Skip to content

M3 Security posture: Trivy, kube-bench and our own rules #55

Description

@Rikarin

docs/plan/18 § assessments · CyberCloud.Security/assessments · M3 · 1.5 EM.

Trivy + kube-bench + our own resource-shape rules, surfaced as a score. The catalogue's note is the right scoping instinct: a thin version of this is worth more than nothing.

⚠ "Our own resource-shape rules" is the same evaluator as #M3-policy, for the third time (policy, conditional access, posture). Building three rule engines is how they come to disagree; building one with three subjects is the version that stays true.

Related: #17 — the licence scan does not exist and bundle images are pinned by tag rather than digest. Posture that reports on tenant resources while the platform's own supply chain is unscanned is a score with an asterisk.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    securityControls named in docs/plan/18

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions