Back to Frameworks

CNCF Security Technical Advisory Group (TAG)

International (CNCF/Linux Foundation)
vv2 (2022) - CNCF Cloud Native Security Whitepaper
7 domains
24 controls

The CNCF Security Technical Advisory Group (TAG) publishes security guidance for cloud‑native ecosystems, including the CNCF Cloud Native Security Whitepaper (v2, 2022), the Software Supply Chain Best Practices guide, and the CNCF Security Assessment process. These resources are best‑practice documents rather than a formal framework with defined domains or controls.

Verified

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (7)

CNCF: Cloud Native Layers (4C)

4 controls
Controls in the CNCF: Cloud Native Layers (4C) domain of CNCF Security Technical Advisory Group (TAG)4 controls
CodeTitle
CNCF-4C-CLOUDCloud Layer Security
CNCF-4C-CLUSTERCluster Layer Security
CNCF-4C-CODECode Layer Security
CNCF-4C-CONTAINERContainer Layer Security

CNCF: Compliance

2 controls
Controls in the CNCF: Compliance domain of CNCF Security Technical Advisory Group (TAG)2 controls
CodeTitle
CNCF-COMP-AUDITSRegulatory Audits
CNCF-COMP-INDUSTRYIndustry-Specific Compliance

CNCF: Lifecycle - Deploy

4 controls
Controls in the CNCF: Lifecycle - Deploy domain of CNCF Security Technical Advisory Group (TAG)4 controls
CodeTitle
CNCF-DEP-ARTIFACTSArtifact and Image Verification
CNCF-DEP-INCIDENTIncident Response and Mitigation
CNCF-DEP-OBSERVABILITYObservability and Metrics
CNCF-DEP-PREFLIGHTPre-Flight Deployment Checks

CNCF: Lifecycle - Develop

2 controls
Controls in the CNCF: Lifecycle - Develop domain of CNCF Security Technical Advisory Group (TAG)2 controls
CodeTitle
CNCF-DEV-CHECKSSecurity Checks in Development
CNCF-DEV-TESTINGSecurity Testing

CNCF: Lifecycle - Distribute

5 controls
Controls in the CNCF: Lifecycle - Distribute domain of CNCF Security Technical Advisory Group (TAG)5 controls
CodeTitle
CNCF-DIST-IMGHARDENImage Hardening
CNCF-DIST-IMGSCANImage Scanning
CNCF-DIST-MANIFESTHARDENContainer Application Manifest Hardening
CNCF-DIST-MANIFESTSCANContainer Application Manifest Scanning
CNCF-DIST-PIPELINEBuild Pipeline Security

CNCF: Lifecycle - Runtime

4 controls
Controls in the CNCF: Lifecycle - Runtime domain of CNCF Security Technical Advisory Group (TAG)4 controls
CodeTitle
CNCF-RT-ACCESSRuntime Access (Identity, Authentication, Authorization)
CNCF-RT-AVAILABILITYRuntime Availability
CNCF-RT-COMPUTERuntime Compute Security (Orchestration, Hosts, Containers)
CNCF-RT-STORAGERuntime Storage Security

CNCF: Security Assurance

3 controls
Controls in the CNCF: Security Assurance domain of CNCF Security Technical Advisory Group (TAG)3 controls
CodeTitle
CNCF-SA-PRINCIPLESSecurity Principles
CNCF-SA-STACKSecurity Stack and Tooling
CNCF-SA-THREATMODELThreat Modeling

Maps to 4 other frameworks

24 total controls
Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1
24 source controls mapped|21 target controls covered
100%
NIST SP 800-53 Rev 5
18 source controls mapped|11 target controls covered
75%
NIST Cybersecurity Framework 2.0
1 source controls mapped|1 target controls covered
4%
ISO 27002:2022
1 source controls mapped|1 target controls covered
4%

Frequently Asked Questions

What is CNCF Security Technical Advisory Group (TAG)?

CNCF Security Technical Advisory Group (TAG) is a compliance framework from International (CNCF/Linux Foundation) with 7 domains and 24 controls. The CNCF Security Technical Advisory Group (TAG) publishes security guidance for cloud‑native ecosystems, including the CNCF Cloud Native Security Whitepaper (v2, 2022), the Software Supply Chain Best Practices guide, and the CNCF Security Assessment process. These resources are best‑practice documents rather than a formal framework with defined domains or controls. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

How many controls does CNCF Security Technical Advisory Group (TAG) have?

CNCF Security Technical Advisory Group (TAG) has 24 controls organised across 7 domains. The largest domains are CNCF: Lifecycle - Distribute (5 controls), CNCF: Cloud Native Layers (4C) (4 controls), CNCF: Lifecycle - Deploy (4 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

What frameworks does CNCF Security Technical Advisory Group (TAG) map to?

CNCF Security Technical Advisory Group (TAG) maps to 4 other compliance frameworks. The top mapping partners are Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1 (100% coverage), NIST SP 800-53 Rev 5 (75% coverage), NIST Cybersecurity Framework 2.0 (4% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I get started with CNCF Security Technical Advisory Group (TAG) compliance?

Start your CNCF Security Technical Advisory Group (TAG) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about CNCF Security Technical Advisory Group (TAG) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 24 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 718 frameworks.

Get Started Free →

Free forever — no credit card required