Announcing the CIS Benchmark for Amazon EKS
Share
Services
The new CIS Benchmark for Amazon EKS helps you accurately assess the secure configuration of nodes running as part of your Amazon EKS clusters.
Security is a critical consideration for configuring and maintaining Kubernetes clusters and applications. The [Center for Internete Security (CIS) Kubernetes Benchmark](https://www.cisecurity.org/benchmark/kubernetes/) provides good practice guidance on security configurations for self-managed Kubernetes clusters, but did not accurately help evaluate the security configuration status for the AWS-managed Kubernetes clusters run by Amazon EKS. Not all of the recommendations from the CIS Kubernetes Benchmark were applicable to EKS clusters as customers are not responsible for configuring or managing the control plane.
Now, the CIS Amazon EKS Benchmark provides accurate guidance for node security configurations for EKS. The benchmark is applicable to EC2 nodes (both managed and self-managed) where you are responsible for security configurations of Kubernetes components. The benchmark provides a standard, community-approved way to ensure that you have configured your Kubernetes cluster and nodes securely when using Amazon EKS.
The CIS Amazon EKS Benchmark consists of four sections; control plane logging configuration, node security configurations, policies, and managed services. The benchmark supports the Kubernetes versions currently available from Amazon EKS (v1.15 - v1.17) and can be run using [kube-bench](https://github.com/aquasecurity/kube-bench), a standard open source tool for checking configuration using the CIS benchmark on Kubernetes clusters.
To learn more, read our [blog](https://aws.amazon.com/blogs/containers/introducing-cis-amazon-eks-benchmark/) or see the benchmark by navigating to “Access all benchmarks” on the [CIS website](https://www.cisecurity.org/cis-benchmarks).
What else is happening at Amazon Web Services?
Amazon AppStream 2.0 users can now save their user preferences between streaming sessions
December 13th, 2024
Services
Share
AWS Elemental MediaConnect Gateway now supports source-specific multicast
December 13th, 2024
Services
Share
Amazon EC2 instances support bandwidth configurations for VPC and EBS
December 13th, 2024
Services
Share
AWS announces new AWS Direct Connect location in Osaka, Japan
December 13th, 2024
Services
Share
Amazon DynamoDB announces support for FIPS 140-3 interface VPC and Streams endpoints
December 13th, 2024
Services
Share