Skip to content
This repository was archived by the owner on Dec 18, 2025. It is now read-only.

Latest commit

History

History
32 lines (20 loc) 路 1.64 KB

File metadata and controls

32 lines (20 loc) 路 1.64 KB

Automated Governance

The TAG has advanced secure software practices with the Secure Software Factory Reference Architecture Paper. Building on this, the new initiative will provide guidelines for automated governance in cloud-native environments, focusing on integrating security, compliance, and auditability into CI/CD pipelines to automate and operationalize governance and compliance practices.

Goals

  • Provide guidelines and best practices for implementing automated governance processes in cloud native environments.
  • Integrate security, compliance, and auditability into CI/CD pipelines.
  • Streamline compliance processes and enhance the overall security posture of cloud native applications.

Scope

The scope of this project includes:

  • Research and analysis of current automated governance practices.
  • Development of a comprehensive reference architecture.
  • Creation of best practice guidelines and documentation.
  • Potential development of tooling or integration patterns for common CI/CD platforms.

WIP Documentation

Meeting Information

Contact

  • Lead: Andr茅s Vega, Brandt Keller
  • Slack Channel: Link