NIST SP 800-190
Orchestrator

NIST SP 800-190 SP800-190-3.10: Network Segmentation Between Pods

Limit pod to pod communication using network policies that follow a default deny model. Allow only the flows that the application requires, including egress, so a compromised pod cannot pivot freely across the cluster.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Other controls in Orchestrator

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.