I will begin the talk with discussing the role of Policy-as-Code in enhancing the security of modern application stacks, and how it can be used to enforce compliance, automate security processes, and improve overall security posture. Policy-as-Code is a powerful approach to defining and enforcing security policies and practices in an automated and consistent way. By using code to define and enforce policies, organizations can ensure that their security practices are consistently applied and maintained over time. This can help to prevent errors and mistakes that can compromise security, and can make it easier to detect and respond to potential security threats. In this talk, I will provide an overview of Policy-as-Code and how it can be used to improve stack security, starting from the bottom of your stack - the Infrastructure layer and climbing up to the top with policy as code as part of the Application layer.
Session 🗣 Intermediate ⭐⭐ Track: Native Languages (Rust, Go lang, C++, C#, .Net, ...)
Policy-as-Code
Stack Security
Compliance
Automation
Security posture
Consistency
Prevention
Detection
Response
Stack improvement
Infrastructure
Application layer
Best practices
Open-source tools
Kubernetes
GitOps
Everything-as-code
DevOps.