Session

Simplifying IaC Security

Let's talk through the ups, downs, and lessons learned of using open source security tools to secure IaC pipelines, as well as a new open source tool I developed to simplify the management and deployment of these tools. Teams should be able to easily manage and configure their tools independently and in a distributed manner, while still having centralized visibility and the ability to quickly deploy new IaC-specific security policies.

We will also discuss a reasonable onramping process to ensure that teams don’t have their sprints uprooted by triaging piles of findings only to discover that most of them are false positives or low-priority noise. This will include a discussion of a real world roll-out, and a method that was developed to add passive security scans into existing IaC pipelines with no changes other than running the existing commands (terraform, ansible, etc.) inside of a new docker container.

Jon Zeolla

Founder, Zenable

Pittsburgh, Pennsylvania, United States

Actions

Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.

Jump to top