Skip to content

Qualys Launches DevSecOps Blog Series for Securing Cloud Infrastructures

Qualys is embedding its Cloud Agent into approved golden AMIs. Discover how to continuously scan instances for vulnerabilities and compliance issues in the new blog series.

In this image there is a big tanker with iron ladder and fence at the top.
In this image there is a big tanker with iron ladder and fence at the top.

Qualys Launches DevSecOps Blog Series for Securing Cloud Infrastructures

Today marks the start of a new blog series by Qualys, focusing on integrating their solutions into DevSecOps for securing cloud infrastructures. The company is working with Aikido Security and Amazon to facilitate this integration.

Qualys' AWS Golden Amazon Machine Image Pipeline will embed the Qualys Cloud Agent into approved golden AMIs. This allows customers to continuously scan instances deployed from these approved AMIs for vulnerabilities and compliance issues.

The company has published a GitHub repository and documentation to guide users through implementing Qualys scanning in a golden AMI pipeline. Qualys has also integrated its scanners with the AWS Golden AMI Pipeline for vulnerability and configuration compliance assessment.

Amazon has released a sample implementation demonstrating how to integrate a golden AMI pipeline with Qualys scanners. Looking ahead, Qualys plans to introduce an AWS Lambda function to process serious vulnerability scan results and automate image approval.

The initial post in this series emphasizes the importance of assessing vulnerabilities and misconfigurations in AWS pipelines. Qualys recommends continuous and automated checks for these issues in golden Amazon Machine Images (AMIs). In addition to these services, Qualys offers other cloud platform applications such as Qualys File Integrity Monitoring, Qualys Indication of Compromise, and Qualys Threat Protection.

Read also:

Latest