Security compliance for modular code
A catalog of pipelines for modular coding integrates resources for security compliance. The platform may incorporate tools and metadata for selecting suitable compliance standards and verifying security compliance for existing pipelines within the catalog as well as new pipelines created from existing pipelines.
1 . A computer program product comprising a non-transitory computer readable medium storing computer executable code that, when executing on one or more computing devices, causes the one or more computing devices to perform the steps of:
storing a catalog of pipelines, each of the pipelines executable on computing resources of an enterprise for performing security functions;
storing a description of a pipeline in the catalog of pipelines, the description including:
an identifier for the pipeline,
a version for the pipeline, and
a definition of the pipeline including one or more inputs to the pipeline, one or more outputs of the pipeline, and a graph of other pipelines from the catalog containing code segments used in the pipeline, the graph characterizing a location for accessing the code segments for each other one of the pipelines, a component security compliance of each other one of the pipelines, and a functional location of the code segments for each of the other pipelines in the pipeline;
evaluating a security compliance of the pipeline for execution in the enterprise based on security compliances for each of the other pipelines identified in the graph of the definition for the pipeline by performing the steps of:
traversing the graph for the pipeline to identify the component security compliance of each other one of the pipelines,
evaluating the component security compliance of each of the other pipelines identified in the graph based on a security compliance framework for the enterprise, thereby providing one or more evaluations of the component security compliance of each of the other pipelines identified in the graph, and
evaluating the security compliance of the pipeline based on the one or more evaluations of the component security compliance of each of the other pipelines identified in the graph; and
storing the security compliance in the description of the pipeline.
2 . The computer program product of claim 1 , wherein evaluating the component security compliance for at least one of the other pipelines includes verifying an operation of at least one of the code segments used in the at least one of the other pipelines.
3 . The computer program product of claim 1 , wherein evaluating the component security compliance for at least one of the other pipelines includes verifying a source of the at least one of the other pipelines from the catalog.
4 . The computer program product of claim 1 , wherein evaluating the component security compliance for at least one of the other pipelines includes verifying a source of at least one of the code segments used in the at least one of the other pipelines.
5 . The computer program product of claim 1 , wherein the component security compliance is based on an industry standard compliance framework.
6 . The computer program product of claim 1 , further comprising, when the security compliance of the pipeline fails to meet a predetermined condition, evaluating the security compliance independently from the component security compliance of each of the other pipelines.
7 . A method comprising:
storing a catalog of pipelines, each of the pipelines executable on computing resources of an enterprise for performing security functions;
storing a description of a pipeline in the catalog of pipelines, the description including:
an identifier,
a version, and
a definition including one or more inputs to the pipeline, one or more outputs of the pipeline, and a graph of other pipelines from the catalog containing resources used in the pipeline, the graph characterizing a location for accessing the resources for each other one of the pipelines, a component security compliance of each other one of the pipelines, one or more evaluations of the component security compliance of each other one of the pipelines in the definition, and a functional location of the resources for each of the other pipelines in the pipeline;
evaluating a security compliance of the pipeline for execution in the enterprise based on security compliances for each of the other pipelines identified in the graph of the definition for the pipeline by performing the steps of:
traversing the graph for the pipeline to identify the one or more evaluations of the component security compliance of each other one of the pipelines, and
evaluating the security compliance of the pipeline relative to a security compliance framework based on the one or more evaluations of the component security compliance of each of the other pipelines identified in the graph; and
storing the security compliance in the description of the pipeline.
8 . The method of claim 7 , wherein evaluating the security compliance includes verifying an operation of at least one of the resources used in the pipeline.
9 . The method of claim 7 , wherein evaluating the security compliance includes verifying a source of at least one of the other pipelines from the catalog containing resources used in the pipeline.
10 . The method of claim 7 , wherein evaluating the security compliance includes verifying a source of at least one of the resources used in the pipeline.
11 . The method of claim 7 , wherein the security compliance framework for the enterprise includes an industry standard compliance framework.
12 . The method of claim 7 , wherein the security compliance framework for the enterprise includes at least one security policy specified by an end user.
13 . The method of claim 7 , further comprising:
evaluating the component security compliance of each of the other pipelines in the pipeline based on the security compliance framework for the enterprise; and
evaluating the security compliance of the pipeline based on the component security compliance of each of the other pipelines.
14 . The method of claim 7 , further comprising verifying the security compliance of the pipeline independently from the component security compliance of each of the other pipelines.
15 . The method of claim 7 , wherein evaluating the security compliance of the pipeline includes verifying a digital signature for a source of the pipeline.
16 . The method of claim 7 , wherein evaluating the security compliance of the pipeline includes verifying a digital signature for a source of at least one of the other pipelines in the graph of other pipelines from the catalog.
17 . The method of claim 7 , wherein evaluating the security compliance of the pipeline includes verifying a digital signature for at least one of the resources used in the pipeline.
18 . A system comprising:
a data repository in a non-transitory physical memory, the data repository storing a catalog of pipelines for performing security functions;
a description of a pipeline stored as non-transitory information in the catalog of pipelines in the non-transitory physical memory of the data repository, each of the pipelines executable on computing resources of an enterprise, the description including:
an identifier for the pipeline,
a version for the pipeline,
a definition including one or more inputs to the pipeline, one or more outputs of the pipeline, and a graph of other pipelines from the catalog containing resources used in the pipeline, the graph characterizing a location for accessing the resources for each other one of the pipelines, a component security compliance of each other one of the pipelines, one or more evaluations of the component security compliance of each other one of the pipelines used in the pipeline, and a functional location of the resources for each of the other pipelines in the pipeline, and
a security compliance of the pipeline for execution in the enterprise based on the component security compliance for each of the other pipelines identified in the graph of the definition for the pipeline, wherein the security compliance of the pipeline is determined by performing the steps of:
evaluating the component security compliance of each other one of the pipelines in the definition based on a security compliance framework for the enterprise, and
evaluating the component security compliance of each of the other pipelines in the definition to a compliance framework for a user of the data repository; and
an integrated development environment executing on one or more processors, the integrated development environment configured by non-transitory computer executable code executing on the one or more processors to create and deploy an application using the catalog of pipelines, the integrated development environment including a user interface for selecting and arranging pipelines from the catalog into the application.
19 . The system of claim 18 , further comprising a search interface to the data repository, the search interface configured to support searches of the catalog for pipelines of interest.
20 . The system of claim 18 , wherein the data repository includes at least one of a cloud-based data repository and a federated data store.