Security News > 2021 > June > Regula: Open source policy engine for IaC security
Fugue announced Regula 1.0, an open source policy engine for infrastructure as code security.
Available at GitHub, the tool includes support for common IaC tools such as Terraform and AWS CloudFormation, prebuilt libraries with hundreds of policies that validate AWS, Microsoft Azure, and Google Cloud resources, and new developer tooling to support custom rules development and testing with Open Policy Agent.
Cloud and security engineers can use their Regula policies in the Fugue SaaS platform to check their AWS, Microsoft Azure, and Google Cloud environments, giving them a unified policy engine for securing the entire cloud development lifecycle from IaC through deployment and runtime.
"These new Regula capabilities and policies make it easier than ever for cloud teams to secure their IaC and apply policy consistently across the CDLC and across cloud platforms-and avoid the overhead of maintaining and reconciling different policy frameworks."
Regula utilizes the Cloud Native Computing Foundation's Open Policy Agent framework, with expressive and powerful rules written in the Rego language.
Regula provides out-of-the-box support for the CIS Foundations Benchmarks; additional Regula policies check for cloud vulnerabilities that compliance frameworks can miss, such as dangerously permissive AWS IAM policies, Lambda function policies allowing global access, EBS volumes with encryption disabled, and untagged cloud resources.
News URL
http://feedproxy.google.com/~r/HelpNetSecurity/~3/NGYF3IfPu4Y/
Related news
- Osmedeus: Open-source workflow engine for offensive security (source)
- Am I Isolated: Open-source container security benchmark (source)
- ScubaGear: Open-source tool to assess Microsoft 365 configurations for security gaps (source)
- Debunking myths about open-source security (source)
- AxoSyslog: Open-source scalable security data processor (source)
- How to Plan a New (and Improved!) Password Policy for Real-World Security Challenges (source)
- Vanir: Open-source security patch validation for Android (source)