FREE RESOURCE · CI/CD SECURITY
SecOps Baseline for CI/CD Pipelines
A triage checklist and starter script to find common CI/CD pipeline risks before the next release.
- Checks6supply chain · secrets · containers · IaC
- FormatPDFchecklist and triage script
- PriceFreedownload unlocked after submit
§01Baselinegithub.com/OkamiOps/secops-baseline
SecOps checklist for CI/CD in SMBs
The baseline covers controls that appear early in any AppSec journey: dependencies, secrets, containers, IaC and auditable evidence.
- Supply chain — SCA, lockfiles, critical packages and risk signals in the build flow.
- Secrets and credentials — finds tokens, keys and credentials before they enter a release.
- Containers and filesystem — flags high and critical issues in images, project files and local dependencies.
- IaC and permissions — creates a path to review Terraform, Kubernetes and sensitive permissions.
- AppSec evidence — guides storage of SARIF, JSON and logs for OWASP SAMM, ISO 27001 and audits.
- Next control — shows where the pipeline needs ongoing consulting with ownership and metrics.
When to call the consulting team
If the baseline becomes noise, recurring risk appears or nobody owns remediation, the problem is no longer tooling. It is AppSec maturity, Secure SDLC and OWASP SAMM.