DevSecOps CI/CD Pipeline Security Checklist

This DevSecOps CI/CD pipeline security checklist ensures compliance with NIST SP 800-218 Secure Software Development Framework (SSDF), SLSA Framework v1.0 Supply Chain Levels, CISA Software Supply Chain Security Guidance, and Executive Order 14028 software security requirements. Designed for DevSecOps teams to embed security into every stage of the delivery pipeline.

  • Industry: Telecommunications & IT
  • Frequency: Per Release / Quarterly Review
  • Estimated Time: 30-45 minutes
  • Role: DevSecOps Engineer / Application Security Lead
  • Total Items: 13
  • Compliance: NIST SP 800-218 Secure Software Development Framework (SSDF), SLSA Framework v1.0 Supply Chain Levels for Software Artifacts, OWASP Top 10 CI/CD Security Risks (2022), CISA Software Supply Chain Security Guidance, EO 14028 Improving Nation's Cybersecurity - Software Security

Source Code Security

SAST, secrets detection, and code review requirements.

  • SAST (Static Analysis) runs on every pull request and blocks merges with critical findings?
  • Secrets/credential scanning (GitGuardian/Gitleaks/TruffleHog) active on all repos?
  • Mandatory peer code review required before merging to main/protected branches?
  • Branch protection rules: signed commits, PR reviews, no force-push on main?

Dependency and Supply Chain Security

SCA scanning, SBOM generation, and dependency pinning.

  • Software Composition Analysis (SCA) scanning all third-party dependencies?
  • Critical/High CVEs in dependencies block the build pipeline?
  • SBOM (Software Bill of Materials) generated per release (SPDX or CycloneDX)?
  • Third-party actions/images pinned to exact SHA digest (not floating tags)?

Build and Artifact Integrity

Build provenance, signing, and artifact verification.

  • Build provenance attestations generated for all artifacts (SLSA Level 2+)?
  • Container images and binaries signed with Cosign/Sigstore or GPG?
  • IaC security scanning (Checkov/tfsec/Trivy) on all Terraform/CloudFormation?
  • DAST (Dynamic Analysis) run against staging environment before production?
  • DevSecOps Pipeline Security Notes

Related IT & Data Security Checklists

Related Cybersecurity Checklists

Why Use This DevSecOps CI/CD Pipeline Security Checklist?

This devsecops ci/cd pipeline security checklist helps telecommunications & it teams maintain compliance and operational excellence. Designed for devsecops engineer / application security lead professionals, this checklist covers 13 critical inspection points across 3 sections. Recommended frequency: per release / quarterly review.

Ensures compliance with NIST SP 800-218 Secure Software Development Framework (SSDF), SLSA Framework v1.0 Supply Chain Levels for Software Artifacts, OWASP Top 10 CI/CD Security Risks (2022), CISA Software Supply Chain Security Guidance, EO 14028 Improving Nation's Cybersecurity - Software Security. Regulatory-aligned for audit readiness and inspection documentation.

Frequently Asked Questions

What does the DevSecOps CI/CD Pipeline Security Checklist cover?

This checklist covers 13 inspection items across 3 sections: Source Code Security, Dependency and Supply Chain Security, Build and Artifact Integrity. It is designed for telecommunications & it operations and compliance.

How often should this checklist be completed?

This checklist should be completed per release / quarterly review. Each completion takes approximately 30-45 minutes.

Who should use this DevSecOps CI/CD Pipeline Security Checklist?

This checklist is designed for DevSecOps Engineer / Application Security Lead professionals in the telecommunications & it industry. It can be used for self-assessments, team audits, and regulatory compliance documentation.

Can I download this checklist as a PDF?

Yes, this checklist is available as a free PDF download. You can also use it digitally in the POPProbe mobile app for real-time data capture, photo documentation, and automatic reporting.

Browse More Checklists