Security scanning of infrastructure-as-code templates is formally required before deployment
Sekit's IaC scanning policy, one of the topic-specific policies A.5.1 expects, requires infrastructure-as-code templates to pass a security scan before they are deployed.
This policy facet requires infrastructure-as-code templates to pass a security scan before deployment, extending A.8.25's lifecycle discipline to infrastructure definitions.
Requiring infrastructure-as-code templates to pass a security scan before deployment prevents misconfiguration before it reaches the environment A.8.9 is meant to protect.