← Back
ISO 27001 Readiness: Platform & Pipeline Security
Fintech

ISO 27001 Readiness: Platform & Pipeline Security

Platform and pipeline security for a B2B payments platform

Overview

A B2B payments platform processing transactions for enterprise clients was preparing for ISO 27001 certification with unresolved security findings across its software delivery lifecycle. The platform lacked automated security controls in the CI/CD pipeline, had no policy enforcement on Kubernetes, handled secrets inconsistently across environments, and applied infrastructure changes manually. The engagement covered remediating those findings on AWS, introducing a Terraform deployment pipeline and FluxCD based GitOps delivery, and automating the evidence needed for the in scope Annex A.8 controls.

Problems

No security gates in the delivery pipeline, and container images deployed without scanning

Kubernetes workloads running without admission controls or policy enforcement

Secrets handled manually across environments, with no rotation or access policies

Infrastructure and cluster changes applied manually, leading to inconsistency between environments

Audit evidence produced by hand, with no repeatable process

Goals

Embed automated security controls directly into the CI/CD pipeline

Enforce policy at admission across all Kubernetes workloads

Centralise secrets management with dynamic credentials and rotation

Provision infrastructure through a Terraform pipeline and deliver changes via GitOps, so every change is versioned, reviewed and traceable

Automate audit evidence collection mapped to the in scope ISO 27001 Annex A.8 controls

What Was Done

01

Enforced security gates in the delivery pipeline covering SAST results, container image scanning and dependency analysis, blocking on agreed severity thresholds

02

Deployed OPA Gatekeeper for policy enforcement across Kubernetes workloads

03

Migrated secrets management to HashiCorp Vault with dynamic credentials and rotation policies

04

Built a Terraform deployment pipeline for repeatable, reviewed infrastructure changes on AWS

05

Introduced FluxCD based GitOps delivery so cluster changes go through Git review

06

Built automated audit evidence collection mapped to the in scope Annex A.8 controls

Results and Impact

Critical SDLC findings remediated across the full delivery lifecycle

Automated security gates operational across all pipelines

Infrastructure and cluster changes flowing through version control, with drift between environments removed

Machine readable audit evidence produced for the in scope Annex A.8 controls

Stack

AWSKubernetesTerraformGitLab CIFluxCDTrivyOPA GatekeeperVault