Security Domains Explained

Security Domains Explained

CI/CD Security, DevSecOps, and Application Security address different risks, controls, and audit expectations. This page explains why regulated organisations keep them separate, how each maps to DORA, NIS2, ISO 27001, SOC 2, and PCI DSS, and where the seams between them create audit findings.

CI/CD Security Tooling — Auditor’s Guide to Tool Categories and Controls

CI/CD Security Tooling — Auditor’s Guide to Tool Categories and Controls

A Governance-Focused Guide to CI/CD Security Control Categories for Auditors, Compliance Officers, and Regulators CI/CD pipelines are the backbone of modern software delivery. For auditors and compliance officers, understanding the security controls embedded within these pipelines is essential for evaluating whether an organization adequately manages software delivery risk. This guide explains the main CI/CD security … Read more

DAST in Regulated Environments — Auditor’s Guide to Assessing DAST Controls

DAST in Regulated Environments — Auditor’s Guide to Assessing DAST Controls

A structured framework for auditors, compliance officers, and regulators assessing DAST controls in regulated CI/CD environments — covering coverage, enforcement, evidence, and exception governance — and how auditors actually review DAST in practice, including the deficiencies that most often trigger findings.

SAST Tool Governance — Selection Checklist, RFPs & What Auditors Should Verify

SAST Tool Governance — Selection Checklist, RFPs & What Auditors Should Verify

A verification framework for auditors assessing SAST tool governance — from a 28-point selection audit checklist and the reasons most SAST RFPs fail, through policy enforcement, evidence, and regulatory alignment under DORA, NIS2, and ISO 27001.

SAST in Regulated Environments — Auditor’s Guide to Assessing SAST Controls

SAST in Regulated Environments — Auditor’s Guide to Assessing SAST Controls

A structured framework for auditors and compliance officers assessing SAST controls in regulated environments — covering coverage, enforcement, exception governance, and evidence, plus a step-by-step walk-through of how auditors actually review SAST during an audit.

How Auditors Actually Review CI/CD Pipelines

How Auditors Actually Review CI/CD Pipelines

CI/CD pipelines are increasingly in scope during security and regulatory audits. While many organizations focus on policies and tooling descriptions, auditors assess CI/CD pipelines very differently in practice. This guide explains how auditors really approach CI/CD reviews, what they look for first, how they test controls, and why many organizations fail audits despite having “secure” … Read more