Chef Advances Security Capabilities
March 13, 2019

Chef announced the achievement of three significant security milestones, helping its government and enterprise customers ensure that they can achieve and maintain the secure infrastructure needed to accelerate their cloud strategies.

These include Secure Technical Implementation Guidelines (STIG) profiles for RHEL 7 and Windows Server 2016 in Chef InSpec, along with FIPS 140-2 compliance and Center for Internet Security (CIS) certification for AWS Foundations Benchmarks Level 1 and 2 in Chef Automate. Chef is the first CIS partner to achieve certification across AWS, Microsoft Azure and Google Cloud Platform, giving its customers maximum flexibility when choosing and securing cloud platforms.

Chef has worked closely with federal, government and enterprise organizations to automate the way they build and manage their infrastructure and enable compliance as code. The capacity to not only automate configuration but also ensure compliance and remediate vulnerabilities, is critical to automating infrastructure, particularly in highly-regulated industries.

Chef InSpec incorporates compliance processes into every stage of users’ development cycles, significantly mitigating these concerns. Chef and Chef InSpec enable continuous compliance by allowing customers to automatically resolve potential compliance issues without human intervention.

Cloud platforms offer easy-to-use resources for configuring access control, data storage and virtual networking, giving organizations the tools to scale their environments quickly. But with these new tools come new guidelines and best practices for securing them properly. STIG profiles let Chef customers determine whether their cloud implementations meet the requirements outlined within the benchmarks and provide actionable insights regarding where insecure configurations are found. New CIS benchmarks deliver prescriptive implementation criteria for each cloud provider, while FIPS compliance enables government organizations to take maximum advantage of InSpec compliance automation at scale.

“The security milestones announced today give our customers the tools and the confidence they need to accelerate their most critical cloud initiatives,” said John Snow, Senior Software Development Engineer and Federal Content Lead at Chef. “This work builds on our long history of close collaboration with government users and the organizations that support them, furthering our ongoing commitment to provide the most innovative and easy-to-use application delivery and compliance automation solutions available to organizations of all types.”

Share this

Industry News

January 23, 2025

Progress announced the launch of Progress Data Cloud, a managed Data Platform as a Service designed to simplify enterprise data and artificial intelligence (AI) operations in the cloud.

January 23, 2025

Sonar announced the release of its latest Long-Term Active (LTA) version, SonarQube Server 2025 Release 1 (2025.1).

January 23, 2025

Idera announced the launch of Sembi, a multi-brand entity created to unify its premier software quality and security solutions under a single umbrella.

January 22, 2025

Postman announced the Postman AI Agent Builder, a suite empowering developers to quickly design, test, and deploy intelligent agents by combining LLMs, APIs, and workflows into a unified solution.

January 22, 2025

The Cloud Native Computing Foundation® (CNCF®), which builds sustainable ecosystems for cloud native software, announced the graduation of CubeFS.

January 21, 2025

BrowserStack and Bitrise announced a strategic partnership to revolutionize mobile app quality assurance.

January 21, 2025

Render raised $80M in Series C funding.

January 16, 2025

Mendix, a Siemens business, announced the general availability of Mendix 10.18.

January 16, 2025

Red Hat announced the general availability of Red Hat OpenShift Virtualization Engine, a new edition of Red Hat OpenShift that provides a dedicated way for organizations to access the proven virtualization functionality already available within Red Hat OpenShift.

January 16, 2025

Contrast Security announced the release of Application Vulnerability Monitoring (AVM), a new capability of Application Detection and Response (ADR).

January 15, 2025

Red Hat announced the general availability of Red Hat Connectivity Link, a hybrid multicloud application connectivity solution that provides a modern approach to connecting disparate applications and infrastructure.

January 15, 2025

Appfire announced 7pace Timetracker for Jira is live in the Atlassian Marketplace.

January 14, 2025

SmartBear announced the availability of SmartBear API Hub featuring HaloAI, an advanced AI-driven capability being introduced across SmartBear's product portfolio, and SmartBear Insight Hub.

January 14, 2025

Azul announced that the integrated risk management practices for its OpenJDK solutions fully support the stability, resilience and integrity requirements in meeting the European Union’s Digital Operational Resilience Act (DORA) provisions.

January 14, 2025

OpsVerse announced a significantly enhanced DevOps copilot, Aiden 2.0.