ChaptersEventsBlog

Shifting Left the Right Way with OSCAL, Dr. Michaela Iorga, Senior Security Technical Lead for Cloud Computing, National Institute of Standards and Technology (NIST/ITL)

Released: 10/29/2021

Shifting Left the Right Way with OSCAL, Dr. Michaela Iorga, Senior Security Technical Lead for Cloud Computing, National Institute of Standards and Technology (NIST/ITL)
Shifting Left the Right Way with OSCAL, Dr. Michaela Iorga, Senior Security Technical Lead for Cloud Computing, National Institute of Standards and Technology (NIST/ITL)
A key component of the Cloud Development Lifecycle (CDLC) is the early development phase involving infrastructure as code (IaC), which is used to define and provision the initial cloud resources and configurations in code files. If IaC contains misconfiguration or compliance violations, it becomes a means of deploying those vulnerabilities at scale, representing significant cloud risk. NIST’s Open Security Controls Assessment Language (OSCAL) provides a normalized expression of security requirements across standards, and a machine-readable representation of security information from controls to system implementation and security assessment, allowing to shift left on cloud security. This talk will briefly describe OSCAL models and discuss its ability to shift left cloud security continuous assessment.
Topics:

Prefer to access this resource without an account? Download it now.

Partner Event Spotlight

Want to see your content featured here?

Contact us to learn more!

Explore More of CSA

Research & Best Practices

Stay informed about the latest best practices, reports, and solutions in cloud security with CSA research.

Upcoming Events & Conferences

Stay connected with the cloud security community by attending local events, workshops, and global CSA conferences. Engage with industry leaders, gain new insights, and build valuable professional relationships—both virtually and in person.

Training & Certificates

Join the countless professionals who have selected CSA for their training and certification needs.

Industry News

Stay informed with the latest in cloud security news - visit our blog to keep your competitive edge sharp.