KubeCon + CloudNativeCon Europe

Project Lightning Talk: A Maintainer’s Tour Of Tag Security And Compliance - Marina Moore

5:26 · 23 Mar 2026 – 26 Mar 2026 · YouTube

About this talk

This talk covers TAG Security and Compliance, which is focused on building secure cloud native systems. The speaker explains how TAGs collaborate with the Technical Oversight Committee to assist incoming and existing CNCF projects with security reviews and guidance for achieving cybersecurity and compliance readiness. They provide resources, including self-assessments for project maintainers to evaluate their security posture and joint assessments for deeper analysis of project security. Current initiatives include refreshing the cloud native security controls catalog, developing guidance for MCP server authentication and authorization, and gathering metrics for supply chain security insights. The presentation encourages audience engagement with ongoing projects and resources available through the TAG Security and Compliance GitHub repo and CNCF Slack channels.

Full transcript

Hi everyone. Let's get get right into it. So what is TAG Security and Compliance? So we're a TAG or a Technical Advisory Group that focuses on security and compliance. So what TAGs do is we kind of work with the TOC in our focus area. So for us that means helping build secure cloud native systems. Specifically the way we help projects build these secure cloud native systems is

through security review for incoming and existing CNCF projects as well as providing general guidance for projects to achieve cybersecurity and compliance readiness. And supporting content for end users to drive adoption. So if end users are curious about compliance, curious about security, we help provide those resources. What kind of resources you may ask? So if you're a project maintainer, this is the kind of stuff that you can

you can come to us for. First of all we have security assessments. There's two different types. There are self-assessments that projects can do really at any time in the project life cycle especially earlier on where we provide a format for maintainers of the projects to look themselves at their project, the security posture and kind of look at their kind of their threat model, what kind of attacks

could happen and really just kind of give an opportunity for you to think for yourself how would how to improve your project security. And then as projects mature and if they're interested in kind of learning more past that self-assessment process, we also provide the joint assessment you actually work with folks in TAG Security and Compliance who you know, look over that self-assessment, who ask more questions, you

kind of dive into sometimes dive into the code itself and kind of look at, you know, more detail about the security of your project and kind of come up with guidance for things you can do to make it even better. And so these are resources that we provide for projects. The self-assessments are sometimes required for moving levels and the joint assessments are really just a resource we

provide to help you make your project more secure. We also provide a lot of guidance. These are things like best practices guides and white papers about topics in security that um that you might have questions about. So this is a kind of and how kind of general security guidance applies specifically to the world of cloud native. Right? So if there's things that are different, we try to

make sure to highlight those and make things clear about how that can work for you. What are we working on right now? This is a a list of kind of our current projects that we're working on now. Um The first one is the cloud native we're we're doing a refresh of the cloud native security controls catalog. So this this looks at compliance controls and how they map

to some of our our security guidance and other guidance in the cloud native community so that if you are trying to achieve regulatory compliance, you can kind of use this to see how this fits into the cloud native system. We're also working on some guidance around MCP server authentication and authorization. Um you may have heard of MCP, one of these news tools used for AI and so

we're trying to see how that guidance applies to this world of of cloud native, what the best practices are. So if it's coming to your project, you can kind of find those. There's also a project we're working on, the CNCF Supply Chain Security Insights where we're trying to This is kind of more for that ecosystem side where we're looking at all the different projects in the CNCF

and trying to gather metrics about their supply chain security both so you as a project can see how you how you're faring, how you can improve, but also so that users of the projects can get a sense for where all this metadata is, how they can use it, the you know, how to find things like SBOMs. And we're also doing more guidance around identity and access management,

another white paper about you know, how that applies to this world of cloud native. Um and some kind of recipe cards to try to make it easy to use um advice in supply chain security. It's kind of a very quick overview of what we're doing now. If you're curious about any of this, we have a issue tracker as part of the the TOC repo. So if you

go to on GitHub, the TOC repo, if you can filter by TAG Security and Compliance, you can see all the cool stuff we're up to and suggest more ideas if you have more things that you think we should be taking a look at. So please get involved. We um are a community-based organization volunteer run. So if you are a project looking for you know, you have questions

about security and compliance, if you are interested in security and compliance and want to just show up, we have meetings in two different time zones. We have them the time zones are there, you can figure out which which one works for your for your schedule. Um and that there's that link to the issue tracker with the with the filter. These slides will be online too, but if

you're curious how to find our our stuff, that's right there. We're on the CNCF Slack under TAG Security and Compliance as well as a couple channels for individual projects. Um come get involved. And also this week, come find us. I'll be I'll be I'll be here after this talk. We also have a kiosk in the project pavilion in the mornings all week. Those are the those are

the times that we'll be kind of open and and hosting that that kiosk. We're giving a talk with a lot more deep dive into security assessments. So if you are curious about that, we'll be we have a panel with actually some folks who've already done the security assessment process. So you can kind of get some some people with some real experience doing them and you can learn

what that process could look like for you. And finally we we kind of leading up to to KubeCon, we ran the security slam to kind of help projects do kind of a quick you know, um improvements to security and so we're doing an award ceremony for the projects that have participated in that. If you didn't participate, you can come and learn what that was, how you can

get involved next time. that's us. Thank you so much and have a have a fantastic event. >> [applause]