CloudSecurityAlliance-WG / wg-DevSecOps
DevSecOps Working Group
☆12Updated 5 years ago
Alternatives and similar repositories for wg-DevSecOps:
Users that are interested in wg-DevSecOps are comparing it to the libraries listed below
- A collection of 2020 artifacts describing the major pain points, vulnerabilities and concerns with Cloud Security.☆19Updated 3 years ago
- A collection of DevSecOps reference architectures☆66Updated 3 years ago
- The Secure Cloud Architecture (SCA) is a location & cloud agnostic flexible and repeatable conceptual deployment pattern that can adapt f…☆15Updated 4 years ago
- A repository for wardley maps related to security topics.☆47Updated 7 years ago
- ☆12Updated 3 years ago
- AppSecPipeline Specification for DevOps automation.☆38Updated 2 years ago
- A collection of DoD and Federal Government Cloud Computing Resources☆48Updated 3 years ago
- Examples on how to maintain security/compliance as code and to automate SecOps using the JupiterOne platform.☆53Updated last year
- Assess certain AWS network configurations☆11Updated 6 years ago
- (WIP) A terraform / kitchen-terraform hardening baseline for the cis-aws-foundations-baseline☆24Updated 2 years ago
- Docker container bundling tools for manual AWS security reviews☆13Updated 6 years ago
- Documentation on the Cyber Defense Matrix☆24Updated last year
- CI Pipeline with Pixi, the WAF OWASP Core Rule Set and TestCafe tests.☆15Updated 3 years ago
- Project intended to make Attack Maps part of software development by reducing the time it takes to complete them.☆47Updated 8 years ago
- InSpec profile to validate your VPC to the standards of the CIS Amazon Web Services Foundations Benchmark☆78Updated 2 weeks ago
- Labs for Threat Modelling training delivered by ControlPlane☆30Updated 8 months ago
- CloudSplaining on AWS Managed Policies☆41Updated this week
- A repository containing OSCAL serializations of the CIS Critical Security Controls☆48Updated last year
- A ComplianceAsCode blog☆25Updated last month
- A continuous security pipeline demo for the AWS DevSecOps Workshop.☆45Updated 5 years ago
- Continuous Audit Metrics☆24Updated 7 months ago
- ***MERGED: SEE README:*** The XCCDF to InSpec parser scans and extracts the controls defined in the DISA XCCDF STIG XML documents and con…☆12Updated 6 years ago
- Threat Modeling Manifesto☆27Updated 6 months ago
- Repo to hold mapping of user-security-stories☆114Updated 6 years ago
- Decision trees generated via Graphviz to inform pragmatic threat modelling.☆10Updated 4 years ago
- A platform to create, catalog and deploy tests for tools such as Gauntlt, AttackIQ and Metasploit.☆16Updated 8 years ago
- Updated incident response generator for training classes☆42Updated 3 years ago
- Utilities for programmatic analysis of Cartography data.☆33Updated last year