Skip to main content
All answers

How do I run the CIS Kubernetes Benchmark?

Run the CIS Kubernetes Benchmark by assessing both the control plane (API server, etcd, controller manager, and scheduler configuration) and the worker nodes (kubelet settings and node configuration files) against the benchmark's recommendations. kube-bench is a widely used open-source tool for point-in-time checks. CISGuard assesses Kubernetes agentlessly through API scanning with continuous monitoring and drift detection. Managed distributions have dedicated benchmark variants, including AKS and EKS, because the provider operates the control plane.

The longer answer.

The control-plane and node split matters for tooling: control-plane checks read API server, etcd, and controller flags and files, while node checks verify kubelet configuration and file permissions on every worker. On managed services such as AKS and EKS the provider controls the control plane, which is why CIS publishes distribution-specific benchmark variants that scope the checks to what the customer can actually configure.

Point-in-time runs answer "is this cluster compliant today?" but Kubernetes environments change constantly as workloads deploy and nodes rotate. Continuous agentless scanning keeps every cluster verified between audits, flags drift as it happens, and maps results to NIST 800-53, ISO 27001, and SOC 2, which is the operating model CISGuard provides.

More questions on Implementation?

Our compliance engineers can show you exactly how CISGuard handles Implementation in a briefing scoped to your environment.