Container Security Audit Toolkit for Docker & Kubernetes
They containerised everything. The board wants assurance on compliance, resilience and control effectiveness. This is the complete, risk-based container security audit toolkit including Risk Register with 59 controls across 12 domains, step-by-step test procedures, 176 pre-drafted evidence requests, 7 built-in dashboards, and two board-ready decks. Skip the blank spreadsheet.
The assurance challenge
Your workloads moved to containers. Did your audit coverage move with them?
Containers collapsed the boundary between infrastructure and application. Build, deploy and runtime now happen in minutes, on shared kernels, from images assembled out of third-party layers no one on the audit plan has ever reviewed. The traditional ITGC audit does not reach any of it.
The image supply chain is an unaudited third party
Every production container inherits code from base images, public registries and transitive layers. Without provenance, signing and scanning controls, your organisation is running third-party code it never assessed.
Privileged containers quietly defeat host isolation
A single container running privileged, with a mounted host socket or as root, collapses the isolation the whole architecture depends on. These misconfigurations are trivially common and almost never appear in a standard infrastructure audit.
Secrets live in places auditors never look
Credentials embedded in image layers, environment variables, and unencrypted cluster objects survive every code review. If your audit program has no procedure for secrets in the container lifecycle, the exposure is undocumented by definition.
Generic IT audit programs do not cover this
Standard ITGC programs test change management, access and operations at the server layer. They contain no procedures for admission control, RBAC in the cluster, pod security standards, registry hardening or CI/CD pipeline integrity. The gap is structural, not incidental.
What’s included
59 audit controls across 12 domains with a full Risk Register and a fieldwork-ready Audit Program
The 12 domains follow a container’s lifecycle from the registry to the boardroom i.e. build, ship, run, observe, report. Every control carries a step-by-step test procedure, a framework citation, and a linked evidence request. Ready to deploy on your next engagement.
- Board-approved container and cloud-native security policy
- Defined ownership for platform, image and cluster security
- Container risk assessment refreshed within 12 months
- Skills and capacity assessment for the platform team
- Approved base image catalogue and golden image governance
- Registry access control, authentication and tenant separation
- Image signing, provenance attestation and verification at pull
- Prohibition and detection of unapproved public registries
- Image tag immutability and content-addressable deployment
- Retention, promotion and quarantine of registry artefacts
- Automated image scanning at build and on a recurring schedule
- Severity thresholds that block promotion to production
- Software Bill of Materials generation and retention
- Base image rebuild cadence and drift from upstream patches
- Exception register with expiry dates and compensating controls
- Prohibition of privileged containers and privilege escalation
- Non-root execution and enforced user namespace mapping
- Linux capability dropping and read-only root filesystems
- Seccomp, AppArmor or SELinux profiles applied to workloads
- Resource limits preventing noisy-neighbour and DoS conditions
- Runtime threat detection and anomalous behaviour alerting
- Minimal, purpose-built container host operating system
- CIS benchmark conformance and configuration drift monitoring
- Host patching cadence and kernel currency
- Administrative access, bastion controls and MFA to nodes
- File integrity monitoring on host and container binaries
- Daemon socket exposure, TLS authentication and remote access
- Daemon configuration hardening against CIS Docker benchmark
- Runtime version currency and supported release management
- Daemon audit logging enabled and forwarded off-host
- API server authentication, authorisation and anonymous access
- Kubernetes RBAC least privilege and service account scoping
- Pod Security Standards or admission policy enforcement
- etcd encryption at rest, access control and backup integrity
- Control plane component hardening and audit policy configuration
- Namespace segregation, quotas and multi-tenancy boundaries
- Default-deny network policies between namespaces and workloads
- Ingress and egress control, and prevention of unauthorised egress
- Mutual TLS for east-west service-to-service traffic
- Service exposure review — load balancers and NodePorts
- DNS security and cluster-internal name resolution controls
- External secrets manager integration in place of native objects
- Detection of credentials embedded in image layers and environment
- Secret rotation, expiry and revocation on personnel change
- Encryption of secrets at rest and restricted read access
- Pipeline access control and segregation of build from deploy
- Build agent isolation and protection of pipeline credentials
- Mandatory security gates that cannot be bypassed manually
- Infrastructure-as-code review, approval and version control
- Deployment approval evidence and rollback capability
- Centralised, tamper-resistant collection of container and audit logs
- Log retention aligned to regulatory and forensic requirements
- Container-aware detection use cases and alert tuning
- Incident response runbooks covering container and cluster compromise
- Forensic readiness i.e. image, volume and node evidence preservation
- Persistent volume encryption, access mode and reclaim policy
- Personal data mapping across containerised workloads (DPA 2019)
- Backup, restore testing and recovery objectives for stateful sets
- Data residency, cross-border transfer and deletion assurance
Built-in management dashboards
7 board-ready dashboards
Most audit programs give you a spreadsheet. This toolkit gives you a complete management intelligence system. The Risk Register workbook includes 7 formula-driven dashboards that auto-populate directly from your data — open the file, populate your controls, and your board-ready risk reporting is generated instantly. No additional configuration. No extra software.
What the framework reveals
What organisations typically discover on their first structured container audit
These patterns are drawn from container security audit work conducted using this framework. They are what your audit committee will see the first time the estate is assessed on a documented, repeatable basis.
The investment case
KES 20,000 — versus building it yourself
Any organisation running containers in production needs exactly what is in this toolkit. Here is what producing each component independently would cost — versus purchasing the complete Container Security Audit Toolkit today.
Framework alignment
Defensible against the standards your stakeholders cite
Every test procedure traces to a recognised framework reference — not generic best practice. When your QA reviewer, external auditor or regulator asks for the basis of a conclusion, you point to the specific control and the specific clause it satisfies.
Who this is for
Built for the people who sign the report
Whether you are an internal audit function adding containers to the plan for the first time, an external firm standardising a methodology, or a CISO self-assessing before the auditors arrive, this toolkit gives you a structured, defensible audit approach — ready to tailor and deploy. It costs less than half a day of specialist consulting.
What you receive
Everything you need ready to use on your next container security engagement
-
Excel workbook 1IT Risk Register — 59 controls, 12 domains, 17 risk groupsEvery control documented with inherent scoring, control effectiveness, residual scoring, risk response and board-approved appetite thresholds. Includes the 7 formula-driven dashboards, which populate automatically from the register data.
-
Excel workbook 2Overall Audit Program — step-by-step test proceduresA fieldwork-ready procedure for all 59 controls, each mapped to NIST SP 800-190, ISO/IEC 27001:2022, CIS Benchmarks and data protection requirements. Planning, fieldwork, findings and reporting columns in a single sheet.
-
Excel workbook 3Evidence Request Log — 176 pre-drafted itemsYour PBC list, written before kickoff. Each evidence item is linked to the control it supports, with requested date, deadline and status, plus domain-level progress tracking as evidence lands.
-
Excel workbook 4Findings Log — 14 fully drafted example findingsCondition, criteria, cause, effect, recommendation, management action plan, owner, due date and overdue tracking. Fourteen worked examples show your team exactly what a defensible container finding looks like.
-
PowerPoint deck 1Board PresentationExecutive KPIs, inherent versus residual risk position, risk reduction analysis, appetite breach status, critical-finding deep-dives, and proposed board resolutions. Designed for a governance audience, not a technical one.
-
PowerPoint deck 2IT Management ReportThe operational layer — domain-by-domain results, control effectiveness detail, the full action register with owners and due dates, remediation sequencing and the 90-day critical path.
-
Framework coverageFull mapping — NIST SP 800-190, ISO 27001:2022, CIS, DPA 2019, NIST CSFCitation-ready for QA review, external audit reliance and regulator questions. Every control maps to specific framework clauses, so a conclusion can always be traced to its authority.
-
Ready to customise and deployAll fields are unlocked. Rebrand, rescope, adjust risk ratings, reassign ownership and adapt to your environment. The Index sheet includes usage instructions and methodology notes. Costs less than half a day of specialist IT audit consulting.
Complete toolkit — all workbooks, dashboards & decks included
- IT Risk Register (59 controls, 12 domains, 17 risk groups)
- Overall Audit Program (step-by-step procedures)
- Evidence Request Log (176 pre-drafted items)
- Findings Log (14 worked findings + MAP tracking)
- 7 built-in management dashboards
- Board Presentation (PowerPoint)
- IT Management Report (PowerPoint)
- Risk appetite thresholds on residual scoring
- NIST SP 800-190, ISO 27001:2022, CIS & DPA 2019 mapping
- Email support from Sentinel’s audit team
🔒 Secure payment | Instant delivery by email
Multi-entity & firm licensing available — contact us
Add-on services
Optional services to deploy the toolkit faster
The KES 20,000 toolkit is complete and ready to use on its own. For organisations that want hands-on support, Sentinel’s certified IT audit team offers these optional add-on services — priced separately depending on the size of your estate and the agreed scope of work.
We configure the Risk Register and Audit Program to your actual environment i.e. orchestrator, registry, CI/CD platform and cluster topology populating ownership, scope and applicable domains so your team can begin testing immediately.
A remote or on-site working session where our team helps your internal audit and platform functions deploy the toolkit, calibrate risk ratings and appetite thresholds, and produce your first board-ready container risk report.
We populate a Management Action Plan tracker from your completed fieldwork, each finding with a named owner, agreed due date and live status — giving your audit committee a ready remediation-tracking dashboard.
A structured review mapping your current container and cluster configuration against NIST SP 800-190 and CIS benchmark guidance, pinpointing exactly which controls need designing, implementing or evidencing.
Sentinel independently tests and validates your populated register and controls delivering the board- and regulator-ready independent assurance that internal documentation alone cannot provide. Scope and fee depend on estate size.
For audit firms, consultancies and groups deploying the toolkit across multiple clients, subsidiaries or clusters — discounted multi-engagement licensing tailored to the number of entities.
To add any of these services, email sales@sentinelassurancepartners.co.ke or call +254 769 546 128. Fees depend on estate size and scope of work.
Risk Control Matrix & Risk Register
A complete Risk Register — not just an audit checklist
Most container security material tells you what to configure. This toolkit goes further, it includes a Risk Control Matrix (RCM) / Risk Register with 59 individual controls mapped to risks, framework references, control types, ownership and testing frequency. This is the living document your board expects to be maintained and your auditors expect to test against.
The Risk Register and Overall Audit Program are linked by Control ID, every test procedure traces directly back to a documented risk and control in the register, and every finding traces back to the procedure that produced it. That chain is what makes a conclusion defensible under review.
Controls classified as Critical address risks that — if the control fails — are likely to result in container escape, control plane compromise, or irreversible loss of personal data. Every Critical control has a named owner, a documented framework reference, and a specific test procedure.
High-rated controls cover significant risks with elevated probability of exploitation — unsigned images, permissive RBAC, absent network policy. Each includes inherent assessment, control effectiveness, residual rating, risk response and framework mapping.
Each risk is documented at three levels: Enterprise Risk (e.g. Technology Risk), Intermediary Risk (e.g. Information Security Risk), and Library Risk (e.g. Container Escape Risk). This hierarchy lets container risk roll up cleanly into an existing enterprise risk taxonomy.
Risk Register columns — what’s captured for every control
Overall Audit Program columns — what the auditor completes in the field
Why Sentinel
Written by certified IT auditors with 15+ years of financial sector experience
Sentinel Assurance Partners Ltd is Kenya’s dedicated IT audit, cybersecurity assurance and technology risk advisory firm. Our team brings global experience across banking, insurance, gaming and financial services, combined with deep understanding of the East African regulatory environment.
This toolkit was built by practitioners who have audited containerised production environments and know the difference between a configuration checklist and an audit conclusion that survives QA review.
We take no vendor, reseller or implementation revenue. Our independence is structural, not a policy statement — which is precisely why our work is relied on by boards and regulators.
Our credentials
- Certified Information Systems Auditor (CISA) — ISACA
- Certified Information Systems Security Professional (CISSP)
- Certified in Risk and Information Systems Control (CRISC)
- Certified Cloud Security Professional (CCSP)
- Certified Data Privacy Solutions Engineer (CDPSE)
- AI Governance Professional (AIGP) — IAPP
Read more from Sentinel Insights
Practitioner analysis on IT audit, cloud and cybersecurity assurance for regulated institutions across East Africa.
Read the blog →Frequently asked questions
Common questions from IT auditors and security teams
Your next container audit starts at control 1 of 59 — not at a blank sheet.
Get the complete Container Security Audit Toolkit — Risk Register with 59 controls across 12 domains, step-by-step audit program, 176 evidence requests, 14 worked findings, 7 built-in dashboards and 2 board-ready decks. Everything ready before your kickoff meeting. Instant delivery. KES 20,000.