iac
2 posts · all writing
A misconfiguration has no CVSS, which is why nobody fixes it
A privileged pod and a public S3 bucket have no CVE, no CVSS score and no NVD entry, so every IaC tool invents its own severity, and findings that would be a breach get sorted below dependency CVEs that are unreachable. Why misconfiguration findings get ignored, and what to rank them by instead.
You don't need twelve scanners, you need to know which four apply
Security tooling is usually adopted in one of two ways: nothing, or everything at once. Both fail for the same reason. Nobody decided which controls the thing you actually build requires. A short way to work that out from what your software is made of.