Incrementally validating security policy code using information from an infrastructure as code repository

    公开(公告)号:US11977476B2

    公开(公告)日:2024-05-07

    申请号:US17587896

    申请日:2022-01-28

    CPC classification number: G06F11/368 G06F11/3664 G06F11/3692 H04L63/20

    Abstract: In an example, an apparatus may include a validation module configured to identify a security policy update from a security as code repository, wherein the identified security policy update is a candidate for deployment to a production environment having a plurality of attributes defined by an infrastructure as code repository; identify, from the plurality of attributes and using the infrastructure as code repository, individual attributes that correspond to the identified security policy update, wherein the identified individual attributes are identical to a subset of the plurality of attributes; generate a test environment based on the identified individual attributes; following deployment of the identified security policy update to the test environment, check for security exceptions or availability exceptions using the test environment; and output validation results based on a result of the checking.

Patent Agency Ranking