Secure development controls
What a developer now meets on the way to production: static and dynamic analysis (SAST/DAST) wired into GitLab CI/CD; software bills of materials (SBOM) and container scanning for supply-chain traceability; ModSecurity/Falco web application firewalls on the PaaS edge — with the WAF tightening and finer DoS protections scheduled for 2026. The SOC watches the rest, ingesting Google Workspace, Azure and network logs.
Topology
- Part of: security-governance
- About: it-department — it reshapes how the department’s users ship software.
- About: cern-paas — where the WAF controls are enforced.
- Cites: security-audited-for-the-better — the measure list.