Specifying security requirements for container orchestration
Containers are built on a cluster management plane and a control plane. The control plane connects the API server for client connections to the nodes that are running the cluster configuration for the application. Security data and events are monitored through Azure policy and Defender for Cloud through the Azure Security Benchmark.
Microsoft Defender for Containers monitors containers and container registries for vulnerabilities and threats. Figure 8.11 shows a diagram of the workflow for monitoring security posture:
Figure 8.11 – Microsoft Defender for Containers policy orchestration
The next section will provide information that will help you understand security operations frameworks and perform forensics on endpoints.