kubernetes
2 posts · all writing
A misconfiguration has no CVSS, which is why nobody fixes it
A privileged pod and a public S3 bucket have no CVE, no CVSS score and no NVD entry, so every IaC tool invents its own severity, and findings that would be a breach get sorted below dependency CVEs that are unreachable. Why misconfiguration findings get ignored, and what to rank them by instead.
CIS benchmarks are somebody else's checklist, and that is the point
A benchmark will flag things you have deliberately chosen, and treating every failed check as a defect is how teams end up ignoring the whole report. The value is not the score. It is the short list of checks you decided not to meet, and the record of who decided.