{"id":335,"date":"2018-08-15T13:28:20","date_gmt":"2018-08-15T13:28:20","guid":{"rendered":"http:\/\/ismiletechnologies.com\/?p=335"},"modified":"2018-08-15T13:28:20","modified_gmt":"2018-08-15T13:28:20","slug":"secure-devops-kit-azureazsk","status":"publish","type":"post","link":"https:\/\/ismiletechnologies.com\/en_us\/devsecops\/secure-devops-kit-azureazsk\/","title":{"rendered":"Secure DevOps Kit for Azure(AzSK)"},"content":{"rendered":"<h1>We have used\u00a0Secure DevOps Kit for Azure(AzSK) for many of our clients, also have enhanced to meet HIPAA, HITRUST Compliance<\/h1>\n<h1><\/h1>\n<p>The &#8220;Secure DevOps Kit for Azure&#8221; (referred to as &#8216;AzSK&#8217; henceforth) is a collection of scripts, tools, extensions, automations, etc. that caters to the end to end Azure subscription and resource security needs for dev ops teams using extensive automation and smoothly integrating security into native dev ops workflows helping accomplish secure dev ops with these 6 focus areas:<\/p>\n<ol>\n<li><strong><code>Secure the subscription<\/code>:<\/strong>\u00a0A secure cloud subscription provides a core foundation upon which subsequent development and deployment activities can be conducted. An engineering team should have the capabilities to deploy and configure security in the subscription including elements such as alerts, ARM policies, RBAC, Security Center policies, JEA, Resource Locks, etc. Likewise, it should be possible to check that all settings are in conformance to a secure baseline.<\/li>\n<li><strong><code>Enable secure development<\/code>:<\/strong>\u00a0During the coding and early development stages, developers should have the ability to write secure code and to test the secure configuration of their cloud applications. Just like\u00a0<em>build verification tests<\/em>\u00a0(BVTs), we introduce the concept of\u00a0<em>security verification tests<\/em>\u00a0(SVTs) which can check for security of various resource types in Azure.<\/li>\n<li><strong><code>Integrate security into CICD<\/code>:<\/strong>\u00a0Test automation is a core tenet of devops. We emphasize this by providing the ability to run SVTs as part of the VSTS CICD pipeline. These SVTs can be used to ensure that the target subscription used to deploy a cloud application and the Azure resources the application is built upon are all setup in a secure manner.<\/li>\n<li><strong><code>Continuous Assurance<\/code>:<\/strong>\u00a0In the constantly changing dev ops environment, it is important to move away from the mindset of security being a milestone. We have to treat security as a\u00a0<em>continuously varying state<\/em>\u00a0of a system. This is made possible through capabilities that enable\u00a0<em>continuous assurance<\/em>\u00a0using a combination of automation runbooks, schedules, etc.<\/li>\n<li><strong><code>Alerting &amp; Monitoring<\/code>:<\/strong>\u00a0Visibility of security status is important for individual application teams and also for central enterprise teams. We provide solutions that cater to the needs of both. Moreover, the solution spans across all stages of dev ops in effect bridging the gap between the\u00a0<em>dev<\/em>\u00a0team and the\u00a0<em>ops<\/em>\u00a0team from a security standpoint through the single, integrated views it generates.<\/li>\n<li><strong><code>Cloud Risk Governance<\/code>:<\/strong>\u00a0Lastly, underlying all activities in the kit is a telemetry framework that generates events capturing usage, adoption, evaluation results, etc. This allows us to make measured improvements to security targeting areas of high risk and maximum usage before other<\/li>\n<\/ol>\n<p>The Secure DevOps Kit Git repo has moved to a new location.<br \/>\nPlease go here for source:\u00a0<a href=\"https:\/\/github.com\/azsk\/DevOpsKit\">https:\/\/github.com\/azsk\/DevOpsKit<\/a>\u00a0and here for docs:\u00a0<a href=\"https:\/\/github.com\/azsk\/DevOpsKit-docs\">https:\/\/github.com\/azsk\/DevOpsKit-docs<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>We have used\u00a0Secure DevOps Kit for Azure(AzSK) for many of our clients, also have enhanced to meet HIPAA, HITRUST Compliance The &#8220;Secure DevOps Kit for Azure&#8221; (referred to as &#8216;AzSK&#8217; henceforth) is a collection of scripts, tools, extensions, automations, etc. that caters to the end to end Azure subscription and resource security needs for dev [&hellip;]<\/p>\n","protected":false},"author":3,"featured_media":336,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[72],"tags":[],"class_list":["post-335","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-devsecops"],"_links":{"self":[{"href":"https:\/\/ismiletechnologies.com\/en_us\/wp-json\/wp\/v2\/posts\/335","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ismiletechnologies.com\/en_us\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ismiletechnologies.com\/en_us\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ismiletechnologies.com\/en_us\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/ismiletechnologies.com\/en_us\/wp-json\/wp\/v2\/comments?post=335"}],"version-history":[{"count":0,"href":"https:\/\/ismiletechnologies.com\/en_us\/wp-json\/wp\/v2\/posts\/335\/revisions"}],"wp:attachment":[{"href":"https:\/\/ismiletechnologies.com\/en_us\/wp-json\/wp\/v2\/media?parent=335"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ismiletechnologies.com\/en_us\/wp-json\/wp\/v2\/categories?post=335"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ismiletechnologies.com\/en_us\/wp-json\/wp\/v2\/tags?post=335"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}