Security

Articles

Articles

SearchTopic
ARTIFICIAL INTELLIGENCE CI/CD CLOUD NATIVE DEVOPS HASHICORP INFRASTRUCTURE AS CODE PLATFORM ENGINEERING SECURITY
Author
Martin Buchleitner Edmund Haselwanter Juergen Brueder Paul Strebenitzer Matthias Theuermann Marina Brooks Infralovers Team Theresa Wallas Miriam Grainer Jan Klare

cnquery

Summary cnquery is an open-source tool from Mondoo for asking questions about the current state of your infrastructure. Using the Mondoo Query Language (MQL),

cnspec

Summary cnspec is an open-source security and compliance scanner from Mondoo. It evaluates infrastructure against policies expressed as code—security

OpenBao

Summary OpenBao is an open-source platform for secrets management, encryption, and identity-based access to sensitive data. It originated as a community fork of

Access Control List (ACL)

Summary An Access Control List (ACL) is an ordered set of rules attached to a resource that specifies which subjects (users, groups, source addresses, services)

CLOUD Act

Summary The Clarifying Lawful Overseas Use of Data Act (CLOUD Act) is a 2018 US federal law. It clarifies that US authorities can compel US-based technology

Device Posture

Summary Device posture is the security state of an endpoint at the moment it tries to connect — patch level, OS version, disk encryption, EDR/MDM enrolment,

Identity Provider (IdP)

Summary An identity provider (IdP) is the trusted service responsible for authenticating users and machines, and for issuing tokens or assertions that

Mesh VPN

Summary A mesh VPN is a VPN topology in which every authorised client builds direct, encrypted peer-to-peer connections to every other client. Only identity,

Multi-Factor Authentication (MFA)

Summary Multi-Factor Authentication (MFA) requires a user to present more than one independent proof of identity. The common combination is "something you

Reverse Proxy

Summary A reverse proxy is a server placed in front of one or more backend services. It accepts client requests on their behalf, applies cross-cutting concerns

Schrems II

Summary Schrems II is the 2020 judgment of the Court of Justice of the European Union (case C-311/18). It invalidated the EU–US Privacy Shield framework and

SCIM (System for Cross-domain Identity Management)

Summary SCIM (System for Cross-domain Identity Management) is an open REST/JSON standard for automatically provisioning, updating, and de-provisioning user

SIEM (Security Information and Event Management)

Summary A SIEM (Security Information and Event Management) platform ingests security events from across an environment, normalises and correlates them, and

Single Sign-On (SSO)

Summary Single Sign-On (SSO) is an authentication pattern that lets a user sign in once with a trusted identity provider and then access multiple applications

SSL VPN

Summary An SSL VPN is a remote-access VPN that wraps user traffic inside a TLS connection to a central concentrator. It became the dominant pattern for

VPN (Virtual Private Network)

Summary A VPN (Virtual Private Network) builds an encrypted tunnel between two endpoints over an untrusted network so that remote systems behave as if they were

WireGuard

Summary WireGuard is a modern open-source VPN protocol designed for simplicity, performance, and strong cryptography. It is built into the Linux kernel since

Zero Trust

Summary Zero Trust is a security model that grants access based on continuously verified identity, device posture, and policy. It explicitly drops the idea that

Ansible Vault

Summary Ansible Vault is the built-in encryption mechanism for Ansible that allows teams to store sensitive values—passwords, API keys, certificates—alongside

Boundary

Summary HashiCorp Boundary is an open-source access management tool that enables secure, identity-based remote access to hosts and services without requiring

CINC Auditor

Summary CINC Auditor is an open-source, license-free rebuild of Chef InSpec that enables infrastructure compliance testing and auditing using the same profile

CVE (Common Vulnerabilities and Exposures)

Summary CVE (Common Vulnerabilities and Exposures) is a publicly maintained dictionary of known security vulnerabilities and exposures, each assigned a unique

DORA (Digital Operational Resilience Act)

Summary DORA (Digital Operational Resilience Act) is an EU regulation that entered into force in January 2025, requiring financial institutions and their

Firewall

Summary A firewall enforces access control between network segments by inspecting packets and applying rules that permit or deny traffic based on source,

GDPR (General Data Protection Regulation)

Summary GDPR (General Data Protection Regulation) is the EU regulation that sets out rights for individuals over their personal data and obligations for

HIPAA

Summary HIPAA (Health Insurance Portability and Accountability Act) is a U.S. federal law that sets national standards for protecting sensitive patient health

ISO 27001

Summary ISO 27001 is the leading international standard for information security management systems (ISMS), providing a systematic approach to managing

Keycloak

Summary Keycloak is an open-source Identity and Access Management (IAM) solution developed by Red Hat that provides single sign-on, identity brokering, and user

Mondoo

Summary Mondoo is a security posture management platform that enables organizations to continuously assess and enforce security policies across cloud

NIS2 Directive

Summary The NIS2 Directive (Network and Information Security Directive 2) is an EU regulation that mandates minimum cybersecurity standards across critical and

Sandboxing Claude Code on macOS: What I Actually Found

If you've used Claude Code for more than a day, you know the drill. Every Bash command, every file write outside the working directory, every network call --

Keeping Credentials Out of Code - A Practical Guide to 1Password and Vault

The Problem: Hardcoded Credentials Every developer has faced this temptation: you need to test something quickly, so you hardcode an API key or database

Secure Communication in Kubernetes with Istio Service Mesh and Vault Agent Injector

Securing Communication in Kubernetes with Istio Service Mesh and Vault Agent Injector In modern cloud-native Kubernetes environments, security is paramount. One

Secure Communication in Kubernetes with Consul Connect and Vault Agent Injector

Securing Communication in Kubernetes with Consul Connect and Vault Agent Injector In modern cloud-native Kubernetes environments, security is paramount. One of

Integrating Terraform with Ansible/Chef for Infrastructure and Configuration Automation

In modern infrastructure automation, teams often combine Terraform with configuration management tools like Ansible or Chef to get end-to-end control of their

Secrets Management Made Simple: Understanding HashiCorp Vault and Its Secret Engines

In today’s fast-paced digital world security isn’t optional, it’s a foundation. Whether you're running microservices in Kubernetes, managing cloud resources, or

Meet Mondoo: Unified Security for DevOps and Cloud

Mondoo bills itself as a comprehensive exposure management platform – think a single pane for all your security needs, on-prem and in the cloud. In practice,

Running AWX on Kubernetes with HashiCorp Vault Secrets Injector: A Seamless Integration for Secure Automation

In the ever-evolving landscape of IT automation, AWX serves as a powerful web-based user interface for Ansible, streamlining complex and repetitive tasks within

Reclaim Your Data: The Power of EU Cloud Services

In the evolving landscape of cloud computing, the reliance on US-based cloud services has become a topic of significant debate. I've observed a growing

Future-Proofing Your Compliance: Strategic Insights with Mondoo and Terraform

Introduction In today's fast-paced digital landscape, ensuring compliance with various frameworks is crucial for companies to maintain the security and

Leveraging Terraform for Enhanced Asset Security with Mondoo - Part 3: Imports

In the previous posts of this blog series, we introduced the Mondoo platform, its Terraform provider resources and data sources, exploring how they enhance

Leveraging Terraform for Enhanced Asset Security with Mondoo - Part 2: Data Sources

As organizations strive to safeguard their digital assets, innovative solutions like Mondoo have emerged to enhance security and compliance across various

Supply Chain Security with CIS SecureSuite Certification and Mondoo's Compliance on Autopilot

Supply Chain Security with CIS SecureSuite Certification and Mondoo's Compliance on Autopilot In today's digital landscape, ensuring the security of your supply

Leveraging Terraform for Enhanced Asset Security with Mondoo - Part 1: Resources

In an era where information security management is more crucial than ever, organizations are seeking innovative solutions to safeguard their digital assets

Optimizing Cost Management: Leveraging Resource Tagging and Mondoo Policies

In today's dynamic and complex cloud environments, organisations face significant challenges in managing costs while ensuring compliance and operational

Previous page
Showing of
Next page