Audit tests and other assurance activities involving assessment of operational systems should be planned and agreed between the tester and appropriate management.
Kyverno’s audit mode continuously evaluates Kubernetes resources against defined security and compliance policies without blocking workloads. All violations are recorded as PolicyReports - a centralized audit trail of misconfigurations, policy breaches, and non-compliant resources.
Before audits, Velero creates backup snapshots of cluster state. Auditors test against isolated copies from backups rather than live systems. This prevents any disruption to production and Original systems remain unaffected.
All auditor access, system events, and audit-related activities are captured centrally in Graylog. Nothing is missed, and every action during audit is traceable.
Application test environments are fully separated from production, ensuring that no production data is used, exposed, or impacted during testing activities.