Opens in a new tab
vmblog logo 2024 wht (updated)

Scaling AppSec Programs with Policy-as-Code

Share: 

David Marshall | Published: July 31, 2024

By: Cherry Han of GitLab

Today’s developers are tasked with shipping software faster and more securely than ever while adhering to stringent security and compliance requirements. In response to these growing demands, organizations began shifting security left with the intention of closer integration between engineering and security in DevSecOps workflows. 

While organizations are increasingly prioritizing application security and governance policies, these written policies often aren’t actionable for the developers on the engineering frontlines. Documentation, while critical for keeping organizations aligned on the latest policies and controls, is often inaccessible or unactionable for development teams. Organizations must build trust into their workflows and processes to reduce the likelihood of malicious or accidental actions that can lead to compromises or breaches. 

Additionally, software security assurance functions including audit and compliance have not yet been widely integrated into the team culture and operations when adopting DevSecOps. As a result, the governance and native evidence needed for regulated software are often an afterthought and ultimately lead to unplanned time and resource constraints. 

To align development, security, and operations objectives at scale organizations must implement policy-as-code – the practice of programmatically applying an organization’s security and risk controls to its development ecosystem and application workflows. 

Policy-as-code enables efficient and automated security and control implementation, while delivering inspection and demonstratable compliance within the context of development workflows. Let’s walk through the benefits of policy-as-code and explore how organizations can integrate policy-as-code into existing DevSecOps workflows. 

Benefits of Policy-as-Code for Developers and Security Teams

Policy-as-code is a method of systematically implementing security testing and gating into DevSecOps workflows, while also significantly reducing the need for separate work streams for audit and attestation. It ensures the necessary controls are applied to an organization’s security and compliance standards throughout the software development lifecycle (SDLC) by requiring security policies and testing plans be turned into programmatic pipeline instructions (for example, YAML). 

Policy-as-code is beneficial for both developers and security teams. Developers are given immediate access to crucial security policies and can apply them while working within their existing DevSecOps tools and processes. This reduces their reliance on security teams and cuts down the cycle time for feedback, allowing them to work faster while still maintaining security standards. As a result, security teams are no longer required for every security decision within the development lifecycle. They can focus on scaling and developing proactive security strategies and managing the organizational security posture. 

Enabling Developers to Ship Secure Code Faster

Recent research from GitLab found that nearly half of organizations globally experience collaboration silos across developer, security, and operations teams. Adding further strain between these teams, the survey also showed that 85% of security respondents reported flat budgets year-over-year – highlighting the need to do more with less. 

However, when shifting security left, many teams find that developers don’t have access to security policies in real-time, and these policies are not enforceable so security issues and vulnerabilities ultimately make their way downstream to security teams. Developers must be given security training and resources to build more secure code. 

By providing a shared framework for policy enforcement and compliance, developers can ship code faster, with the assurance that it adheres to organizational policy. With more accessible resources integrated into existing DevSecOps workflows, developers are empowered to resolve vulnerabilities earlier in the process, and over time, they will be able to deliver secure code faster while improving their release quality. This helps automate and scale remediation support for developers and allows application security teams to focus on proactively mitigating any security risks and strengthening the organization’s security posture. 

Aligning Security and Development Teams to Implement Policy as Code 

Implementing policy-as-code requires development and security team alignment on how predefined security processes are woven into the SDLC to prioritize speed and efficiency. Security teams need to understand the day-to-day work of their developer counterparts and use that knowledge to develop policies that help developers build the necessary security controls into their workflows. Developers must stay open-minded to new tools and practices to make the development process more secure. 

Some best practices for implementing policy-as-code into DevSecOps pipelines include: 

  • Transcribing documented policies into defined steps in application testing strategy. 
  • Defining non-negotiable security testing as part of the continuous integration (CI) process with enforcement. 
  • Establishing and enforcing governance within pipelines, including identifying which roles can approve code changes.
  • Instituting separation of duties by ensuring expected security work in the pipelines cannot be bypassed or dismissed in the development workflow. 
  • Defining test scenarios or gates in which approval or exceptions require peer review or security signoff.
  • Defining which artifacts and logs are needed during the development workflow for audit evidence and attestation. 

Policy-as-code is an interactive practice. Policies and processes must be continuously evaluated and evolved alongside the growing threat landscape. Security and speed do not have to be mutually exclusive goals for a development team – policy-as-code can help organizations achieve the vision promised by a DevSecOps framework. 

##

ABOUT THE AUTHOR

Cherry Han, Field CTO, Americas, at GitLab

Cherry Han 

Cherry is the field CTO at GitLab. Cherry helps technology leaders transform software innovation in their organizations so they can deliver better products faster and more securely. Cherry works with CISO and security professionals to bring AI innovation to the teams.