Review workbook

Container and Serverless Security Review

Review build provenance, deployment access, runtime permissions, secrets, and investigation coverage across containers and functions.

Container and Serverless Security Review visual for DefendArm Security guidance
Preview before download

Review the delivery and runtime paths

Review one workload and environment at a time. Mark checks that do not apply with a reason; container controls and managed-function controls are not interchangeable.

Sample decisions
  • Which identities can deploy, invoke, or read data through this workload?
  • Can the workload perform its intended task while an unrelated operation is denied?
  • Do the reviewed artifact and permissions match what is running in production?
Common mistakes
  • Treating a clean image scan as proof that deployment permissions are safe.
  • Reusing one powerful execution identity across unrelated functions.
  • Assuming short-lived workloads do not need durable audit evidence.
What is inside

Container and Serverless Security Review

Review build provenance, deployment access, runtime permissions, secrets, and investigation coverage across containers and functions. Includes a fillable PDF with worked examples and decision records.

Fillable PDF. Reviewed 2026-09-21. Includes practical guidance and reusable review records.

  • Review the delivery and runtime paths: Review one workload and environment at a time. Mark checks that do not apply with a reason; container controls and managed-function controls are not interchangeable.
  • Worked review / Document processor: Fictional example: a file upload triggers a function that calls a container service. Both use a broad storage role inherited from an early prototype.
  • Workload review record: Repeat this sheet per workload. Use evidence-backed outcomes: verified, gap, unknown, or not applicable with a reason.

References

Examples are fictional. Adapt these materials to your environment; completing a worksheet is not a certification.

Questions teams ask

Practical questions before you decide.

Who should use the Container and Serverless Security Review?

This resource is built for platform engineers, developers, cloud owners, and security reviewers who need a clear way to turn security guidance into owners, evidence, and next actions.

What should a team prepare before using it?

Prepare current system owners, relevant policies, available logs or configuration evidence, and any known exceptions that affect the control area.

When should this turn into a deeper review?

Bring in the relevant specialist when the work exposes missing evidence, unclear authority, or controls your team cannot validate. Keep the unresolved issue, owner, and next decision recorded.