all InfoSec news
Exploring Security Practices in Infrastructure as Code: An Empirical Study. (arXiv:2308.03952v1 [cs.CR])
cs.CR updates on arXiv.org arxiv.org
Cloud computing has become popular thanks to the widespread use of
Infrastructure as Code (IaC) tools, allowing the community to conveniently
manage and configure cloud infrastructure using scripts. However, the scripting
process itself does not automatically prevent practitioners from introducing
misconfigurations, vulnerabilities, or privacy risks. As a result, ensuring
security relies on practitioners understanding and the adoption of explicit
policies, guidelines, or best practices. In order to understand how
practitioners deal with this problem, in this work, we perform an …
cloud cloud computing cloud infrastructure code community computing iac infrastructure infrastructure as code manage misconfigurations popular practices privacy privacy risks process result risks scripting scripts security study tools vulnerabilities