CloudSecurityAlliance-WG / wg-DevSecOps
DevSecOps Working Group
☆12Updated 5 years ago
Related projects ⓘ
Alternatives and complementary repositories for wg-DevSecOps
- A collection of DoD and Federal Government Cloud Computing Resources☆48Updated 3 years ago
- ☆12Updated 3 years ago
- A collection of 2020 artifacts describing the major pain points, vulnerabilities and concerns with Cloud Security.☆19Updated 3 years ago
- CloudSplaining on AWS Managed Policies☆41Updated this week
- Repo to hold mapping of user-security-stories☆114Updated 5 years ago
- A continuous security pipeline demo for the AWS DevSecOps Workshop.☆45Updated 4 years ago
- Assess certain AWS network configurations☆11Updated 6 years ago
- A collection of DevSecOps reference architectures☆64Updated 3 years ago
- Docker container bundling tools for manual AWS security reviews☆13Updated 6 years ago
- Decision trees generated via Graphviz to inform pragmatic threat modelling.☆10Updated 3 years ago
- A public repository with scripts and tools for mass / automated onboarding of cloud accounts (AWS,Azure,GCP)☆23Updated 3 years ago
- Continuous Audit Metrics☆24Updated 5 months ago
- GSA Security Benchmarks and Tools☆21Updated 5 years ago
- Examples on how to maintain security/compliance as code and to automate SecOps using the JupiterOne platform.☆53Updated 10 months ago
- Threat Modeling Manifesto☆27Updated 4 months ago
- InSpec profile to validate your VPC to the standards of the CIS Amazon Web Services Foundations Benchmark☆77Updated 5 months ago
- NIST SP 800-53, Security and Privacy Controls for Federal Information Systems and Organizations☆36Updated 3 months ago
- A small set of scripts to summarize AWS Security Groups, and generate visualizations of the rules.☆62Updated 4 years ago
- A collection of security related user stories compatible with NIST Special Publication 800-53☆34Updated 7 years ago
- AppSecPipeline Specification for DevOps automation.☆38Updated last year
- CDK app to setup an isolated AWS network to experiment with ways of exfiltrating data☆18Updated 3 years ago
- A repository for wardley maps related to security topics.☆47Updated 7 years ago
- Public tables and other research that can accept PRs. Please visit the web link.☆44Updated 5 years ago
- A ComplianceAsCode blog☆25Updated last week
- Simple DLP monitor for AWS S3 is a tool built on top of CloudWatch events and Lambda functions to alert you when data is transferred to S…☆17Updated 4 years ago
- The open source version of the AWS Security Hub documentation. To provide feedback or request changes, you can submit a pull request that…☆35Updated last year
- Updated incident response generator for training classes☆42Updated 3 years ago
- This repository will teach you have to do my talk "Pushing Left, Like a Boss".☆69Updated 2 years ago
- A repository containing OSCAL serializations of the CIS Critical Security Controls☆48Updated last year