Puppet Launches Compliance Enforcement Modules
September 29, 2021

Puppet launched Compliance Enforcement Modules to provide customers with turnkey compliance remediation and enforcement of policy-as-code directly aligned to Center for Internet Security Benchmarks (CIS) for both Windows and Linux.

The Compliance Enforcement Modules will be bundled into Puppet Comply, which works with Puppet Enterprise to assess, remediate, and enforce infrastructure configuration compliance policies at scale across traditional and cloud environments.

With more new vulnerabilities reported in 2020 than in any year in history and an increased focus on industry regulatory standards that harden images and fortify security, there is a heightened focus on maintaining infrastructure security compliance across environments. Failure to comply with regulatory standards can lead to failed audits or risk assessments, putting an organization at risk of everything from lost business to exorbitant fines. The ability to automate the security compliance process to drive increased visibility and quick remediation is a top priority for companies within highly regulated environments or those that are experiencing increased attacks.

With the latest investments and innovations from Puppet, Puppet Comply customers can now more quickly identify the cause and source of compliance failures and determine the correct configuration changes within minutes rather than weeks.

“The need to automate policy and governance to manage infrastructure helps the infrastructure and operations team break free from reactive processes and puts them at the center of understanding what is out of compliance and how to fix it more easily and quickly,” said Abby Kearns, CTO of Puppet. “We’ve been developing solutions and technology in this space alongside our customers to help address current and future needs. This is a huge opportunity for us to help our customers get more time back and address the increased risks they face as security and compliance requirements become more complex, demanding, and sophisticated.”

The Compliance Enforcement Modules are part of Puppet’s continued investment to codify the processes of bringing infrastructure into compliance to help operators:

- Decrease the financial and security risk associated with non-compliance.

- Increase organization-wide visibility into compliance status and predictability of resolution.

- Reduce the time and resources needed to interpret scans, remediate compliance failures, and prepare for audits.

- Increase the percentage of infrastructure that is fully compliant.

Share this

Industry News

February 03, 2025

Linux Foundation Europe and OpenSSF announced a global joint-initiative to help prepare maintainers, manufacturers, and open source stewards for the implementation of the EU Cyber Resilience Act (CRA) and future cybersecurity legislation targeting jurisdictions around the world.

January 30, 2025

OutSystems announced the general availability (GA) of Mentor on OutSystems Developer Cloud (ODC).

January 30, 2025

Kurrent announced availability of public internet access on its managed service, Kurrent Cloud, streamlining the connectivity process and empowering developers with ease of use.

January 29, 2025

MacStadium highlighted its major enterprise partnerships and technical innovations over the past year. This momentum underscores MacStadium’s commitment to innovation, customer success and leadership in the Apple enterprise ecosystem as the company prepares for continued expansion in the coming months.

January 29, 2025

Traefik Labs announced the integration of its Traefik Proxy with the Nutanix Kubernetes Platform® (NKP) solution.

January 28, 2025

Perforce Software announced the launch of AI Validation, a new capability within its Perfecto continuous testing platform for web and mobile applications.

January 28, 2025

Mirantis announced the launch of Rockoon, an open-source project that simplifies OpenStack management on Kubernetes.

January 28, 2025

Endor Labs announced a new feature, AI Model Discovery, enabling organizations to discover the AI models already in use across their applications, and to set and enforce security policies over which models are permitted.

January 27, 2025

Qt Group is launching Qt AI Assistant, an experimental tool for streamlining cross-platform user interface (UI) development.

January 27, 2025

Sonatype announced its integration with Buy with AWS, a new feature now available through AWS Marketplace.

January 27, 2025

Endor Labs, Aikido Security, Arnica, Amplify, Kodem, Legit, Mobb and Orca Security have launched Opengrep to ensure static code analysis remains truly open, accessible and innovative for everyone:

January 23, 2025

Progress announced the launch of Progress Data Cloud, a managed Data Platform as a Service designed to simplify enterprise data and artificial intelligence (AI) operations in the cloud.

January 23, 2025

Sonar announced the release of its latest Long-Term Active (LTA) version, SonarQube Server 2025 Release 1 (2025.1).

January 23, 2025

Idera announced the launch of Sembi, a multi-brand entity created to unify its premier software quality and security solutions under a single umbrella.