Security-as-Code: Embedding Policy-Driven Security in CI/CD Workflows

Guru Pramod Rusum · International Journal of AI BigData Computational and Management Studies · 2022

Security in software development has long been considered an independent, downstream process- flowing after the code has been written, and before the code gets deployed. Such a reactive stance has proven ineffective in the present, cloud-native world, where agile iteration and rapid releases are the norms. The paradigm shift toward DevSecOps also requires integrating security directly into the CI/CD pipelines themselves, so that policy enforcement becomes automated and a continuous process. The Security-as-Code (SaC) framework is proposed in this paper as an approach to managing security rules, compliance standards, and risk mitigation, similar to conventional application code. We discuss ways of integrating SaC into a cloud-native CI/CD pipeline, compare available tools, and their compliance with policy-driven security practices. We evaluate the evolution of academia and industry in terms of automation, from static/manual controls to automated, code-driven enforcement, through a literature survey of pre-2022 works. The pipeline is a policy-driven SaC pipeline composed of Infrastructure-As-Code (IaC) scanning, dependency scanning, container hardening, and runtime policy checks. Included results include the reduction of vulnerabilities introduced into production environments and measurable successes in terms of conformance adherence. Future research opportunities are discussed in the paper: in the area of automated threat modeling, in zero-trust CI/CD environments, and AI-assisted SaC policies

Read the paper · More papers on PaperTik