CI/CD Compliance
CI/CD compliance ensures adherence to industry standards: CIS GitLab/GitHub and OWASP Top 10.
Cortex Cloud CI/CD compliance focuses on the security posture of your delivery pipelines and version control systems. It detects misconfigurations, such as insecure branch protections or permissive runner access, that violate software supply chain security benchmarks
Supported standards: Cortex Cloud supports compliance checks against the CIS GitLab Benchmark v1.0.1, CIS GitHub Benchmark v1.0.0, and the OWASP Top 10 CI/CD Risks v2025.
Scope of checks:
Pipeline risks: Poisoned Pipeline Execution (PPE), insecure configurations
VCS security: Repository permissions, branch protection, access controls
Build security: Supply chain risks, credential management.
Create CI/CD compliance reports
The following steps describe the workflow for creating CI/CD compliance reports.
Step
Description
Step 1. Create an Asset Group.
Step 2. Create an Assessment Profile.
Step 3. View reports.
Create an Asset Group
Create an asset group to define a logical collection of your CI/CD assets (such as specific repositories or pipelines within a provider like GitHub). This step scopes your security assessments, ensuring that subsequent compliance checks and scans performed by an assessment profile are applied to the relevant resources.
Navigate to Inventory → Groups → + Add Group.
On the Create New Assets Group screen:
Provide a group name (required) and description.
Select Create Dynamic Group, or select assets from the list that is displayed, and click Create Static Group.
Note
For more information about about Asset Groups, refer to Asset groups.
Create an Assessment Profile
Create an assessment profile, which configures the specific security standards and initiates the scans against the assets defined in your asset group.
Navigate to Posture Management → Compliance → Assessment Profiles → Create New Assessment.
On the General step of the wizard.
Provide a profile name (required) and description (optional), and select Generate a scheduled report.
Specify the email recipients for the report.
Set the Evaluation frequency (required).
Click Next.
Review the details on the Summary step of the wizard and click Create.
Note
For more information about assessment profiles, refer to Use an assessment profile to run compliance checks on your assets.
View and access reports
The email recipients defined in the assessment profile will receive the compliance report.
To view the compliance scan results:
Navigate to Posture Management → Compliance → Reports.
For more information about compliance assessment reports, refer to View and manage compliance assessments and reports.
Last updated
Was this helpful?
