ISO 27001 Annex A Controls Mapped to CI/CD Pipelines

ISO 27001 Annex A Controls Mapped to CI/CD Pipelines

Why CI/CD Pipelines Fall Within ISO 27001 ISMS Scope Continuous Integration and Continuous Delivery (CI/CD) pipelines are not merely engineering conveniences — they are information processing facilities that handle source code, credentials, cryptographic keys, and production deployment authority. Under ISO 27001, any system that processes, stores, or transmits information assets must fall within the scope … Read more

NIS2 Incident Reporting — Pipeline Evidence Requirements

NIS2 Incident Reporting — Pipeline Evidence Requirements

NIS2 Article 23: Incident Reporting Requirements Overview NIS2 Article 23 imposes strict incident notification obligations on essential and important entities. Organisations must report significant incidents to their national CSIRT or competent authority within tight timeframes: Early warning: Within 24 hours of becoming aware of a significant incident Incident notification: Within 72 hours, providing an initial … Read more

Continuous Compliance via CI/CD — Architecture & Evidence Model

Continuous Compliance via CI/CD — Architecture & Evidence Model

Introduction Traditional compliance approaches rely heavily on periodic audits, manual evidence collection, and static documentation. While this model may satisfy basic regulatory requirements, it struggles to keep pace with modern software delivery practices driven by continuous integration and continuous delivery (CI/CD). In regulated enterprise environments — financial institutions, insurance companies, and public sector organizations — … Read more

Supplier Governance & CI/CD Controls Checklist — Including the Strict Auditor Version

Supplier Governance & CI/CD Controls Checklist — Including the Strict Auditor Version

A supplier-governance and CI/CD controls checklist for regulated pipelines, now including a stricter auditor worksheet with per-control evidence references and a formal auditor decision block.

Third-Party Risk in CI/CD Pipelines under DORA Article 28

Third-Party Risk in CI/CD Pipelines under DORA Article 28

DORA Article 28 requires financial entities to manage risks introduced by ICT third-party service providers. In modern software delivery, CI/CD pipelines are among the most third-party–dependent systems in the organization. Git platforms, CI runners, plugins, and artifact registries are not just tooling choices — they are embedded external services that directly influence software integrity, availability, … Read more

DORA Article 28 — Evidence Pack (Auditor & Engineer Views)

DORA Article 28 — Evidence Pack (Auditor & Engineer Views)

Introduction DORA Article 28 requires regulated financial entities to demonstrate effective control over ICT third-party risks. This obligation goes far beyond vendor questionnaires or contractual statements. Auditors do not assess intent — they assess evidence. This article provides a practical evidence pack for DORA Article 28, focusing on what auditors typically ask for, where evidence … Read more

DORA Article 28 Architecture: Third-Party ICT Risk Controls Across CI/CD and Cloud (Auditor & Engineer Views)

DORA Article 28 Architecture: Third-Party ICT Risk Controls Across CI/CD and Cloud (Auditor & Engineer Views)

Introduction DORA Article 28 requires financial entities to manage risks arising from ICT third-party service providers. In modern software delivery, these providers are not peripheral — they are embedded directly into CI/CD pipelines and cloud runtime environments. This article presents a practical architecture view of DORA Article 28, showing: The objective is not to describe … Read more