ControlPlane reposted this
Here's my slides and a short summary from my talk Australian Information Security Association (AISA) #CyberCon Melbourne 2025. Essential 8 controls must be applied with cloud-native strategies and a DevOps culture where security is everyone's responsibility from the outset. Traditional security approaches are ineffective due to the ephemeral and distributed nature of Kubernetes containers. E8s Application control | Patch applications |User application hardening: - Security should be integrated into the early stages of the development pipeline (build and test phases) rather than being an afterthought. - Vulnerability Management involves controlling base images, static and dependency analysis in CI/CD, hermetic builds, rootless container execution, and configuration scanning. E8s Restrict administrative privileges | Multi-factor authentication (MFA): - Emphasize the principle of least privilege using role-based access control (RBAC) to limit lateral movement by attackers. E8s Regular Backups: - Three critical components to back up are etcs, resources, persistent volumes Missed it? Reach out to schedule me to come and deliver it as a lunch and learn at your office!