{"id":17,"date":"2022-09-30T23:27:43","date_gmt":"2022-10-01T04:27:43","guid":{"rendered":"https:\/\/waratek.com\/?page_id=17"},"modified":"2022-10-26T17:37:57","modified_gmt":"2022-10-26T22:37:57","slug":"chapter-1-why-security-as-code","status":"publish","type":"page","link":"https:\/\/waratek.com\/security-as-code\/chapter-1-why-security-as-code\/","title":{"rendered":"Chapter 1: Why Security-as-Code"},"content":{"rendered":"<h2 id=\"anchor-1\">Why Security-as-Code?<\/h2>\n<p>Every major company, regardless of industry, is now in the software business. To remain competitive, companies are shipping code faster and faster using agile methodologies.<\/p>\n<p>While this increased development speed is excellent for engineering teams and profitable for companies, it&#8217;s unsustainable for Security teams.<\/p>\n<p>We live in a world where 84% of software exploits happen at the application layer. Yet we rely on vintage security techniques at the network layer to protect enterprise applications and the millions of users that use them.<\/p>\n<p>Whether your organization uses a WAF, RASP, or a combination of SAST, DAST, or IAST, the only reliable approach to address these vulnerabilities is to patch the codebase.<\/p>\n<p>Still, we make assumptions about risk in the form of heuristics that require a significant amount of manual investigation. In today&#8217;s fast-paced world, where enterprises deploy code multiple times a day, Security teams must keep pace with each deployment where each code change can introduce new and previously patched vulnerabilities.<\/p>\n<p>Three factors make this increased speed unsustainable for Security teams:<\/p>\n<ol>\n<li>Fixing vulnerabilities is manual<\/li>\n<li>Existing tooling adds noise rather than value<\/li>\n<li>Code changes lead to vulnerability regressions<\/li>\n<\/ol>\n<p>Security-as-Code aims to fix these issues and enable Security to scale with modern software development.<\/p>\n<nav class=\"sidenav\"><ul><li><a href=\"https:\/\/waratek.com\/security-as-code\/chapter-2-security-as-code-basics\/\">Chapter 2: Security-as-Code Basics<\/a><\/li><li><a href=\"https:\/\/waratek.com\/security-as-code\/chapter-3-declarative-and-immutable-security-as-code\/\">Chapter 3: Declarative and Immutable Security-as-Code<\/a><\/li><li><a href=\"https:\/\/waratek.com\/security-as-code\/chapter-4-imperative-and-instant-security-as-code\/\">Chapter 4: Imperative and Instant Security-as-Code<\/a><\/li><\/ul><\/nav>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"Companies are shipping code faster using agile methodology. This increased speed is good for engineering teams &#038; companies but unsustainable for Security teams.","protected":false},"author":1,"featured_media":43,"parent":16,"menu_order":1,"comment_status":"closed","ping_status":"closed","template":"template-chapter.blade.php","meta":{"footnotes":"","_links_to":"","_links_to_target":""},"class_list":["post-17","page","type-page","status-publish","has-post-thumbnail","hentry"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v24.7 (Yoast SEO v25.4) - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Chapter 1: Why Security-as-Code | Waratek<\/title>\n<meta name=\"description\" content=\"Companies are shipping code faster using agile methodology. This increased speed is good for companies but unsustainable for Security teams.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/waratek.com\/security-as-code\/chapter-1-why-security-as-code\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Chapter 1: Why Security-as-Code | Waratek\" \/>\n<meta property=\"og:description\" content=\"Companies are shipping code faster using agile methodology. This increased speed is good for engineering teams &amp; companies but unsustainable for Security teams.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/waratek.com\/security-as-code\/chapter-1-why-security-as-code\/\" \/>\n<meta property=\"og:site_name\" content=\"Waratek\" \/>\n<meta property=\"article:modified_time\" content=\"2022-10-26T22:37:57+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/waratek.com\/wp-content\/uploads\/2022\/10\/thumbnail-chapter-1.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t<meta property=\"og:image:height\" content=\"630\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:site\" content=\"@waratek\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"1 minute\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/waratek.com\/security-as-code\/chapter-1-why-security-as-code\/\",\"url\":\"https:\/\/waratek.com\/security-as-code\/chapter-1-why-security-as-code\/\",\"name\":\"Chapter 1: Why Security-as-Code | Waratek\",\"isPartOf\":{\"@id\":\"https:\/\/waratek.com\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/waratek.com\/security-as-code\/chapter-1-why-security-as-code\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/waratek.com\/security-as-code\/chapter-1-why-security-as-code\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/waratek.com\/wp-content\/uploads\/2022\/10\/thumbnail-chapter-1.png\",\"datePublished\":\"2022-10-01T04:27:43+00:00\",\"dateModified\":\"2022-10-26T22:37:57+00:00\",\"description\":\"Companies are shipping code faster using agile methodology. This increased speed is good for companies but unsustainable for Security teams.\",\"breadcrumb\":{\"@id\":\"https:\/\/waratek.com\/security-as-code\/chapter-1-why-security-as-code\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/waratek.com\/security-as-code\/chapter-1-why-security-as-code\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/waratek.com\/security-as-code\/chapter-1-why-security-as-code\/#primaryimage\",\"url\":\"https:\/\/waratek.com\/wp-content\/uploads\/2022\/10\/thumbnail-chapter-1.png\",\"contentUrl\":\"https:\/\/waratek.com\/wp-content\/uploads\/2022\/10\/thumbnail-chapter-1.png\",\"width\":1200,\"height\":630},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/waratek.com\/security-as-code\/chapter-1-why-security-as-code\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/waratek.com\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Security-as-Code: How to with Modern Development\",\"item\":\"https:\/\/waratek.com\/security-as-code\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Chapter 1: Why Security-as-Code\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/waratek.com\/#website\",\"url\":\"https:\/\/waratek.com\/\",\"name\":\"Waratek\",\"description\":\"Just another WordPress site\",\"publisher\":{\"@id\":\"https:\/\/waratek.com\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/waratek.com\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/waratek.com\/#organization\",\"name\":\"Waratek\",\"url\":\"https:\/\/waratek.com\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/waratek.com\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/waratek.com\/wp-content\/uploads\/2022\/10\/logo-dark-small.png\",\"contentUrl\":\"https:\/\/waratek.com\/wp-content\/uploads\/2022\/10\/logo-dark-small.png\",\"width\":150,\"height\":31,\"caption\":\"Waratek\"},\"image\":{\"@id\":\"https:\/\/waratek.com\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/x.com\/waratek\",\"https:\/\/www.linkedin.com\/company\/waratek-ltd\"]}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Chapter 1: Why Security-as-Code | Waratek","description":"Companies are shipping code faster using agile methodology. This increased speed is good for companies but unsustainable for Security teams.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/waratek.com\/security-as-code\/chapter-1-why-security-as-code\/","og_locale":"en_US","og_type":"article","og_title":"Chapter 1: Why Security-as-Code | Waratek","og_description":"Companies are shipping code faster using agile methodology. This increased speed is good for engineering teams & companies but unsustainable for Security teams.","og_url":"https:\/\/waratek.com\/security-as-code\/chapter-1-why-security-as-code\/","og_site_name":"Waratek","article_modified_time":"2022-10-26T22:37:57+00:00","og_image":[{"width":1200,"height":630,"url":"https:\/\/waratek.com\/wp-content\/uploads\/2022\/10\/thumbnail-chapter-1.png","type":"image\/png"}],"twitter_card":"summary_large_image","twitter_site":"@waratek","twitter_misc":{"Est. reading time":"1 minute"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/waratek.com\/security-as-code\/chapter-1-why-security-as-code\/","url":"https:\/\/waratek.com\/security-as-code\/chapter-1-why-security-as-code\/","name":"Chapter 1: Why Security-as-Code | Waratek","isPartOf":{"@id":"https:\/\/waratek.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/waratek.com\/security-as-code\/chapter-1-why-security-as-code\/#primaryimage"},"image":{"@id":"https:\/\/waratek.com\/security-as-code\/chapter-1-why-security-as-code\/#primaryimage"},"thumbnailUrl":"https:\/\/waratek.com\/wp-content\/uploads\/2022\/10\/thumbnail-chapter-1.png","datePublished":"2022-10-01T04:27:43+00:00","dateModified":"2022-10-26T22:37:57+00:00","description":"Companies are shipping code faster using agile methodology. This increased speed is good for companies but unsustainable for Security teams.","breadcrumb":{"@id":"https:\/\/waratek.com\/security-as-code\/chapter-1-why-security-as-code\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/waratek.com\/security-as-code\/chapter-1-why-security-as-code\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/waratek.com\/security-as-code\/chapter-1-why-security-as-code\/#primaryimage","url":"https:\/\/waratek.com\/wp-content\/uploads\/2022\/10\/thumbnail-chapter-1.png","contentUrl":"https:\/\/waratek.com\/wp-content\/uploads\/2022\/10\/thumbnail-chapter-1.png","width":1200,"height":630},{"@type":"BreadcrumbList","@id":"https:\/\/waratek.com\/security-as-code\/chapter-1-why-security-as-code\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/waratek.com\/"},{"@type":"ListItem","position":2,"name":"Security-as-Code: How to with Modern Development","item":"https:\/\/waratek.com\/security-as-code\/"},{"@type":"ListItem","position":3,"name":"Chapter 1: Why Security-as-Code"}]},{"@type":"WebSite","@id":"https:\/\/waratek.com\/#website","url":"https:\/\/waratek.com\/","name":"Waratek","description":"Just another WordPress site","publisher":{"@id":"https:\/\/waratek.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/waratek.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/waratek.com\/#organization","name":"Waratek","url":"https:\/\/waratek.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/waratek.com\/#\/schema\/logo\/image\/","url":"https:\/\/waratek.com\/wp-content\/uploads\/2022\/10\/logo-dark-small.png","contentUrl":"https:\/\/waratek.com\/wp-content\/uploads\/2022\/10\/logo-dark-small.png","width":150,"height":31,"caption":"Waratek"},"image":{"@id":"https:\/\/waratek.com\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/waratek","https:\/\/www.linkedin.com\/company\/waratek-ltd"]}]}},"_links":{"self":[{"href":"https:\/\/waratek.com\/wp-json\/wp\/v2\/pages\/17","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/waratek.com\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/waratek.com\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/waratek.com\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/waratek.com\/wp-json\/wp\/v2\/comments?post=17"}],"version-history":[{"count":0,"href":"https:\/\/waratek.com\/wp-json\/wp\/v2\/pages\/17\/revisions"}],"up":[{"embeddable":true,"href":"https:\/\/waratek.com\/wp-json\/wp\/v2\/pages\/16"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/waratek.com\/wp-json\/wp\/v2\/media\/43"}],"wp:attachment":[{"href":"https:\/\/waratek.com\/wp-json\/wp\/v2\/media?parent=17"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}