包阅导读总结
1.
关键词:Kubernetes 安全、CIS GKE 基准、Google Cloud、合规努力、安全姿态
2.
总结:文章主要讲述了 Google Cloud 与 CIS 合作发布更新的 CIS GKE 基准,介绍了其对 GKE 安全的重要性、更新内容及如何通过相关工具进行合规审查,强调了其对提升组织安全姿态的作用。
3.
主要内容:
– 合规努力常具挑战性,工程团队难以理解要求
– Google Cloud 认为与强大平台如 Kubernetes 结合,合规管理能更易
– CIS 是负责 CIS 控制和基准的组织,其配置建议是行业标准
– Google Cloud 与 CIS 合作发布 GKE 和 GKE Autopilot 的更新基准
– 支持 GKE 1.29 – 1.31 版本
– 包括更新、删除、新增控制,分类并调整优先级等变化
– 与最新 CIS Kubernetes 基准版本对齐
– 可用 Security Health Analytics 审查合规,GKE Enterprise 有控制器加强安全
– 此基准更新体现 Google Cloud 对客户的承诺
思维导图:
文章来源:cloud.google.com
作者:Poonam Lamba,Michele Chubirka
发布时间:2024/8/7 0:00
语言:英文
总字数:562字
预计阅读时间:3分钟
评分:87分
标签:Kubernetes 安全,CIS 基准,Google Kubernetes Engine,合规性,安全态势
以下为原文内容
本内容来源于用户推荐转载,旨在分享知识与观点,如有侵权请联系删除 联系邮箱 media@ilingban.com
Compliance efforts can feel like a challenging endeavor in most organizations. Engineering teams routinely don’t understand how often-confusing requirements will actually make the organization more secure. Sometimes, even the words that define compliance requirements can be hard to comprehend. The entire exercise can feel overwhelming, like being on an endless security treadmill.
At Google Cloud, we believe that compliance efforts, essential to securely managing technology, can be easier to manage when paired with a powerful platform such as Kubernetes. From your first experience with Google Kubernetes Engine (GKE), you will find guidance on how to best implement GKE securely and in compliance with common frameworks — including those from the Center for Internet Security (CIS).
The CIS is an independent, nonprofit organization with a mission to create confidence in the connected world. It’s responsible for the CIS Controls and CIS Benchmarks, globally-recognized best practices for securing IT systems and data. These prescriptive configuration recommendations are industry-standard guidelines that can help you identify how to harden different technologies to help minimize your organizational risk.
The CIS also offers recommendations to address provider-specific implementations, such as GKE. Google Cloud’s GKE provides a best-in-class, secure-by-default configuration, which can be further heightened through Autopilot, a hands-off operations mode that follows best practices and recommendations for cluster and workload setup, scalability, and security. Google Cloud also provides the information needed to verify GKE’s security posture for assessment and audit activities.
With this goal in mind, we’ve partnered with the CIS to release updated CIS Benchmarks for GKE and GKE Autopilot. These tailored guidelines were developed in collaboration with the community to clarify which recommendations are relevant for GKE users. The latest updates feature more than 80 recommended controls which can help enhance your organization’s GKE security posture.
These benchmarks now fully support GKE versions 1.29, 1.30, and 1.31, ensuring your security posture stays in sync with the latest advancements in Google’s Kubernetes platform. Some of the changes we’ve made include:
-
Updated controls to ensure they address the latest security challenges and best practices in GKE.
-
Removed controls that are no longer relevant to GKE, streamlining the focus on essential safeguards.
-
Introduced new controls that address threats using the latest GKE security features.
-
Reviewed and categorized all controls as L1 (essential) or L2 (advanced), and streamlined guidance on how to prioritize security efforts based on your organization’s risk posture.
-
Aligned the benchmark and its recommendations with the latest CIS Kubernetes Benchmark version.
You can view the updated CIS GKE and Autopilot Benchmarks here. Additionally, GKE Enterprise comes with Compliance and Policy Controller for enforcing security controls across your GKE clusters.
This benchmark refresh represents Google Cloud’s ongoing commitment to a shared fate relationship with our customers and our secure by default pledge to the Cybersecurity and Infrastructure Security Agency (CISA). We’ve gathered the best Kubernetes security experts from Google to craft benchmarks that are accurate and can be practically applied.
You can review your compliance with CIS GKE Benchmark items using Security Health Analytics, a capability built into Security Command Center (SCC). You’ll be able to identify, review, and remediate any cluster configurations which don’t comply with recommendations displayed in the SCC dashboard.
Using the CIS Benchmarks represents an important step in safeguarding your Google Cloud infrastructure and improving your organization’s risk posture. If you’re new to GKE Enterprise, learn more about how to start a free trial.