Orchestration / K8S / Controls / DEV
Allowlist CSP-Provided Cluster Add-ons and Extensions
CCC.K8S.CN08 · Orchestration
Restrict enabled CSP-provided cluster add-ons, extensions, and managed features to an organization-controlled allowlist.
Related Capabilities
| ID | Title | Description |
|---|
| CCC.K8S.CP14 | Managed Cluster Extensions | The service can manage the installation and lifecycle of supported extensions for networking, storage, policy, observability, and workload management. |
| CCC.K8S.CP18 | Admission Policy Enforcement | The service may be configured with policies, admission controllers, and webhooks that validate, mutate, or reject Kubernetes API requests before persistence. |
Related Threats
| ID | Title | Description |
|---|
| CCC.K8S.TH08 | Cluster Extensions Execute Untrusted Code | An operator, controller, admission webhook, or managed extension installed without verified provenance and constrained permissions may execute untrusted code with cluster-level access. The extension can intercept sensitive data, rewrite cluster state, or interrupt workloads across its granted scope. |
Assessment Requirements
| ID | Text | Applicability |
|---|
| CCC.K8S.CN08.AR01 | When a CSP-provided cluster add-on, extension, or managed feature is enabled, it MUST be included in an organization-controlled allowlist. | tlp-clear, tlp-green, tlp-amber, tlp-red |
Guideline Mappings
| Framework | ID | Remarks |
|---|
| NIST_800_53 | SI-7 | Software, Firmware, and Information Integrity |
| NIST_800_53 | SR-3 | Supply Chain Controls and Processes |