Skip to main content

Kubernetes Audit Records are Incomplete or Unavailable

CCC.K8S.TH15

Audit policies, log categories, collection agents, export destinations, or retention settings that omit security-relevant activity may leave required Kubernetes records incomplete or unavailable. Cluster access and configuration changes can then occur without a reliable investigative trail, delaying detection and weakening the integrity and availability of security monitoring and incident response.

Related Capabilities

IDTitleDescription
CCC.K8S.CP16Kubernetes Audit LoggingThe service may be configured to emit Kubernetes API audit and control-plane records to a cloud logging destination for monitoring and investigation.
CCC.K8S.CP17Cluster Monitoring IntegrationThe service can send cluster, node, workload, and network activity telemetry to cloud-native or Kubernetes-compatible monitoring components.

Related Controls

IDTitleDescription
CCC.K8S.CN14Preserve Kubernetes Audit and Monitoring RecordsMaintain complete, externally retained, access-controlled, and monitored records of security-relevant Kubernetes activity and health signals.

External Mappings

FrameworkIDRelationshipRemarks
CWECWE-778relates-toInsufficient Logging
MITRE-ATT&CKT1685.002relates-toDisable or Modify Tools - Disable or Modify Cloud Log