• Home
  • >
  • DevOps News
  • >
  • SaltStack Expands into Security Compliance Scanning and Remediation – InApps Technology 2025

SaltStack Expands into Security Compliance Scanning and Remediation – InApps Technology is an article under the topic Devops Many of you are most interested in today !! Today, let’s InApps.net learn SaltStack Expands into Security Compliance Scanning and Remediation – InApps Technology in today’s post !

Key Summary

This article from InApps Technology, authored by Phu Nguyen, discusses the introduction of SaltStack SecOps, a new feature for SaltStack Enterprise unveiled at SaltConf18 in Salt Lake City. It enhances the configuration management software with security compliance scanning and automated remediation capabilities, aiming to alleviate “audit hell” for operations teams. Key points include:

  • SaltStack SecOps Overview:
    • Purpose: Extends SaltStack Enterprise to include auditing and instant remediation of configuration errors and vulnerabilities, addressing user demand for integrated security features.
    • Availability: Set for general release in early 2019.
  • Problem Addressed:
    • Traditional security scanning tools (e.g., from security providers) identify misconfigured machines but require manual remediation, creating a time-consuming bottleneck for DevOps teams.
    • Misconfigurations can serve as entry points for malicious attacks, necessitating robust compliance checks.
  • Key Features:
    • Automated Discovery and Remediation: Leverages Salt’s advanced targeting to scan thousands of machines and instantly fix configuration issues or generate reports for scheduled fixes (e.g., during off-hours).
    • Compliance Standards: Uses settings from CIS, DISA STIGs, and NIST, covering checks like disabling telnet ports or setting user access permissions. Users can also define custom checks.
    • Execution: Performed by Salt Minions (agents on managed machines), supporting major Linux, Unix, and Windows distributions.
    • Management: Configurations stored in-house and on a public repository (likely GitHub).
  • Advantages:
    • Eliminates manual remediation processes, reducing late nights and weekends for operations teams.
    • Integrates seamlessly with automated DevOps workflows, minimizing bottlenecks.
    • Offers flexibility with both predefined and custom compliance checklists.
  • Future Plans:
    • Initially focused on configuration settings, with potential expansion to patch management and vulnerability remediation.
  • InApps Insight:
    • InApps Technology leverages tools like SaltStack for efficient DevOps and security solutions, integrating React Native, ReactJS, Microsoft’s Power Platform, and Azure, using Power Fx for low-code solutions and Azure Durable Functions for scalable workflows.
    • Combines Node.js, Vue.js, GraphQL APIs (e.g., Apollo), and Azure to deliver secure, automated solutions, targeting startups and enterprises with Millennial-driven expectations.
Read More:   Debug Clusters in 8 Commands – InApps 2022

Read more about SaltStack Expands into Security Compliance Scanning and Remediation – InApps Technology at Wikipedia

You can find content about SaltStack Expands into Security Compliance Scanning and Remediation – InApps Technology from the Wikipedia website

SaltStack wants to save operations folk from “audit hell.”

A new feature of the company’s flagship configuration management software Saltstack Enterprise will include capabilities for auditing and instant remediation of configuration errors and vulnerabilities.

SaltStack debuted SaltStack SecOps, which will become generally available early next year, at the company’s annual user conference, SaltConf18, being held in Salt Lake City this week.

The feature came about as a result of getting a lot of questions from users about how to extend the Salt configuration management software to also encompass security, noted Alex Peay, SaltStack vice president of product.

An increasing number of organizations have been using scanning assessment tools from security providers. Such tools typically can scan a set of machines to ensure they are configured correctly, and issue a report listing the machines that failed the audit, and what the specific issues are. An incorrectly configured machine can offer malicious attackers and entry point to do damage.

“We approach this problem differently than all the other assessment tools out there,” Peay said, noting that it takes advantage of Salt’s complex targeting capabilities to offer a fully automated discovery and instant remediation service, a first for both configuration management and security compliance software.

While existing services from the security companies can help in meeting external or internal security and compliance requirements, they pose a challenge for operations teams, who must fix the troubled computers after a scan and rerun the scan, Peay explained. Sometimes the machine can be fixed through a tool such as SaltStack’s, or by manual scripts. But the task of moving the list of issues into a remediation process is a manual — and time-consuming — one.

Read More:   Update The Open Source and Cloud Symbiosis

“It leads to a lot of late nights and weekends,” said Peay. And for an organization moving to an automated DevOps process, remediation can be a serious bottleneck.

SaltStack automates the process of discovery and remediation. The software can check thousands of machines, and, if configuration errors are found, immediately fix them. Or, it can generate a report, allowing the administrator to set a time to fix them (during off-hours, for instance).

Initially, SaltStack will use desired configuration settings from the Center for Information Security (CIS), the U.S. Defense Information Agency’s Security Technical Implementation Guides (DISA STIGS), and the National Institute of Standards and Technology (NIST). Such guides have thousands of checks for operating systems, ranging from shutting down a telnet port to defining settings that guide user access permissions. Users can also define their own checks, and use a mixture of external and internal compliance checklists.

Such a remediation service can be easily executed by Salt Minions, the agents installed on each Salt-controlled machine. The service will initially support most widely used Linux and Unix distributions, as well as recent editions of Windows. The configurations will be managed in-house and kept on a public repository (likely GitHub).

Initially, SaltStack SecOps will focus on configuration settings, though over time it may include other security needs, such as patch management and vulnerability remediation, Peay said.

 

Rate this post
As a Senior Tech Enthusiast, I bring a decade of experience to the realm of tech writing, blending deep industry knowledge with a passion for storytelling. With expertise in software development to emerging tech trends like AI and IoT—my articles not only inform but also inspire. My journey in tech writing has been marked by a commitment to accuracy, clarity, and engaging storytelling, making me a trusted voice in the tech community.

Let’s create the next big thing together!

Coming together is a beginning. Keeping together is progress. Working together is success.

Let’s talk

Get a custom Proposal

Please fill in your information and your need to get a suitable solution.

    You need to enter your email to download

      Success. Downloading...