Skip to main content

DevSecOps

Use this playbook to connect Cloudaware asset context, security findings, policy evaluation, change evidence, and detection signals into a DevSecOps operating model. The goal is to make security work traceable to real assets, owners, environments, and delivery workflows.

Solution Scope

DevSecOps in Cloudaware is built from several modules that share CMDB context. CMDB identifies the assets and their relationships. Compliance Engine evaluates controls. Vulnerability Management consolidates findings and remediation state. Intrusion Detection adds host-level security telemetry. Change Management records approvals, drift, and implementation evidence.

Use this solution when you need to:

  • Map cloud and host security findings to owners, applications, and environments.
  • Detect policy drift and noncompliant configurations across cloud and on-premises assets.
  • Prioritize vulnerabilities based on asset context, exposure, ownership, and remediation status.
  • Link risky changes to affected CIs and keep evidence for audits.
  • Route security work into ticketing, collaboration, or operational workflows.

Module Fit

ModuleRole in the solution
CMDBProvides asset scope, ownership, relationships, lifecycle state, and history.
Compliance EngineEvaluates policies and stores violations or evidence against CMDB-backed resources.
Vulnerability ManagementNormalizes scanner findings and tracks prioritization, exceptions, SLAs, and remediation.
Intrusion DetectionAdds host-based security telemetry and detection data for investigation workflows.
Change ManagementConnects planned or detected changes with approvals, risk controls, and audit trail.

Workflow

  1. Establish the DevSecOps asset scope. Use CMDB to identify production assets, internet-facing resources, regulated environments, high-criticality applications, and systems that require host-level telemetry.

  2. Normalize ownership and routing fields. Confirm that CIs have owners, application mapping, environment, business unit, and support group fields. These fields determine who receives findings, tickets, alerts, and exception requests.

  3. Enable security data sources. Configure cloud integrations, vulnerability scanners, Breeze Agent where required, IDS sources, and relevant third-party tools. Verify that findings are attached to the expected CIs instead of remaining as unlinked records.

  4. Define policy and vulnerability priorities. Use Compliance Engine and Vulnerability Management to separate urgent remediation from backlog work. Base priority on severity, exploitability, exposure, environment, business criticality, and existing exceptions.

  5. Connect remediation to change controls. For changes that affect production, critical systems, or audit-sensitive controls, route remediation through Change Management. Link change requests, approvals, implementation evidence, and post-change validation back to the affected CIs.

  6. Build feedback loops. Use dashboards and reports to track open findings, overdue remediation, recurring policy failures, failed changes, and assets with missing coverage. Feed recurring issues into engineering standards, templates, or CI/CD checks where applicable.

  7. Review exceptions and residual risk. Use exception workflows for accepted risk, compensating controls, unsupported systems, and temporary deferrals. Review exceptions regularly so they do not become permanent unmanaged risk.

Expected Outputs

  • Security findings tied to CMDB assets, owners, applications, and environments.
  • Policy violations with evidence and remediation state.
  • Vulnerability queues prioritized by business and technical context.
  • Change records for high-risk remediation work.
  • Dashboards for security posture, SLA performance, exceptions, and coverage gaps.