What TAG Security and Compliance Does
TAG Security and Compliance is a CNCF Technical Advisory Group that works alongside the TOC. Its remit covers three areas: security reviews for incoming and existing CNCF projects, guidance to help projects reach cybersecurity and compliance readiness, and resources for end users who want to understand how compliance requirements apply to cloud native systems. All of this work is volunteer-run.
Two Security Assessment Types for Project Maintainers
Self-assessments give maintainers a structured format to examine their own threat model and security posture at any point in the project life cycle, especially early on. Joint assessments go further: TAG members review the self-assessment, ask follow-up questions, sometimes read the code directly, and produce specific improvement guidance. Self-assessments are sometimes required for CNCF maturity level changes. Joint assessments are an optional resource any project can request.
Four Active Workstreams
Four projects are underway right now. The cloud native security controls catalog is being refreshed to map compliance controls to existing cloud native guidance, helping teams pursuing regulatory compliance. New guidance covers MCP server authentication and authorization for AI tooling. The CNCF Supply Chain Security Insights project gathers supply chain metrics across all CNCF projects, including SBOM locations. A fourth workstream produces identity and access management guidance plus supply chain security recipe cards.
How to Track Work and Get Involved
All active work is tracked in the CNCF TOC GitHub repo. Filter by “TAG Security and Compliance” to see open issues and suggest new topics. The group holds meetings in two time zones. The CNCF Slack has a dedicated TAG Security and Compliance channel plus channels for individual projects. This week at KubeCon, a project pavilion kiosk runs each morning, and a panel with maintainers who have completed the security assessment process covers what that experience looks like in practice.
Security Slam Award Ceremony
Leading up to KubeCon, TAG ran the Security Slam, a sprint to help projects make quick security improvements. An award ceremony for participating projects is happening at the event. Projects that did not participate can attend to learn what the slam involved and how to join the next round. Moore is available after the talk for questions.
Notable Quotes
So what TAGs do is we kind of work with the TOC in our focus area. Marina Moore · ▶ 00:09
The self-assessments are sometimes required for moving levels and the joint assessments are really just a resource we provide to help you make your project more secure. Marina Moore · ▶ 01:42
we ran the security slam to kind of help projects do kind of a quick you know, um improvements to security Marina Moore · ▶ 05:03
Key Takeaways
- Self-assessments and joint assessments serve different maturity stages of CNCF projects.
- Four active workstreams cover compliance mapping, MCP auth, supply chain metrics, and IAM guidance.
- All TAG work is tracked publicly in the CNCF TOC GitHub repo and open to contributors.
About the Speaker(s)
Marina Moore is a Research Scientist at Edera. She maintains The Update Framework (TUF), a CNCF graduated project for secure software update and delivery, and chairs CNCF’s TAG Security and Compliance, where she contributes to security assessments and whitepapers.