Memory hook: A framework sets direction; a benchmark checks configuration; evidence proves the control ran.
Must remember
Compliance means satisfying applicable obligations and agreed controls within a defined scope. Security is the broader practice of reducing risk. Passing a configuration scan is evidence about particular checks at a particular time, not proof that an entire organization or application is secure or compliant.
| Reference | Main purpose | Exam distinction |
|---|---|---|
| NIST Cybersecurity Framework | Organize risk-management outcomes | CSF 2.0 functions: Govern, Identify, Protect, Detect, Respond, Recover |
| ISO/IEC 27001 | Requirements for an information security management system | Governance, risk assessment and continual improvement; not a Kubernetes manifest |
| CIS Kubernetes Benchmark | Assess recommended platform configuration | Use the version/profile suitable for the cluster and provider |
| STRIDE | Structure threat discovery | Analyze how identities, information and availability can be attacked |
| MITRE ATT&CK | Organize adversary behavior | Connect techniques to detection and mitigation, rather than certify compliance |
| SLSA | Strengthen software supply-chain assurance | Build/source integrity and provenance, not proof of vulnerability-free code |
Map obligations to assets, owners, controls and evidence. For sensitive data, that can include restricted access, protected transport/storage, retention decisions, audit records and tested recovery. Privacy or payment-card obligations depend on the data, system and jurisdiction. The exam decision is to identify the applicable control and responsible owner, not assume every workload has the same legal scope.
Threat-modeling frameworks guide repeatable reasoning. Draw assets, entry points, data flows and trust boundaries, identify plausible threats, select mitigations, then validate and update the model as the system changes. Risk scoring aids prioritization but does not remove uncertainty or replace a documented treatment decision.
Supply-chain compliance needs traceable evidence: reviewed source, approved dependencies/licenses, inventory/SBOM, vulnerability decisions, artifact signatures/provenance and authorized deployment records. Bind evidence to a specific artifact digest or release. An unsigned spreadsheet claiming a release was scanned is weaker evidence than verified machine-generated records tied to the deployed artifact.
Automation makes checks repeatable. Kube-bench checks configuration against supported CIS benchmarks; scanners such as Trivy inspect supported artifacts/configuration for known findings. OPA/Gatekeeper or Kyverno can implement admission policy, with capabilities depending on configuration. Falco detects runtime behavior. These tools serve different stages; none alone provides a complete assurance program.
Treat policy as code like application code: version control, peer review, positive and negative tests, gradual rollout, monitored operation and explicit rollback. Detect drift between approved configuration and live state. Give the enforcement tools limited permissions and protect their supply chain too. Track exceptions with a justification, owner, review date and compensating controls; an unbounded bypass quietly becomes permanent policy.
Evidence should identify what was checked, when, against which control version, the result and any remediation. Protect its integrity and access. Periodically verify that alerts route to a person, failed controls are resolved and restored systems actually work. Continuous evidence is more useful than a one-time dashboard with no follow-up.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Check Kubernetes configuration against a recognized baseline | Use an applicable CIS benchmark and compatible checker, then review findings and exceptions. |
| Require a control at every new deployment | Automate admission/CI checks with tested policies and observable enforcement. |
| Prove which artifact met release policy | Keep verified evidence bound to its digest and deployment record. |
| A business requirement temporarily conflicts with a control | Use a documented, owned and time-bounded exception with risk treatment. |
Traps
- Certification of a management system is not a claim that every technical component is invulnerable.
- A scanner may not be able to inspect provider-managed components; record that scope limitation.
- Audit evidence has to be protected from modification by the subjects being audited.
- Framework names are not interchangeable: governance, configuration, threats and supply chain answer different questions.
Active recall
1. Which CSF 2.0 function places cybersecurity responsibility in organizational decision-making?
Govern. It joins Identify, Protect, Detect, Respond and Recover.
2. Does a passed CIS check establish application authorization is correct?
No. A platform configuration benchmark has a defined scope and does not prove all application behavior.
3. Why attach compliance evidence to an image digest?
It identifies the exact artifact assessed and deployed; a mutable tag may later refer to different content.
4. What makes a policy exception safer than a permanent undocumented bypass?
An accountable owner, explicit rationale, limited scope/duration, review date and compensating controls.
5. Which tool class best prevents a prohibited workload from being admitted?
An admission policy/enforcement mechanism. Runtime alerting detects behavior after admission, while a benchmark checker assesses configuration.