FIPS Package Dependency Management
How a DevOps Platform helps protect against supply chain attacks

How a DevOps Platform helps protect against supply chain attacks

4/28/2021 · Cindy Blake

What this post added

This post outlines five steps to enhance application security and protect against supply chain attacks using a DevOps platform. It details the problems with traditional AppSec approaches and highlights the benefits of an integrated DevOps platform like GitLab, including end-to-end visibility, consistent policy administration, more intelligent response, and reduced attack surface. The five steps are: 1. Assess security hygiene (patches, passwords, secrets detection, MFA, visibility, access controls). 2. Automate scanning, policies, and compliance (SAST, DAST, dependency scanning, container scanning, secrets detection, fuzz testing, standardized CI pipelines, policy exceptions, segregation of duties, identity and access controls, configuration management, change control, access restrictions, protected branches/environments, auditing, licensed code usage, security testing). 3. Protect application infrastructure (container scanning, SAST for Helm charts, container host security, container network security, integration with Falco and AppArmor, container registry security). 4. Secure the software factory itself (Zero Trust, least privilege access, integration with Hashicorp Vault, hardening GitLab instances, secure CI/CD variables). 5. Implement a security program that combines people, processes, and tools with cross-department collaboration.

Read the original post ↗