Level Up Kubernetes Security with Our New Rule Pack Built on the CIS Benchmark

Brandon Pfeiffer
Jun 3rd, 2025

We’re rolling out a new Kubernetes Rule Pack aligned with the CIS Kubernetes Benchmark 1.11.1 to help you enforce security best practices across your clusters without slowing down development. Whether you're managing RBAC policies or locking down pod configurations, this rule pack is built to simplify what used to be a  manual and tedious process.

What’s in the rule pack?

The rule pack focuses on two high-impact areas from the CIS Kubernetes Benchmark v1.11.1

🔐 RBAC & Service Account Security (5.1.1 – 5.1.13)

  • Detect overuse of cluster-admin and system:masters
  • Flag wildcard permissions and unrestricted role bindings
  • Ensure default service accounts are not misused
  • Limit impersonation, escalation, and access to sensitive resources
  • Why it matters: These rules enforce least privilege access and help eliminate toxic role combinations that can lead to privilege escalation or unauthorized changes.

🛡️ Pod Security Controls (5.2.1 – 5.2.13)

  • Block privileged containers and host namespace sharing
  • Restrict dangerous capabilities like NET_RAW
  • Prevent use of HostPath volumes and HostPorts
  • Enforce non-root, seccomp, and other baseline security settings
  • Why it matters: These rules prevent container breakout risks, harden workloads by default, and align with Pod Security Admission and OPA/Gatekeeper policies.

📌 What You Need to Do

  1. Review the rule pack in our GitHub repo
  2. Test against your dev or staging clusters
  3. Roll out enforcement incrementally by namespace or environment.

This is the first phase of our rollout: we’re starting with 26 of the 131 CIS Benchmark controls, focused on the areas that deliver the highest risk reduction and fastest wins. Over the next few weeks, we’ll continue expanding coverage across the rest of the benchmark.

Other articles

The Top CAASM Tools in 2026

Here's what actually matters when you evaluate a CAASM platform, plus how the top vendors compare in 2026.

John Le
Sep 3rd, 2026
  • CAASM
A design representing Continuous Controls Monitoring

A failed control is a security event, not a compliance footnote. See how Continuous Controls Monitoring (CCM) treats every control test as a security detection.

John Le
Sep 1st, 2026
  • CCM
  • Compliance

JupiterOne's MCP server is now listed in Anthropic's MCP directory, making it easier to bring your security graph into Claude and ask questions in plain English.

John Le
Aug 10th, 2026

Tools are silent.
Risks aren't.

See your full security program as one connected picture in a 30-minute demo tailored to your environment.