Container Hardening Against CIS Benchmarks: What Automation Can and Cannot Do
The CIS Docker Benchmark is 200 pages. The CIS Kubernetes Benchmark is longer. Most organizations that commit to implementing them discover the same problem: many of the controls are clear in specification but expensive in execution, and the tools that automate compliance checking do not automate compliance remediation. Understanding which controls automation handles well — … Read more