# Cis Ocp V160 5.1.4

> Minimize access to create pods (Manual)

- Skill: `cyberstrikeus/cis-ocp-v160-5-1-4` (Agent Skill)
- Install (CLI): `npx skillmds@latest add cyberstrikeus/cis-ocp-v160-5-1-4`
- Raw SKILL.md: https://api.skillmd.com/api/skills/cyberstrikeus/cis-ocp-v160-5-1-4/raw
- Safety review: PASS (external: skill-scanner PASS, skillspector PASS)
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: DevOps & Infra
- Author: cyberstrikeus (https://skillmd.com/u/cyberstrikeus)
- Updated: 2026-09-17
- Page: https://skillmd.com/skills/cyberstrikeus/cis-ocp-v160-5-1-4

---


# CIS Red Hat OpenShift Container Platform Benchmark v1.6.0 - Control 5.1.4

## Profile Applicability

- **Level:** 1

## Description

The ability to create pods in a namespace can provide a number of opportunities for privilege escalation, such as assigning privileged service accounts to these pods or mounting hostPaths with access to sensitive data (unless Pod Security Policies are implemented to restrict this access).

As such, access to create new pods should be restricted to the smallest possible group of users.

## Rationale

The ability to create pods in a cluster opens up possibilities for privilege escalation and should be restricted, where possible.

## Impact

Care should be taken not to remove access to pods to system components which require this for their operation.

## Audit Procedure

Review the users who have create access to pod objects in the Kubernetes API with the following command:

```bash
oc adm policy who-can create pod
```

## Remediation

Where possible, remove `create` access to `pod` objects in the cluster.

## Default Value

By default in a kubeadm cluster the following list of principals have `create` privileges on `pod` objects.

## References

None

## CIS Controls

| Controls Version | Control                          | IG 1 | IG 2 | IG 3 |
| ---------------- | -------------------------------- | ---- | ---- | ---- |
| v8               | 2.7 Allowlist Authorized Scripts |      |      | \*   |
| v7               | 5.2 Maintain Secure Images       |      | \*   | \*   |

## MITRE ATT&CK Mappings

| Techniques / Sub-techniques | Tactics        | Mitigations |
| --------------------------- | -------------- | ----------- |
| T1078, T1078.002            | TA0001, TA0004 | M1026       |

## Profile

**Level 1** (Manual)

