APP-05.2: IaC templates are consistently assessed for security and policy violations within CI/CD pipelines before being deployed into production. This is often implemented using different tools than SAST and for Level 5 testing must be consistent.
Control automation: Either
AWS control specification: none
Azure control specification: none
GCP control specification: none
Third-party (CSPM/CNAPP) control specification: CNAPP tooling includes IaC scanning at the pipeline level
Description
Control automation: Either
AWS control specification: none
Azure control specification: none
GCP control specification: none
Third-party (CSPM/CNAPP) control specification: CNAPP tooling includes IaC scanning at the pipeline level