Chef Advances Security Capabilities
March 13, 2019

Chef announced the achievement of three significant security milestones, helping its government and enterprise customers ensure that they can achieve and maintain the secure infrastructure needed to accelerate their cloud strategies.

These include Secure Technical Implementation Guidelines (STIG) profiles for RHEL 7 and Windows Server 2016 in Chef InSpec, along with FIPS 140-2 compliance and Center for Internet Security (CIS) certification for AWS Foundations Benchmarks Level 1 and 2 in Chef Automate. Chef is the first CIS partner to achieve certification across AWS, Microsoft Azure and Google Cloud Platform, giving its customers maximum flexibility when choosing and securing cloud platforms.

Chef has worked closely with federal, government and enterprise organizations to automate the way they build and manage their infrastructure and enable compliance as code. The capacity to not only automate configuration but also ensure compliance and remediate vulnerabilities, is critical to automating infrastructure, particularly in highly-regulated industries.

Chef InSpec incorporates compliance processes into every stage of users’ development cycles, significantly mitigating these concerns. Chef and Chef InSpec enable continuous compliance by allowing customers to automatically resolve potential compliance issues without human intervention.

Cloud platforms offer easy-to-use resources for configuring access control, data storage and virtual networking, giving organizations the tools to scale their environments quickly. But with these new tools come new guidelines and best practices for securing them properly. STIG profiles let Chef customers determine whether their cloud implementations meet the requirements outlined within the benchmarks and provide actionable insights regarding where insecure configurations are found. New CIS benchmarks deliver prescriptive implementation criteria for each cloud provider, while FIPS compliance enables government organizations to take maximum advantage of InSpec compliance automation at scale.

“The security milestones announced today give our customers the tools and the confidence they need to accelerate their most critical cloud initiatives,” said John Snow, Senior Software Development Engineer and Federal Content Lead at Chef. “This work builds on our long history of close collaboration with government users and the organizations that support them, furthering our ongoing commitment to provide the most innovative and easy-to-use application delivery and compliance automation solutions available to organizations of all types.”

Share this

Industry News

April 18, 2024

SmartBear announced a new version of its API design and documentation tool, SwaggerHub, integrating Stoplight’s API open source tools.

April 18, 2024

Red Hat announced updates to Red Hat Trusted Software Supply Chain.

April 18, 2024

Tricentis announced the latest update to the company’s AI offerings with the launch of Tricentis Copilot, a suite of solutions leveraging generative AI to enhance productivity throughout the entire testing lifecycle.

April 17, 2024

CIQ launched fully supported, upstream stable kernels for Rocky Linux via the CIQ Enterprise Linux Platform, providing enhanced performance, hardware compatibility and security.

April 17, 2024

Redgate launched an enterprise version of its database monitoring tool, providing a range of new features to address the challenges of scale and complexity faced by larger organizations.

April 17, 2024

Snyk announced the expansion of its current partnership with Google Cloud to advance secure code generated by Google Cloud’s generative-AI-powered collaborator service, Gemini Code Assist.

April 16, 2024

Kong announced the commercial availability of Kong Konnect Dedicated Cloud Gateways on Amazon Web Services (AWS).

April 16, 2024

Pegasystems announced the general availability of Pega Infinity ’24.1™.

April 16, 2024

Sylabs announces the launch of a new certification focusing on the Singularity container platform.

April 15, 2024

OpenText™ announced Cloud Editions (CE) 24.2, including OpenText DevOps Cloud and OpenText™ DevOps Aviator.

April 15, 2024

Postman announced its acquisition of Orbit, the community growth platform for developer companies.

April 11, 2024

Check Point® Software Technologies Ltd. announced new email security features that enhance its Check Point Harmony Email & Collaboration portfolio: Patented unified quarantine, DMARC monitoring, archiving, and Smart Banners.

April 11, 2024

Automation Anywhere announced an expanded partnership with Google Cloud to leverage the combined power of generative AI and its own specialized, generative AI automation models to give companies a powerful solution to optimize and transform their business.

April 11, 2024

Jetic announced the release of Jetlets, a low-code and no-code block template, that allows users to easily build any technically advanced integration use case, typically not covered by alternative integration platforms.

April 10, 2024

Progress announced new powerful capabilities and enhancements in the latest release of Progress® Sitefinity®.