ISO 27001 Readiness: Platform & Pipeline Security
Platform and pipeline security for a B2B payments platform
Overview
A B2B payments platform processing transactions for enterprise clients was preparing for ISO 27001 certification with unresolved security findings across its software delivery lifecycle. The platform lacked automated security controls in the CI/CD pipeline, had no policy enforcement on Kubernetes, handled secrets inconsistently across environments, and applied infrastructure changes manually. The engagement covered remediating those findings on AWS, introducing a Terraform deployment pipeline and FluxCD based GitOps delivery, and automating the evidence needed for the in scope Annex A.8 controls.
Problems
No security gates in the delivery pipeline, and container images deployed without scanning
Kubernetes workloads running without admission controls or policy enforcement
Secrets handled manually across environments, with no rotation or access policies
Infrastructure and cluster changes applied manually, leading to inconsistency between environments
Audit evidence produced by hand, with no repeatable process
Goals
Embed automated security controls directly into the CI/CD pipeline
Enforce policy at admission across all Kubernetes workloads
Centralise secrets management with dynamic credentials and rotation
Provision infrastructure through a Terraform pipeline and deliver changes via GitOps, so every change is versioned, reviewed and traceable
Automate audit evidence collection mapped to the in scope ISO 27001 Annex A.8 controls
What Was Done
Enforced security gates in the delivery pipeline covering SAST results, container image scanning and dependency analysis, blocking on agreed severity thresholds
Deployed OPA Gatekeeper for policy enforcement across Kubernetes workloads
Migrated secrets management to HashiCorp Vault with dynamic credentials and rotation policies
Built a Terraform deployment pipeline for repeatable, reviewed infrastructure changes on AWS
Introduced FluxCD based GitOps delivery so cluster changes go through Git review
Built automated audit evidence collection mapped to the in scope Annex A.8 controls
Results and Impact
Critical SDLC findings remediated across the full delivery lifecycle
Automated security gates operational across all pipelines
Infrastructure and cluster changes flowing through version control, with drift between environments removed
Machine readable audit evidence produced for the in scope Annex A.8 controls
Stack
