IaC security
Infrastructure as code (Terraform, CloudFormation, Ansible, Bicep) defines the cloud and systems in versioned files. That lets you scan infrastructure security before deploying it: a public bucket or an open security group is caught in the PR, not after the breach.
Why IaC changes security
Section titled “Why IaC changes security”- infra is CODE -> reviewed, versioned, and scanned like code (shift-left)- a misconfig (public S3, 0.0.0.0/0 SG, no encryption) is caught BEFORE applying- reproducible and auditable: the desired state is in git, not in manual clicks- risk: one template error is multiplied across N deploymentsWhat IaC scanning detects
Section titled “What IaC scanning detects”- public storage (S3/blob), encryption at rest disabled- security groups/firewalls too open (0.0.0.0/0, admin ports)- IAM with excessive permissions (* in actions/resources, see cloud)- logging/monitoring disabled, no MFA, keys without rotation- untagged resources (governance) and baseline deviationsCheckov policies for Terraform/CFN/K8s/ARM (broad catalog)tfsec / Trivy Terraform scanning and more (Trivy unifies IaC/image/SCA)KICS multi-platform (Checkmarx)OPA/Conftest custom policies (Rego) -> policy as codeTerrascan, cfn-nag, ansible-lint (security)Policy as Code
Section titled “Policy as Code”- express security policies as code (OPA/Rego, Sentinel) -> gate in CI- "no public buckets", "encryption mandatory", "no SGs open to the Internet"- the PR fails if the template violates the policy -> prevention at the sourceDrift and state
Section titled “Drift and state”- drift: the real infra deviates from the code (manual changes) -> re-scan live infra- handle the Terraform STATE carefully: it contains secrets -> encrypted/remote backend- detect and reconcile drift; no "ClickOps" outside the codeBlue Team / AppSec
Section titled “Blue Team / AppSec”- Scan IaC in the PR/CI (Checkov/tfsec/Trivy) and fail on insecure configs.
- Policy as Code (OPA/Conftest) for the org’s invariants (no public, encryption, etc.).
- Protect the Terraform state (it contains secrets) and watch for drift.
- Complement with cloud posture (CSPM, see cloud) for already-deployed infra.
CVEs and real-world cases
Section titled “CVEs and real-world cases”- Countless breaches from public S3 buckets and open security groups deployed by unscanned IaC.
- Capital One (2019): a cloud misconfiguration (WAF/IAM); the kind of flaw IaC scanning prevents.
- Most cloud incidents are misconfigurations, not exploits → IaC scanning is high ROI.
Testing checklist
Section titled “Testing checklist”- IaC scanning in the PR/CI (Checkov/tfsec/Trivy)
- Policy as Code for invariants (OPA/Conftest)
- Detect public storage / open SGs / excessive IAM
- Encryption at rest and logging mandatory by policy
- Terraform state in an encrypted/remote backend
- Drift detection and reconciliation
- Complement with CSPM for deployed infra (cloud)