Skip to main content

Protect Resource Metadata

CCC.K8S.CN15 · Resource

Preserve the completeness and accuracy of policy-relevant cloud tags and Kubernetes labels by limiting modification to authorized identities.

Related Capabilities

IDTitleDescription
CCC.Core.CP20Resource TaggingThe service provides users with the ability to tag a child resource with metadata that can be reviewed or queried.

Related Threats

IDTitleDescription
CCC.Core.TH13Resource Tags are ManipulatedWhen resource tags are altered, it can lead to misclassification or mismanagement of resources. This can reduce the efficacy of organizational policies, billing rules, or network access rules. Such changes could cause compromised confidentiality, integrity, or availability of the system and its data.

Assessment Requirements

IDTextApplicability
CCC.K8S.CN15.AR01When a cluster, node pool, namespace, or governed workload is created, all organization-required ownership, environment, data-classification, and policy metadata MUST be present with approved values.tlp-clear, tlp-green, tlp-amber, tlp-red
CCC.K8S.CN15.AR02When metadata controls authorization, network policy, admission, billing, or data handling, modification of that metadata MUST be restricted to a dedicated role and MUST produce an externally retained audit record.tlp-clear, tlp-green, tlp-amber, tlp-red

Guideline Mappings

FrameworkIDRemarks
NIST_800_53AC-16Security and Privacy Attributes
NIST_800_53CM-3Configuration Change Control
NIST_800_53CM-8System Component Inventory