSC-163 | relates-to | AC-5 | Build Worker Duty Segregation (CNSC-163) · NIST AC-5 — Segregating build worker duties enforces separation of duties in the build pipeline |
CNSC-164 | relates-to | CM-2(2) | Build Worker Environment Control (CNSC-164) · NIST CM-2(2) — Passing in environment and commands enforces baseline configuration through automation |
CNSC-165 | relates-to | AU-9(2) | Secured Output Storage (CNSC-165) · NIST AU-9(2) — Secured output storage protects build audit information in a separate repository |
CNSC-167 | relates-to | AC-2 | User Role Definition (CNSC-167) · NIST AC-2 — Defining user roles for the build pipeline is an account management activity |
CNSC-168 | relates-to | SC-17 | Root of Trust Establishment (CNSC-168) · NIST SC-17 — Offline root of trust establishment aligns with PKI certificate management practices |
CNSC-169 | relates-to | SC-23(5) | Short-Lived Certificates (CNSC-169) · NIST SC-23(5) — Short-lived workload certificates enforce session authenticity with time-bound validity |
CNSC-170 | relates-to | SI-7 | Artifact Verification (CNSC-170) · NIST SI-7 — Client-side artifact verification confirms integrity before consumption |
CNSC-171 | relates-to | SI-7 | Freshness Verification (CNSC-171) · NIST SI-7 — Freshness verification detects stale or replayed artifacts |
CNSC-173 | relates-to | SA-11 | Third-Party Artifact Verification (CNSC-173) · NIST SA-11 — Verification of third-party artifacts is a supply chain evaluation activity |
CNSC-174 | relates-to | CM-8 | Third-Party SBOM Requirements (CNSC-174) · NIST CM-8 — Third-party SBOMs provide component inventory for supply chain transparency |
CNSC-175 | relates-to | CM-10 | Dependency Tracking (CNSC-175) · NIST CM-10 — Tracking open source component dependencies enforces software usage restrictions |
CNSC-179 | relates-to | RA-5 | Software Vulnerability Scanning (CNSC-179) · NIST RA-5 — Software vulnerability scanning identifies known weaknesses in third-party materials |
CNSC-180 | relates-to | CM-10 | License Compliance Scanning (CNSC-180) · NIST CM-10 — License compliance scanning enforces software usage restrictions for legal compliance |
CNSC-181 | relates-to | SA-11(1) | Software Composition Analysis (CNSC-181) · NIST SA-11(1) — SCA combines static analysis to evaluate ingested software |
CNSC-182 | relates-to | SI-7 | Commit and Tag Signing (CNSC-182) · NIST SI-7 — Signed commits and tags establish integrity and authorship of source code changes |
CNSC-183 | relates-to | AC-6(3) | Branch Protection Attestation (CNSC-183) · NIST AC-6(3) — Attestation enforcement for protected branches restricts code modification to authorized privileged commands |
CNSC-184 | relates-to | SC-12(3) | Secret Commit Prevention (CNSC-184) · NIST SC-12(3) — Encrypting secrets before repository commit requires asymmetric key infrastructure |
CNSC-185 | relates-to | PL-1 | Repository Access Definition (CNSC-185) · NIST PL-1 — Defining repository write access is an access planning and policy activity |
CNSC-186 | relates-to | RA-5 | Automated Security Scanning (CNSC-186) · NIST RA-5 — Automation of security scanning ensures consistent vulnerability detection in source code |
CNSC-187 | relates-to | PL-1 | Contribution Policy Enforcement (CNSC-187) · NIST PL-1 — Contribution policies establish governance procedures for source code changes |
CNSC-188 | relates-to | PL-1 | Functional Role Definition (CNSC-188) · NIST PL-1 — Defining roles aligned to functional responsibilities is a planning and policy activity |
CNSC-189 | relates-to | SA-11 | Four-Eyes Principle (CNSC-189) · NIST SA-11 — The four-eyes principle ensures independent evaluation of code changes |
CNSC-190 | relates-to | SA-8 | Branch Protection Rules (CNSC-190) · NIST SA-8 — Branch protection rules implement security engineering principles for source code governance |
CNSC-191 | relates-to | IA-2(1) | Repository MFA Enforcement (CNSC-191) · NIST IA-2(1) — Repository MFA enforcement requires multi-factor authentication for organizational users accessing source code |
CNSC-192 | relates-to | AC-1 | SSH Key Access (CNSC-192) · NIST AC-1 — SSH key-based access to repositories implements access control procedures for developer authentication |
CNSC-193 | relates-to | AC-2(1) | Key Rotation Policy (CNSC-193) · NIST AC-2(1) — Key rotation policy defines prerequisites for automated credential management |
CNSC-194 | relates-to | AC-2(1) | Ephemeral Credentials (CNSC-194) · NIST AC-2(1) — Ephemeral credentials automate credential lifecycle management for machine and service accounts |
CNSC-195 | relates-to | SA-8(23) | Secure Configuration Defaults (CNSC-195) · NIST SA-8(23) — Secure default configuration implements the secure defaults engineering principle |
CNSC-208 | relates-to | IA-2(1)
IA-2(2) | Multi-factor Authentication (CNSC-208) · NIST IA-2(1) — Identity federation with MFA requires multi-factor authentication for privileged users Multi-factor Authentication (CNSC-208) · NIST IA-2(2) — Identity federation with MFA requires multi-factor authentication for non-privileged users |
CNSC-233 | relates-to | SC-7 | Data Trust Management (CNSC-233) · NIST SC-7 — Service mesh data-in-motion protection establishes boundary protection through confidentiality, integrity, and authentication |
CNSC-259 | relates-to | SA-11(1) | Early Vulnerability Scanning (CNSC-259) · NIST SA-11(1) — Integrating scanning in IDE and CI during pull request shifts static analysis left |
CNSC-265 | relates-to | SA-11(4) | Code Review Requirements (CNSC-265) · NIST SA-11(4) — Requiring a non-author reviewer prior to merging is a manual code review gate |
CNSC-271 | relates-to | SC-39 | CI Server Isolation (CNSC-271) · NIST SC-39 — CI server isolation and hardening prevents compromise of build infrastructure |
CNSC-297 | relates-to | SI-7 | Configuration Signing (CNSC-297) · NIST SI-7 — Signed workload configuration prevents unauthorized modification |
CNSC-298 | relates-to | SI-7 | Package Signing (CNSC-298) · NIST SI-7 — Signed workload packages provide integrity verification for deployment artifacts |
CNSC-303 | relates-to | SC-12(3) | Credential Protection (CNSC-303) · NIST SC-12(3) — HSMs or software credential managers protect asymmetric keys for stored credentials |