APP-05.2: IaC templates are consistently assessed for security and policy violations within CI/CD pipelines before being deployed into production. This is often implemented using different tools than SAST and for Level 5 testing must be consistent.
  • Control automation: Either
  • AWS control specification: none
  • Azure control specification: none
  • GCP control specification: none
  • Third-party (CSPM/CNAPP) control specification: CNAPP tooling includes IaC scanning at the pipeline level

Description

  • Control automation: Either
  • AWS control specification: none
  • Azure control specification: none
  • GCP control specification: none
  • Third-party (CSPM/CNAPP) control specification: CNAPP tooling includes IaC scanning at the pipeline level