Главная
Study mode:
on
1
Introduction
2
Welcome
3
Pain Points
4
The Status Quo
5
The Goal
6
Status Checks
7
Formatting Output
8
Custom Rules
9
Waivers
10
Critical Security Vulnerability
11
OnCall Post
12
Questions
Description:
Learn how to implement automated Terraform resource analysis for AWS policy control in this 22-minute DevSecCon talk. Discover how Yelp integrates static analysis into their Infra-as-Code (IaC) pipeline, reducing security reviewer fatigue and improving developer productivity. Explore the benefits of using tools like Regula and Atlantis to catch vulnerabilities during code review, shifting security left and eliminating manual security reviews. Gain insights into formatting output, creating custom rules, implementing waivers, and handling critical security vulnerabilities. Join speaker Muhammad Ahmed, a Software Engineer in Infrastructure Security at Yelp, as he shares his experience and expertise in cloud security and network security.

Removing AWS Policy Review Fatigue with Automated Terraform Resource Analysis

DevSecCon
Add to list
0:00 / 0:00