Skip to main content

07 - References, Standards and Tooling Index

To support continuous learning and production implementation of Infrastructure as Code (IaC) security, this chapter provides a curated index of industry standards, regulatory frameworks, open-source security tools, and official cloud provider documentation.


📚 Industry Standards & Security Frameworks

Center for Internet Security (CIS) Benchmarks

The CIS Benchmarks serve as the global consensus standard for hardening cloud environments and IaC configurations:

NIST SP 800-53 Rev. 5 Security Controls

Key controls mapped to Infrastructure as Code security implementation:

  • CM-2 (Baseline Configuration): Maintaining documented, version-controlled IaC baselines.
  • CM-6 (Configuration Settings): Mandatory automated scanning of IaC parameters prior to deployment.
  • SA-11 (Developer Testing and Evaluation): Integrating SAST and Policy as Code into CI/CD pipelines.
  • SC-28 (Protection of Information at Rest): Enforcing KMS key encryption for state storage and cloud data stores.

OWASP & US Government Guidance


🛠️ Security Tools & Open-Source Projects

Static Application Security Testing (SAST)

Policy as Code Engines

Drift Detection & Cloud Compliance


📖 Official IaC Engine & Cloud Provider Documentation

HashiCorp Terraform

AWS CloudFormation

Azure Bicep & ARM


🔬 Academic & Technical Literature

  • A Analysis of Infrastructure as Code Misconfigurations in Cloud Ecosystems (IEEE Transactions on Software Engineering, 2022)
  • Automated Verification of Static Security Policies in Declarative Infrastructure Templates (ACM Symposium on Cloud Computing)
  • Shifting Cloud Infrastructure Security Left: Empirical Evaluation of Static Analysis Tools on Production Terraform Code (Journal of Cybersecurity and Privacy)

[!NOTE] Continuous Learning: Security rules and cloud provider capabilities evolve rapidly. Regularly update local SAST scanners (Checkov, tfsec) and policy libraries to ensure protection against emerging cloud vulnerability vectors.

Share this guide