Chef Introduces InSpec 3.0
October 16, 2018

Chef announced significant updates to its InSpec by Chef compliance automation platform, including a new plugin architecture, greatly improved ease-of use, improved exception management and automated compliance for Terraform.

InSpec 3.0 greatly increases the velocity of compliance audits and remediation, while reducing risk for cross-functional security, development and operations (DevSecOps) teams and their organizations.

InSpec is an open-source language for describing security and compliance rules that can be shared between software engineers, operations and security engineers. Unlike other products, InSpec is designed to be used at all stages of the software delivery process, from developers’ workstations to production, allowing companies to achieve continuous compliance with no performance impact or side-effects. In contrast to other compliance languages, InSpec is designed to be easy-to-use, even by users with no background in programming.

New features in InSpec 3.0 designed to enhance the developer experience include:

- New plugin architecture: The InSpec 3.0 plugin architecture makes it easier for developers to extend InSpec for use with a broader variety of systems in need of compliance automation. Available for both InSpec and Train (Transport Interface Library), the plugin architecture allows for both pluggable communication protocols as well as new resource types in InSpec to be easily developed.

- Improved exception management: Exception management is challenging both in terms of the ability to skip the execution of certain InSpec controls on specific nodes (e.g., those with compensating controls) and the ability to keep track of acceptable failures (i.e., where controls are not skipped but the failures are acceptable). InSpec 3.0 enables both actions, streamlining processes and outcomes to facilitate core audit and remediation capabilities while minimizing confusion.

- Workflow-enhancing APIs: InSpec 3.0 allows developers to more easily author new resources -- classes of “things” that can be tested on a system or a cloud. This includes the introduction of a new, stable API between profiles -- groups of compliance tests similar to Chef Cookbooks -- and attributes -- the data that enables users to modify how tests are conducted. Improvements to the packaging (vendoring) mechanism for profiles allows developers to more easily iterate on InSpec profiles with dependencies.

InSpec 3.0 features designed to improve user experience, especially in highly mixed environments, include:

- Compliance for Terraform: A provisioner plugin for Terraform allows InSpec to be executed during a Terraform run in order to validate the state of virtual machines as well as cloud infrastructure in one seamless operation. InSpec 3.0 also provides InSpec-Iggy ("InSpec Generator", or I.G.) which allows users to generate compliance controls from a Terraform state file. Both of these features extend compliance into a new domain, allowing provisioning-as-code to be properly validated for compliance whenever changes are proposed to it.

- Compliance for Google Cloud Platform (GCP): Native support for GCP, using InSpec 3.0’s new plugin architecture, further extends InSpec’s cloud compliance capabilities. Premium InSpec content in Chef Automate to support the Center for Internet Security (CIS) benchmarks for GCP helps customers get started quickly to ensure compliance across cloud applications and infrastructure. The CIS has certified Chef as the first compliance automation vendor implementing the CIS GCP Benchmark.

- Improved metadata interface on controls: InSpec 3.0 introduces a key-value based description interface, allowing for more fine-grained reporting as well as de-duplication of controls that satisfy one or more compliance regimes. This allows users to create custom metadata categories, e.g., what compliance regime or regimes a control is for, how to remediate a finding, or how to escalate the finding.

“Establishing and maintaining compliance across heterogeneous environments is a daunting task, made more so by ever-shifting regulatory requirements alongside rapidly-evolving hybrid IT strategies,” said Corey Scobie, SVP of Product and Engineering at Chef. “InSpec 3.0 further eases the path to compliance for both developers and operations teams, and helps accelerate enterprises’ digital transformations by laying a solid foundation for cloud migration.”

Share this

Industry News

November 26, 2024

Check Point® Software Technologies Ltd. has been recognized as a Leader and Fast Mover in the latest GigaOm Radar Report for Cloud-Native Application Protection Platforms (CNAPPs).

November 26, 2024

Spectro Cloud, provider of the award-winning Palette Edge™ Kubernetes management platform, announced a new integrated edge in a box solution featuring the Hewlett Packard Enterprise (HPE) ProLiant DL145 Gen11 server to help organizations deploy, secure, and manage demanding applications for diverse edge locations.

November 26, 2024

Red Hat announced the availability of Red Hat JBoss Enterprise Application Platform (JBoss EAP) 8 on Microsoft Azure.

November 26, 2024

Launchable by CloudBees is now available on AWS Marketplace, a digital catalog with thousands of software listings from independent software vendors that make it easy to find, test, buy, and deploy software that runs on Amazon Web Services (AWS).

November 26, 2024

Kong closed a $175 million in up-round Series E financing, with a mix of primary and secondary transactions at a $2 billion valuation.

November 26, 2024

Tricentis announced that GTCR, a private equity firm, has signed a definitive agreement to invest $1.33 billion in the company, valuing the enterprise at $4.5 billion and further fueling Tricentis for future growth and innovation.

November 25, 2024

Sonatype and OpenText are partnering to offer a single integrated solution that combines open-source and custom code security, making finding and fixing vulnerabilities faster than ever.

November 25, 2024

Red Hat announced an extended collaboration with Microsoft to streamline and scale artificial intelligence (AI) and generative AI (gen AI) deployments in the cloud.

November 25, 2024

Endor Labs announced that Microsoft has natively integrated its advanced SCA capabilities within Microsoft Defender for Cloud, a Cloud-Native Application Protection Platform (CNAPP).

November 21, 2024

Red Hat announced the general availability of Red Hat Enterprise Linux 9.5, the latest version of the enterprise Linux platform.

November 21, 2024

Securiti announced a new solution - Security for AI Copilots in SaaS apps.

November 20, 2024

Spectro Cloud completed a $75 million Series C funding round led by Growth Equity at Goldman Sachs Alternatives with participation from existing Spectro Cloud investors.