On this page
Security tools are essential for identifying vulnerabilities and ensuring compliance in regulated software environments. This guide covers tools for threat modeling, static analysis, dynamic testing, and security scanning.
Security Tool Landscape
Threat modeling is a proactive approach to identifying security threats early in the design phase.
STRIDE Framework
STRIDE Threat Model
Static Application Security Testing (SAST)
Language-Specific Analyzers
Example: SonarQube Configuration
# sonar-project.properties
sonar.projectKey=my-project
sonar.projectName=My Project
sonar.sources=src
sonar.tests=tests
sonar.language=typescript
sonar.sourceEncoding=UTF-8
# Security hotspot rules
sonar.security.sources.javasecurity=java
sonar.security.hotspots.review.history=true
Dependency Scanning
GitHub Dependabot Configuration
# .github/dependabot.yml
version: 2
updates:
- package-ecosystem: "npm"
directory: "/"
schedule:
interval: "weekly"
open-pull-requests-limit: 10
- package-ecosystem: "docker"
directory: "/"
schedule:
interval: "weekly"
- package-ecosystem: "github-actions"
directory: "/"
schedule:
interval: "weekly"
Dynamic Application Security Testing (DAST)
Web Application Scanners
OWASP ZAP Integration
# GitHub Actions with OWASP ZAP
- name: ZAP Scan
uses: zaproxy/action-full-scan@v0.7.0
with:
target: 'https://staging.example.com'
rules_file_name: '.zap/rules.tsv'
cmd_options: '-a'
API Security Testing
GitLeaks Configuration
# .gitleaks.toml
[allowlist]
description = "Allowlist for known false positives"
paths = [
'''\.test\.ts$''',
'''__mocks__''',
]
[[rules]]
description = "AWS Access Key"
regex = '''AKIA[0-9A-Z]{16}'''
tags = ["aws", "credentials"]
[[rules]]
description = "Generic API Key"
regex = '''(?i)api[_-]?key[\s]*[=:]\s*['\"]?[\w-]{20,}'''
tags = ["api-key"]
Container Security
Trivy CI/CD Integration
# GitHub Actions with Trivy
- name: Run Trivy vulnerability scanner
uses: aquasecurity/trivy-action@master
with:
image-ref: 'myapp:${{ github.sha }}'
format: 'sarif'
output: 'trivy-results.sarif'
severity: 'CRITICAL,HIGH'
- name: Upload Trivy scan results
uses: github/codeql-action/upload-sarif@v2
with:
sarif_file: 'trivy-results.sarif'
Infrastructure as Code Security
Checkov Configuration
# .checkov.yaml
framework:
- terraform
- kubernetes
skip-check:
- CKV_AWS_18 # S3 bucket logging
- CKV_AWS_21 # S3 bucket versioning
check:
- CKV_AWS_*
- CKV_K8S_*
Security Standards Reference
OWASP Top 10 (2021)
Security Protocols and Standards
Cyber Threat Intelligence
CI/CD Security Pipeline
# Complete security pipeline example
name: Security Scan
on:
push:
branches: [main]
pull_request:
branches: [main]
jobs:
security:
runs-on: ubuntu-latest
steps:
# SAST
- name: SonarCloud Scan
uses: SonarSource/sonarcloud-github-action@master
env:
SONAR_TOKEN: ${{ secrets.SONAR_TOKEN }}
# Dependency Scanning
- name: Snyk Security Scan
uses: snyk/actions/node@master
env:
SNYK_TOKEN: ${{ secrets.SNYK_TOKEN }}
# Secret Detection
- name: GitLeaks Scan
uses: gitleaks/gitleaks-action@v2
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
# Container Scanning
- name: Trivy Container Scan
uses: aquasecurity/trivy-action@master
with:
image-ref: '${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}:${{ github.sha }}'
severity: 'CRITICAL,HIGH'
# IaC Scanning
- name: Checkov IaC Scan
uses: bridgecrewio/checkov-action@master
with:
directory: terraform/
Compliance
This section fulfills ISO 13485 requirements for risk management tools (7.1) and validation of processes (7.5.2), and ISO 27001 requirements for vulnerability management (A.8.8), security testing (A.8.29), technical vulnerability management (A.8.8), and penetration testing (A.8.29).
View full compliance matrix