Container Security Audit Toolkit — Docker & Kubernetes | Sentinel Assurance Partners
Container Security Toolkit — Risk Register · Audit Program · Dashboards · Board Reports

Container Security Audit Toolkit for Docker & Kubernetes

They containerised everything. The board wants assurance on compliance, resilience and control effectiveness. This is the complete, risk-based container security audit toolkit including Risk Register with 59 controls across 12 domains, step-by-step test procedures, 176 pre-drafted evidence requests, 7 built-in dashboards, and two board-ready decks. Skip the blank spreadsheet.

59 Controls in Register
12 Security domains
7 Built-in dashboards
Container workloads are moving into production faster than audit coverage — and regulators now expect assurance over the whole stack.  Get audit-ready today →
NIST SP 800-190
CIS Docker & Kubernetes Benchmarks
ISO/IEC 27001:2022 Annex A
Kenya Data Protection Act 2019
NIST CSF Aligned

Your workloads moved to containers. Did your audit coverage move with them?

Containers collapsed the boundary between infrastructure and application. Build, deploy and runtime now happen in minutes, on shared kernels, from images assembled out of third-party layers no one on the audit plan has ever reviewed. The traditional ITGC audit does not reach any of it.

The image supply chain is an unaudited third party

Every production container inherits code from base images, public registries and transitive layers. Without provenance, signing and scanning controls, your organisation is running third-party code it never assessed.

Privileged containers quietly defeat host isolation

A single container running privileged, with a mounted host socket or as root, collapses the isolation the whole architecture depends on. These misconfigurations are trivially common and almost never appear in a standard infrastructure audit.

Secrets live in places auditors never look

Credentials embedded in image layers, environment variables, and unencrypted cluster objects survive every code review. If your audit program has no procedure for secrets in the container lifecycle, the exposure is undocumented by definition.

Generic IT audit programs do not cover this

Standard ITGC programs test change management, access and operations at the server layer. They contain no procedures for admission control, RBAC in the cluster, pod security standards, registry hardening or CI/CD pipeline integrity. The gap is structural, not incidental.


59 audit controls across 12 domains with a full Risk Register and a fieldwork-ready Audit Program

The 12 domains follow a container’s lifecycle from the registry to the boardroom i.e. build, ship, run, observe, report. Every control carries a step-by-step test procedure, a framework citation, and a linked evidence request. Ready to deploy on your next engagement.

GOV / Domain 01
Container Governance & Strategy
4 audit procedures
  • Board-approved container and cloud-native security policy
  • Defined ownership for platform, image and cluster security
  • Container risk assessment refreshed within 12 months
  • Skills and capacity assessment for the platform team
📦
IMG / Domain 02
Image Supply Chain & Registry
6 audit procedures
  • Approved base image catalogue and golden image governance
  • Registry access control, authentication and tenant separation
  • Image signing, provenance attestation and verification at pull
  • Prohibition and detection of unapproved public registries
  • Image tag immutability and content-addressable deployment
  • Retention, promotion and quarantine of registry artefacts
🩹
VUL / Domain 03
Vulnerability & Patch Management
5 audit procedures
  • Automated image scanning at build and on a recurring schedule
  • Severity thresholds that block promotion to production
  • Software Bill of Materials generation and retention
  • Base image rebuild cadence and drift from upstream patches
  • Exception register with expiry dates and compensating controls
🔐
RUN / Domain 04
Runtime Privileges & Isolation
6 audit procedures
  • Prohibition of privileged containers and privilege escalation
  • Non-root execution and enforced user namespace mapping
  • Linux capability dropping and read-only root filesystems
  • Seccomp, AppArmor or SELinux profiles applied to workloads
  • Resource limits preventing noisy-neighbour and DoS conditions
  • Runtime threat detection and anomalous behaviour alerting
🖥
HST / Domain 05
Host & Node Hardening
5 audit procedures
  • Minimal, purpose-built container host operating system
  • CIS benchmark conformance and configuration drift monitoring
  • Host patching cadence and kernel currency
  • Administrative access, bastion controls and MFA to nodes
  • File integrity monitoring on host and container binaries
DMN / Domain 06
Container Daemon & Engine
4 audit procedures
  • Daemon socket exposure, TLS authentication and remote access
  • Daemon configuration hardening against CIS Docker benchmark
  • Runtime version currency and supported release management
  • Daemon audit logging enabled and forwarded off-host
ORC / Domain 07
Orchestration & Control Plane
6 audit procedures
  • API server authentication, authorisation and anonymous access
  • Kubernetes RBAC least privilege and service account scoping
  • Pod Security Standards or admission policy enforcement
  • etcd encryption at rest, access control and backup integrity
  • Control plane component hardening and audit policy configuration
  • Namespace segregation, quotas and multi-tenancy boundaries
🌐
NET / Domain 08
Network Segmentation & Service Mesh
5 audit procedures
  • Default-deny network policies between namespaces and workloads
  • Ingress and egress control, and prevention of unauthorised egress
  • Mutual TLS for east-west service-to-service traffic
  • Service exposure review — load balancers and NodePorts
  • DNS security and cluster-internal name resolution controls
🔑
SEC / Domain 09
Secrets & Key Management
4 audit procedures
  • External secrets manager integration in place of native objects
  • Detection of credentials embedded in image layers and environment
  • Secret rotation, expiry and revocation on personnel change
  • Encryption of secrets at rest and restricted read access
🔄
CID / Domain 10
CI/CD Pipeline & Deployment
5 audit procedures
  • Pipeline access control and segregation of build from deploy
  • Build agent isolation and protection of pipeline credentials
  • Mandatory security gates that cannot be bypassed manually
  • Infrastructure-as-code review, approval and version control
  • Deployment approval evidence and rollback capability
📡
LOG / Domain 11
Logging, Monitoring & Incident Response
5 audit procedures
  • Centralised, tamper-resistant collection of container and audit logs
  • Log retention aligned to regulatory and forensic requirements
  • Container-aware detection use cases and alert tuning
  • Incident response runbooks covering container and cluster compromise
  • Forensic readiness i.e. image, volume and node evidence preservation
🗄
DAT / Domain 12
Data Protection & Persistent Storage
4 audit procedures
  • Persistent volume encryption, access mode and reclaim policy
  • Personal data mapping across containerised workloads (DPA 2019)
  • Backup, restore testing and recovery objectives for stateful sets
  • Data residency, cross-border transfer and deletion assurance
Build — image, vulnerability, pipeline Ship — registry, signing, admission Run — privileges, host, daemon, orchestration Observe — network, secrets, logging Report — dashboards, board decks
Methodology note: risk appetite breach status is measured against the residual risk score, never the inherent score. Your dashboards therefore report what the board actually needs to act on after controls are taken into account — which is the same basis a regulator or external reviewer will apply.

7 board-ready dashboards

Most audit programs give you a spreadsheet. This toolkit gives you a complete management intelligence system. The Risk Register workbook includes 7 formula-driven dashboards that auto-populate directly from your data — open the file, populate your controls, and your board-ready risk reporting is generated instantly. No additional configuration. No extra software.

📊
Inherent Risk Dashboard
All 59 controls broken down by inherent risk rating across the 12 domains — the exposure your container estate carries before any mitigating control is applied. The pre-control map the board rarely gets to see.
🛡
Residual Risk Dashboard
Post-control risk profile showing exactly what remains after your controls have been designed, implemented and tested. This is the view external reviewers and regulators ask for first.
📈
Risk Reduction Analysis
Quantifies the reduction your controls actually deliver — inherent versus residual, by domain. The evidence your board needs that platform security investment is reducing risk rather than generating documentation.
🔴
Risk Response Dashboard
Accept / Reduce / Transfer / Avoid breakdown across all 59 controls by domain — demonstrating structured, risk-based decision-making rather than ad-hoc remediation.
🧩
Control Architecture Dashboard
Your full control set at a glance — by control type (Preventive / Detective / Corrective / Directive) and nature (Manual / Semi-Automated / Automated) across all 12 domains. Exposes over-reliance on manual controls.
Risk Appetite Dashboard
Maps every control’s residual risk score against board-approved appetite thresholds — automatically flagging AT LIMIT and BREACHED positions that require escalation.
🗺
Framework Coverage Dashboard
Coverage map across NIST SP 800-190, ISO/IEC 27001:2022 Annex A, CIS Benchmarks and data protection requirements — showing which framework clauses each control satisfies and where gaps remain.

What organisations typically discover on their first structured container audit

These patterns are drawn from container security audit work conducted using this framework. They are what your audit committee will see the first time the estate is assessed on a documented, repeatable basis.

59
Controls, and most present at Critical or High inherent risk
Shared-kernel architecture, inherited third-party image layers and rapid deployment cadence create a genuinely high-exposure environment before any control is applied. Without a documented register, none of this exposure is visible to the board.
80%+
Achievable risk reduction once controls are documented and tested
Container risk responds well to structured control i.e. admission policy, signing, network policy and privilege restriction move the needle sharply. That reduction is exactly what the Risk Reduction Analysis dashboard evidences for your board.
14
Worked example findings included in the Findings Log
Fourteen fully drafted findings with condition, criteria, cause, effect, recommendation and management action plan, covering the issues that recur most often across container estates. You are not drafting from a blank page.
176
Pre-drafted evidence requests, ready on day one
Your PBC list is written before kickoff. Each item is linked to the control it supports, with domain-level progress tracking as evidence lands ,so you can see exactly which domains are blocked and which are ready for testing.
0
Container procedures in a standard ITGC audit program
Conventional ITGC programs contain no procedures for admission control, cluster RBAC, pod security standards, image provenance or registry hardening. If your plan relies on one, container risk is unaudited by design not by oversight.

KES 20,000 — versus building it yourself

Any organisation running containers in production needs exactly what is in this toolkit. Here is what producing each component independently would cost — versus purchasing the complete Container Security Audit Toolkit today.

Building it in-house
Risk register from scratch — 2–3 weeks of senior IT auditor research
59 step-by-step test procedures — drafting plus technical validation
NIST SP 800-190 / ISO 27001 / CIS mapping — specialist research hours
7 formula-driven dashboards — Excel development and configuration
176 evidence requests — manual extraction from the audit program
Findings log with worked examples and MAP tracking
Risk appetite framework calibrated to residual scoring
Two board and IT management reporting decks, designed
KES 180,000+
Estimated 5–7 weeks of qualified IT auditor time, plus ongoing maintenance
VS
Container Security Audit Toolkit
Risk register — 59 controls, 12 domains, 17 risk groups, fully populated
Audit program — step-by-step procedures for every control, fieldwork-ready
Evidence request log — 176 items, linked to controls, progress-tracked
Findings log — 14 worked findings with MAP and overdue tracking
7 management dashboards — auto-populate from your register data
2 board-ready decks (Board Presentation & IT Management Report)
NIST SP 800-190 / ISO 27001:2022 / CIS / DPA 2019 — all mapped
Risk appetite thresholds measured on residual score
KES 20,000
Complete toolkit · Instant delivery by email · Single-organisation licence

Defensible against the standards your stakeholders cite

Every test procedure traces to a recognised framework reference — not generic best practice. When your QA reviewer, external auditor or regulator asks for the basis of a conclusion, you point to the specific control and the specific clause it satisfies.

Application Container Security Guide — the reference standard for container risk. Image, registry, orchestrator, container and host OS countermeasures mapped throughout.
ISO/IEC 27001:2022 Annex A control mapping for organisations with a certified or aspiring ISMS — supports certification evidence directly.
CIS Docker and Kubernetes Benchmarks — hardening checks aligned to benchmark guidance for daemon, host, control plane and worker node configuration.
Kenya Data Protection Act 2019 & Regulations — controls covering personal data in containerised workloads, persistent storage, residency and deletion assurance.
Cybersecurity Framework functions — Identify, Protect, Detect, Respond and Recover mapped across the container lifecycle for enterprise reporting alignment.

Built for the people who sign the report

Whether you are an internal audit function adding containers to the plan for the first time, an external firm standardising a methodology, or a CISO self-assessing before the auditors arrive, this toolkit gives you a structured, defensible audit approach — ready to tailor and deploy. It costs less than half a day of specialist consulting.

🏢
Internal IT Audit Teams
First container audit on the plan? Start from a complete, framework-mapped program rather than a blank sheet and demonstrate governance maturity to your audit committee.
📋
External IT Audit Firms
Deploy a consistent methodology across every container engagement. Procedures, evidence lists and workpaper references are built in, so junior staff can execute to a defined standard.
🛡
CISOs & Security Architects
Self-assess before the auditors arrive. Identify gaps on your own timeline and present the board a documented, defensible risk position rather than a reactive one.
📔
GRC & Technology Risk Teams
Risk register, appetite thresholds and KRI-style dashboards ready to adapt to your enterprise taxonomy with residual-based appetite measurement built in from the start.
👥
Boards & Audit Committees
Receive container risk in the same language as every other risk on the register i.e. rated, owned, tracked against appetite, and reported in a deck built for the boardroom.

Everything you need ready to use on your next container security engagement

  • 📄
    Excel workbook 1
    IT Risk Register — 59 controls, 12 domains, 17 risk groups
    Every control documented with inherent scoring, control effectiveness, residual scoring, risk response and board-approved appetite thresholds. Includes the 7 formula-driven dashboards, which populate automatically from the register data.
  • 📑
    Excel workbook 2
    Overall Audit Program — step-by-step test procedures
    A fieldwork-ready procedure for all 59 controls, each mapped to NIST SP 800-190, ISO/IEC 27001:2022, CIS Benchmarks and data protection requirements. Planning, fieldwork, findings and reporting columns in a single sheet.
  • 📬
    Excel workbook 3
    Evidence Request Log — 176 pre-drafted items
    Your PBC list, written before kickoff. Each evidence item is linked to the control it supports, with requested date, deadline and status, plus domain-level progress tracking as evidence lands.
  • 🔎
    Excel workbook 4
    Findings Log — 14 fully drafted example findings
    Condition, criteria, cause, effect, recommendation, management action plan, owner, due date and overdue tracking. Fourteen worked examples show your team exactly what a defensible container finding looks like.
  • 📊
    PowerPoint deck 1
    Board Presentation
    Executive KPIs, inherent versus residual risk position, risk reduction analysis, appetite breach status, critical-finding deep-dives, and proposed board resolutions. Designed for a governance audience, not a technical one.
  • 🗂
    PowerPoint deck 2
    IT Management Report
    The operational layer — domain-by-domain results, control effectiveness detail, the full action register with owners and due dates, remediation sequencing and the 90-day critical path.
  • 🔒
    Framework coverage
    Full mapping — NIST SP 800-190, ISO 27001:2022, CIS, DPA 2019, NIST CSF
    Citation-ready for QA review, external audit reliance and regulator questions. Every control maps to specific framework clauses, so a conclusion can always be traced to its authority.
  • 🎉
    Ready to customise and deploy
    All fields are unlocked. Rebrand, rescope, adjust risk ratings, reassign ownership and adapt to your environment. The Index sheet includes usage instructions and methodology notes. Costs less than half a day of specialist IT audit consulting.
Infrastructure Audit Toolkit
Container Security Audit Toolkit — Docker & Kubernetes
KES 20,000

Complete toolkit — all workbooks, dashboards & decks included

  • IT Risk Register (59 controls, 12 domains, 17 risk groups)
  • Overall Audit Program (step-by-step procedures)
  • Evidence Request Log (176 pre-drafted items)
  • Findings Log (14 worked findings + MAP tracking)
  • 7 built-in management dashboards
  • Board Presentation (PowerPoint)
  • IT Management Report (PowerPoint)
  • Risk appetite thresholds on residual scoring
  • NIST SP 800-190, ISO 27001:2022, CIS & DPA 2019 mapping
  • Email support from Sentinel’s audit team
Purchase & Download Now

🔒 Secure payment  |  Instant delivery by email

Multi-entity & firm licensing available — contact us

Optional services to deploy the toolkit faster

The KES 20,000 toolkit is complete and ready to use on its own. For organisations that want hands-on support, Sentinel’s certified IT audit team offers these optional add-on services — priced separately depending on the size of your estate and the agreed scope of work.

Add-on service
Done-for-you Customisation & Configuration
Custom pricing

We configure the Risk Register and Audit Program to your actual environment i.e. orchestrator, registry, CI/CD platform and cluster topology populating ownership, scope and applicable domains so your team can begin testing immediately.

🎓
Add-on service
Half-Day Facilitated Deployment Workshop
Custom pricing

A remote or on-site working session where our team helps your internal audit and platform functions deploy the toolkit, calibrate risk ratings and appetite thresholds, and produce your first board-ready container risk report.

Add-on service
Management Action Plan Tracker Build
Custom pricing

We populate a Management Action Plan tracker from your completed fieldwork, each finding with a named owner, agreed due date and live status — giving your audit committee a ready remediation-tracking dashboard.

🛡
Add-on service
Container Security Gap Review
Custom pricing

A structured review mapping your current container and cluster configuration against NIST SP 800-190 and CIS benchmark guidance, pinpointing exactly which controls need designing, implementing or evidencing.

🔍
Add-on service
Independent External Examination
Custom pricing

Sentinel independently tests and validates your populated register and controls delivering the board- and regulator-ready independent assurance that internal documentation alone cannot provide. Scope and fee depend on estate size.

🏢
Add-on service
Multi-Entity & Firm Licensing
Custom pricing

For audit firms, consultancies and groups deploying the toolkit across multiple clients, subsidiaries or clusters — discounted multi-engagement licensing tailored to the number of entities.

To add any of these services, email sales@sentinelassurancepartners.co.ke or call +254 769 546 128. Fees depend on estate size and scope of work.

A complete Risk Register — not just an audit checklist

Most container security material tells you what to configure. This toolkit goes further, it includes a Risk Control Matrix (RCM) / Risk Register with 59 individual controls mapped to risks, framework references, control types, ownership and testing frequency. This is the living document your board expects to be maintained and your auditors expect to test against.

The Risk Register and Overall Audit Program are linked by Control ID, every test procedure traces directly back to a documented risk and control in the register, and every finding traces back to the procedure that produced it. That chain is what makes a conclusion defensible under review.

Critical
Critical-rated controls documented

Controls classified as Critical address risks that — if the control fails — are likely to result in container escape, control plane compromise, or irreversible loss of personal data. Every Critical control has a named owner, a documented framework reference, and a specific test procedure.

High
High-rated controls documented

High-rated controls cover significant risks with elevated probability of exploitation — unsigned images, permissive RBAC, absent network policy. Each includes inherent assessment, control effectiveness, residual rating, risk response and framework mapping.

Three Risk Levels
Enterprise → Intermediary → Library risk hierarchy

Each risk is documented at three levels: Enterprise Risk (e.g. Technology Risk), Intermediary Risk (e.g. Information Security Risk), and Library Risk (e.g. Container Escape Risk). This hierarchy lets container risk roll up cleanly into an existing enterprise risk taxonomy.

Risk & Control Identity Risk Classification Control Details Assessment & Response
Control ID (e.g. ORC/07.3)
Enterprise Risk Level 1
Individual Control Statement
Likelihood
Area Reference
Intermediary Risk Level 2
Control Type (Preventive / Detective / Corrective / Directive)
Impact
Risk Entry Date
Library Risk Level 3
Control Nature (Automated / Semi-Automated / Manual)
Inherent Risk Rating
Security Domain
Risk Description / Statement
Testing Frequency
Control Effectiveness
Process / Audit Area
Risk Owner
Control Owner
Residual Risk Rating
Framework Reference (NIST / ISO / CIS)
Next Review Date
Status
Appetite Status (measured on residual)
Planning Fieldwork Findings Reporting
Domain & Process Name
Test Procedure (step-by-step)
Conclusion
Recommendation
W/P Reference Number
Evidence Required
Finding Description
Management Action Plan
Sub-Control ID
Framework Reference
Finding Owner
Management Action Owner
Risk Statement
Sample Size
Residual Risk Rating
Remediation Due Date
Inherent Risk Rating
Responsible IT Auditor
Audit Phase
Status
Control Objective
W/P Completion Date
Control Type & Nature
Testing Frequency
59 Total controls documented
12 Security domains covered
17 Risk groups mapped
176 Evidence requests drafted
7 Built-in dashboards

Written by certified IT auditors with 15+ years of financial sector experience

Sentinel Assurance Partners Ltd is Kenya’s dedicated IT audit, cybersecurity assurance and technology risk advisory firm. Our team brings global experience across banking, insurance, gaming and financial services, combined with deep understanding of the East African regulatory environment.

This toolkit was built by practitioners who have audited containerised production environments and know the difference between a configuration checklist and an audit conclusion that survives QA review.

We take no vendor, reseller or implementation revenue. Our independence is structural, not a policy statement — which is precisely why our work is relied on by boards and regulators.

CISAIT Audit
CISSPSecurity
CRISCRisk
CCSPCloud
CDPSEData Privacy
15+ yrsExperience

Our credentials

  • Certified Information Systems Auditor (CISA) — ISACA
  • Certified Information Systems Security Professional (CISSP)
  • Certified in Risk and Information Systems Control (CRISC)
  • Certified Cloud Security Professional (CCSP)
  • Certified Data Privacy Solutions Engineer (CDPSE)
  • AI Governance Professional (AIGP) — IAPP

Read more from Sentinel Insights

Practitioner analysis on IT audit, cloud and cybersecurity assurance for regulated institutions across East Africa.

Read the blog →

Common questions from IT auditors and security teams

Does it cover Kubernetes as well as Docker?
Yes, The 12 domains span the full container stack i.e. image supply chain, vulnerability management, runtime privileges, host and daemon hardening, orchestration and control plane, network policy and service mesh, secrets, CI/CD, logging and data protection. Kubernetes-specific areas including RBAC, Pod Security Standards, admission control and etcd are covered in their own domain.
Is everything editable?
Yes. All four workbooks are standard Excel files with formula-driven dashboards, and both reporting decks are standard PowerPoint. Nothing is locked or password protected. Rebrand, rescope and adapt them to your engagement freely including under your own firm’s branding.
Do I need deep container engineering experience to use it?
No. Each of the 59 controls comes with a step-by-step test procedure, and the 176 pre-drafted evidence requests tell you exactly what to ask the platform team for. The 14 worked example findings show what a well-written container finding looks like. A competent IT auditor can execute the program without prior Kubernetes engineering background.
How is risk appetite handled?
The register scores every risk on both an inherent and residual basis, with risk appetite thresholds built in. Risk Appetite breach status is always assessed against the residual score and the dashboards visualise breaches and risk reduction automatically. This is deliberate: measuring appetite against inherent risk would flag every control as breached and render the framework useless to a board.
Can it be used by an internal audit team or only external auditors?
It is designed for both. Internal audit teams use it to add container coverage to the annual plan and demonstrate governance maturity. External firms use it as a deployment-ready fieldwork program across multiple clients. Security teams also use it for self-assessment ahead of an audit. The risk rating framework and sign-off structure suit all three.
What formats are included and how is it delivered?
Four Microsoft Excel workbooks (.xlsx) and two PowerPoint decks (.pptx), delivered by email immediately after payment. No specialist software is required beyond Microsoft Office. Payment is by M-Pesa or card.
Is multi-entity or firm-wide licensing available?
Yes. If you are an audit firm or consultancy planning to use this toolkit across multiple clients, or a group requiring deployment across several subsidiaries or clusters, contact sales@sentinelassurancepartners.co.ke to discuss firm licensing.
How does this relate to a cloud security audit?
It is complementary but distinct. A cloud security audit covers the account, identity and service configuration layer. This toolkit covers the container layer that runs on top of it — images, registries, orchestrators, runtime and the build pipeline. Organisations running containers on cloud infrastructure typically need both, and the control IDs are structured so the two can be run in a single engagement without duplication.

Your next container audit starts at control 1 of 59 — not at a blank sheet.

Get the complete Container Security Audit Toolkit — Risk Register with 59 controls across 12 domains, step-by-step audit program, 176 evidence requests, 14 worked findings, 7 built-in dashboards and 2 board-ready decks. Everything ready before your kickoff meeting. Instant delivery. KES 20,000.