---
title: "SecOps Baseline for CI/CD Pipelines - OkamiOps"
description: "Download a free checklist and starter script for CI/CD risks: SCA, secrets, containers, IaC and AppSec evidence."
url: https://okamiops.com/materiais/baseline-secops-ci-cd/
lang: en
alternates:
  en: https://okamiops.com/materiais/baseline-secops-ci-cd/
  pt-BR: https://okamiops.com/pt/materiais/baseline-secops-ci-cd/
  de: https://okamiops.com/de/materiais/baseline-secops-ci-cd/
  x-default: https://okamiops.com/materiais/baseline-secops-ci-cd/
lastmod: 2026-09-10
---

# SecOps Baseline for CI/CD Pipelines

FREE RESOURCE · CI/CD SECURITY

A triage checklist and starter script to find common CI/CD pipeline risks before the next release.

- [Get the baseline](https://okamiops.com/materiais/baseline-secops-ci-cd/#download)
- [See checks](https://okamiops.com/materiais/baseline-secops-ci-cd/#verifica)

- **Checks**: 6 supply chain · secrets · containers · IaC
- **Format**: PDF checklist and triage script
- **Price**: Free download unlocked after submit

## SecOps checklist for CI/CD in SMBs

The baseline covers controls that appear early in any AppSec journey: dependencies, secrets, containers, IaC and auditable evidence.

// what the SecOps baseline checks

- Supply chain — SCA, lockfiles, critical packages and risk signals in the build flow.
- Secrets and credentials — finds tokens, keys and credentials before they enter a release.
- Containers and filesystem — flags high and critical issues in images, project files and local dependencies.
- IaC and permissions — creates a path to review Terraform, Kubernetes and sensitive permissions.
- AppSec evidence — guides storage of SARIF, JSON and logs for OWASP SAMM, ISO 27001 and audits.
- Next control — shows where the pipeline needs ongoing consulting with ownership and metrics.

A first line of defense for teams that do not have a formal Secure SDLC yet.

## When to call the consulting team

If the baseline becomes noise, recurring risk appears or nobody owns remediation, the problem is no longer tooling. It is AppSec maturity, Secure SDLC and OWASP SAMM.

- [Talk to consulting](https://okamiops.com/servicos/consultoria/)
