Hybrid cloud platform vendor builds security into every release
The maker of a popular hybrid cloud management platform needed dynamic scanning woven into a mission-critical SDLC. Winmill made security part of the release cycle, not an interruption to it.
A structured remediation workflow developers actually use
A secure development lifecycle on industry standards
The project
This client created one of the most popular automation platforms for managing hybrid cloud and application infrastructures. When it needed Invicti integrated into a mission-critical software development lifecycle, it called Winmill. Winmill helped the team create initial scan profiles, build URL rewrite rules for front-facing pages and API endpoints, execute and monitor scans, review results, and set the remediation path.
The challenges
Segment a sprawling platform. The application platform needed a segmentation strategy that gave visibility and control over each individual segment, reduced scan times, and enabled faster analysis and reporting.
Shorten feedback loops. Findings had to reach the right people quickly, with vulnerability assessments feeding the merge-approval process to determine when a change needs a security review.
Developer independence. Developers needed to run scans without engaging the security team, with results flowing into Pivotal Tracker.
The solution
Winmill began by reviewing the front-facing functionality and the publicly available API endpoint definitions, then created Invicti scan profiles optimized for the assets under test, using regular expression rules and URL rewrite rules to sharpen coverage.
Through each release cycle, Winmill worked in regular communication with the client’s security team and IT managers: reviewing and triaging scan results, making sure only confirmed and actionable issues entered the development workflow, and documenting each item in Pivotal Tracker with its Common Weakness Enumeration, affected paths, and CVSS score. Winmill also maintained the monthly release notes shared with the platform’s end users.
Winmill then added software composition analysis, evaluating results, assessing risk, and folding newly vulnerable libraries into the regular reporting cycle. An automation script now invokes the SCA scans and downloads vulnerable library information for immediate remediation by the security team.
The results
A secure SDLC on industry standards. Invicti is incorporated into an automated development lifecycle based on industry best practices, supporting secure DevOps with automated scanning and informed assessment of results.
A structured remediation workflow. Actionable security flaws are reviewed, assessed, and mitigated through a defined process instead of ad hoc handoffs.
“Winmill’s team played a critical role in the success of our ongoing secure release cycles. We were able to readily triage scan results, suppress false positives and assign actionable vulnerabilities to our technical team for further review using a highly optimized process. This enabled us to release critical updates on time to meet our customer’s needs. This has been a game changer!”
Security team, hybrid cloud platform vendor
Is security part of your release, or a scramble before it?
Tell us what you’re building and we’ll connect you with the engineers who integrate security into development pipelines every day.