Sabel Systems, a managed DevSecOps pipeline platform provider for the defense industry, reduced vulnerability review from 2 weeks to 3 days using Anchore Enterprise while maintaining zero critical vulnerabilities in multiple IL5 environments. The Code Foundry platform enables DoD missions to achieve both platform and vehicle ATO through automated security scanning and compliance workflows that provide real-time transparency to government auditors.
Problems
Manual vulnerability review cannot scale with application growth
DoD customers required cloud-agnostic, IL5-compliant DevSecOps solutions for accelerated ATO
Complex environment demanded seamless integration across multiple Cl/ CD tools and cloud providers
Solutions
Anchore Enterprise delivered:
Automated vulnerability scanning and SBOM generation integrated into Cl/CD pipelines
On-premise IL5-ready deployment with DoD policy packs for automated compliance
API-first architecture enabling flexible integration across GitLab, Jenkins, and Kubernetes
Results
75% reduction in vulnerability review time (from 1-2 weeks to 3 days)
Scaled zero critical vulnerabilities policy across 100+ applications
Real-time audit transparency through compliance evidence dashboards
Introduction
Sabel Systems provides a managed DevSecOps pipeline-as-a-service for Department of Defense (DoD) missions and defense contractors developing mission-critical vehicle systems. The company’s Code Foundry platform fills a crucial gap in the marketplace by offering a comprehensive software development platform specifically designed for applications that must run on air-gapped, field systems rather than traditional, cloud-dependent, web deployments.
Code Foundry operates as a platform-agnostic solution that is designed to operate across different infrastructure environments (e.g., AWS GovCloud, private DoD-approved cloud, and on-premise infrastructure). With a lean team of 10 supporting 100+ active developers, the platform manages hundreds of applications for next-generation military vehicles.
Problems
Sabel Systems faced three critical challenges in delivering a DevSecOps platform that could meet the demanding requirements of DoD vehicle development programs:
Manual vulnerability review cannot scale with growth
As Sabel Systems supported Army, Air Force, and Navy Digital Engineering initiatives, a common challenge emerged within their software acquisition pathway. The DoD security teams were unable to adequately support the 100+ developers they served. The manual review process—time¬consuming, labor-intensive, and prone to error—became a bottleneck that threatened the platform’s ability to fulfill its mandate of producing secure applications. This inefficiency underscored the urgent need for a scalable solution. What had worked in the early days was now buckling under the pressure of scaling a successful business.
To address this, Sabel Systems designed its Code Foundry architecture to eliminate the need for the DoD’s standard manual vulnerability review process and ensure the software acquisition pathway could scale to support enterprise-level functionality.
DoD customer demanded exacting compliance and deployment capabilities
Code Foundry customers operate in one of the most demanding technical environments in software development: DoD vehicle systems that must achieve Authority to Operate (ATO) before field deployment. The DoD software acquisition pathway mandates modern DevSecOps practices but within fully air-gapped environments; a challenge for many traditional cloud-based security tools.
Beyond technical requirements, Code Foundry needed to support the complex organizational structure within the DoD. Different military branches have distinct preferences for cloud environments and security protocols, requiring a truly agnostic solution that can be deployed anywhere while maintaining consistent security standards.
Technical architecture required seamless multi-tool integration in controlled environments
Code Foundry’s technical architecture presented unique integration challenges. Operating in IL5 (controlled unclassified) environments on NIPR networks means that the security software must run without external connectivity. Additional requirements are seamless integration with diverse Cl/CD toolchains such as GitLab, Jenkins, Bitbucket, GitHub, and various Kubernetes distributions without requiring extensive per-environment configuration.
Solutions
Sabel Systems selected Anchore Enterprise to scale their vulnerability management across hundreds of applications with limited resources, streamline compliance workflows, and leverage a platform purpose-built for DoD environments.
Automated vulnerability scanning enables scale without additional headcount
Sabel Systems’ lean security was able to remove manual review bottlenecks with Anchore Enterprise and is now able to support their growing customer base and applications without adding personnel. Anchore Enterprise’s automated approach allows the same 10-person security team to effectively support 100s of applications across multiple DoD contractors. Anchore Enterprise integrates directly into Code Foundry’s Cl/CD pipelines, automatically scanning every container image as soon as it’s built and providing immediate feedback on security posture. Rather than security reviews becoming a constraint on business growth, they now happen seamlessly in the background.
On-premises deployment meets DoD security and compliance requirements
Anchore Enterprise’s DoD-tailored on-premise and IL5-compliant deployment capabilities deliver comprehensive security entirely within government-approved infrastructure.
Anchore Enterprise includes pre-built policy packs specifically designed for DoD requirements, including FedRAMP, NIST, and STIG compliance frameworks. Through automated compliance enforcement, Code Foundry customers receive real-time notifications of compliance issues, enabling them to address problems early in development rather than discovering them during costly ATO audits. This proactive approach helps customers build their ATO packages with confidence while avoiding the time-consuming remediation cycles that typically delay program timelines.
Anchore Enterprise’s native compliance dashboards and reporting offer the DoD auditors real-time transparency into the compliance state of all parties. Instead of waiting weeks for static compliance reports, auditors access live security data directly, creating dynamic review meetings and building trust through transparency.
API-first architecture enables flexible integration across diverse environments
Anchore Enterprise’s API-first architecture deploys via Helm charts into Kubernetes clusters and integrates seamlessly with GitLab CI, Jenkins, and other Cl/CD tools that different military branches prefer.
Anchore CTL, the vulnerability scanner for Anchore Enterprise, executes scans directly within the Kubernetes cluster, a critical security advantage for modern infrastructure teams. By baking AnchoreCTL directly into Code Foundry, Sabel Systems created a secure approach that eliminates the need to open network connections to external systems. This addresses a common security concern where external security tools create potential attack vectors.
“We include AnchoreCTL in an image and use that image to run the scanning and analysis steps. We do that so we can keep all the connections inside of the cluster without having to SSH into an already running pod.”
—Robert McKay, Digital Solutions Architect, Code Foundry, Sabel Systems
Results
The implementation of Anchore Enterprise transformed Sabel Systems’ operational efficiency and positioned Code Foundry as the premier DoD DevSecOps platform:
Zero critical vulnerabilities maintained across 100+ applications
Anchore Enterprise enables Code Foundry to maintain their strict security policy of zero critical or high vulnerabilities at scale. This level of security assurance is essential for applications that will eventually deploy to mission-critical vehicle systems.
75% reduction in vulnerability review time
Code Foundry’s now automated vulnerability review process was cut from 1-2 weeks to 3-days leading to faster platform updates and more responsive customer support.
“Before Anchore, it would take us a week to two weeks to go through everything that an image could have—we’d have to first build the actual software on the image and then go through all the different connection points and dependencies. Using Anchore has brought that down to a 3-day review time.”
—Robert McKay, Digital Solutions Architect, Code Foundry, Sabel Systems
Code Foundry now provides government reviewers with live access to security dashboards and compliance data. This transparency accelerates the review process and builds trust between contractors and government oversight teams.
“The idea is that you can replace your static contract deliverables with dynamic ones -doing review meetings based on Anchore’s live data instead of ‘here’s my written report that took me a week to write up on what we found last week,’ and by the time the government gets it, it’s now 2-3 weeks old.”
—Joe Bern, Senior Manager, Code Foundry, Sabel Systems
By leveraging Anchore Enterprise, Sabel Systems has established Code Foundry as the trusted platform for DoD contractors requiring the highest levels of security, compliance, and operational efficiency in their software development workflows.
Download the PDF version of this case study for a complete look at how Sabel Systems leverages Anchore SBOM and Secure to scale compliance while reducing vulnerability review time by 75%.
ModuleQ, an AI-powered enterprise knowledgean AI-powered enterprise knowledgesolution, reduced vulnerability managementsolution, reduced vulnerability management time by 80% with Anchore Enterprise whiletime by 80% with Anchore Enterprise while meeting regulatory compliance for the financialmeeting regulatory compliance for the financial services industry. Anchore Enterprise integratedservices industry. Anchore Enterprise integrated seamlessly into ModuleQ’s existing DevSecOpsseamlessly into ModuleQ’s existing DevSecOps workflow supporting enterprise deployments andworkflow supporting enterprise deployments and now automates previously manual vulnerabilitynow automates previously manual vulnerability processesprocesses.
Challenges
Identify, triage and analyze constant flood of new vulnerabilities with limited resources
Ensure critical vulnerabilities never reach production without disrupting developer workflow
Address regulatory compliance demands for strict container security requirements
Solutions
Anchore Enterprise secures the software supply chain with:
Turnkey container vulnerability scanning, triage and analysis
Cloud native integration enabling proactive vulnerability notification and remediation workflow
Support for enterprise deployments to meet uncompromising compliance requirements
Results
80% reduction on time spent managing vulnerabilities
50% less time on security tasks for production deployments
Built immediate trust with financial services customer base
Introduction
ModuleQ’s enterprise AI software delivers timely, proactive customer insights by anticipating user needs, helping organizations streamline their decision-making processes. Operating in the highly regulated financial services industry, ModuleQ deploys its solutions directly within customer-controlled tenants, ensuring data security and compliance.
The software is built using a robust development stack that includes .NET and C#, with Azure DevOps Pipelines driving the build environment. The platform consists of a single application made up of dozens of microservices, utilizing a multi-stage pipeline to ensure stability and security. As code progresses from nightly builds to production, container scans are automatically run to identify vulnerabilities, ensuring secure and seamless deployments
Challenges
Managing constant flood of new vulnerabilities with limited resources
With a small but dedicated team, ModuleQ was straining under the weight of the constant flood of new vulnerabilities released. High-profile security incidents like the Log4j supply chain attack and Crowdstrike incident only served to highlight the importance of vigilant vulnerability management. The sheer volume of new vulnerabilities—25,000 in 2023 alone—was overwhelming ModuleQ’s manual processes.
ModuleQ quickly recognized their current systems were no longer scaling with the resources on hand and started researching a turnkey vulnerability management solution that automated vulnerability scanning, management and analysis.
Ensure crictial vulnerabilities never reach production without disrupting developer workflow
In the high-stakes threat environment that ModuleQ operates in they found that requiring engineers to break out of their workflow and manually review vulnerabilities didn’t meet the security posture they needed. Each time their developers switched to a traditional, passive vulnerability management dashboard, they would lose context. This led to concerns around potentially missing critical vulnerabilities. With limited resources and the constant pressure to secure sensitive data, a natively integrated DevSecOps solution was needed to retain the high velocity of their software delivery and maintain the highest possible security guarantees.
This called for a vulnerability management platform that embedded into their existing DevSecOps ecosystem. By directly integrating vulnerability scanning and management into their existing automation tooling they could remove all manual intervention from vulnerability scanning, triage and reporting.
Address regulatory compliance demands for strict container security requirements
ModuleQ specializes in deploying its enterprise AI software into customer environments operating in the highly regulated financial service sector. To meet the expectations of clients, ModuleQ needed a partner capable of supporting enterprise deployments while guaranteeing airtight security. These institutions operate in high-stakes environments where even a minor security lapse can have catastrophic consequences, especially with sensitive content like Microsoft 365 and Salesforce data.
Deployments are often conducted directly by the financial institutions themselves, meaning no data can leave the client’s secure environment. This created the need for a security solution that could operate effectively without external network access, delivering bulletproof protection against sophisticated threats from state-sponsored actors and cybercriminals.
“Anyone can push out code quickly. Can they push secure code with the highest confidence that it fits the risk profiles of critical national infrastructure like financial services?.“
—Joseph Zuromski, VP of Engineering, ModuleQ
Solutions
ModuleQ selected Anchore Enterprise as their container vulnerability solution to solve the challenges presented by their customer base:
Turnkey container vulnerability scanning, triage and analysis
Anchore’s container vulnerability scanning and analysis platform helped ModuleQ automate and streamline its security processes. Previously manual security reviews of software builds heavily taxed the engineering team. With Anchore Enterprise, ModuleQ now automatically scans all software builds nightly, stores the reports for reference and analyzes the identified vulnerabilities to determine prioritization in the development cycle.
Anchore Enterprise automates each step of this process and provides the analysis tooling to quickly derive actionable security insights. ModuleQ is now able to de-risk their software deliverables and free up their developer’s time for new features rather than hunting down low- signal vulnerabilities.
“Anchore was one of the first tools that we brought on. It was recommended by our CISO who has been deeply involved in the security community for decades.“
—Joseph Zuromski, VP of Engineering, ModuleQ
Cloud native integration enabling proactive vulnerability notification and remediation workflow
Anchore Enterprise was designed to be integrated directly into any modern, cloud native DevSecOps pipeline to help organizations shift security left from release time earlier into the development cycle. By embedding vulnerability scanning and reporting directly into their CI/CD pipeline, ModuleQ stops crucial vulnerabilities from slipping into production with the reliability guarantees of a fully automated system.
Anchore Enterprise automatically reports all HIGH and CRITICAL vulnerabilities directly to the build runner which immediately breaks to prevent these vulnerabilities from being promoted to production. This provides immediate feedback to the engineering team and initiates the remediation process. This proactive security posture prevents any potential disastrous vulnerabilities from being missed and reduces time wasted by developers context switching out of their existing workflow.
On top of this, Anchore’s support for ModuleQ’s existing developer toolchain—including Azure DevOps Pipelines, .NET, and C#—was paramount. The benefits that Anchore Enterprise brings to ModuleQ are possible because of Anchore’s support for the Microsoft ecosystem of development tooling.
Support for enterprise deployments to meet uncompromising compliance requirements
ModuleQ selected Anchore Enterprise for its support for on-prem deployments. Given that ModuleQ’s customers expected on-prem deployments to safeguard their data, Anchore was able to reinforce ModuleQ’s commitment to meeting and exceeding these security expectations.
Anchore’s platform was designed from the ground up to operate in on-prem and even air-gapped environments, ensuring that no external connectivity is required. These design choices gave ModuleQ the confidence that Anchore was the trusted partner to support container security needs of their demanding customer base.
Results
The implementation of Anchore Enterprise transformed ModuleQ’s security posture and business operations:
80% reduction on time spent managing vulnerabilities
By leveraging Anchore’s automated scanning and reporting capabilities, ModuleQ reduced the time spent managing vulnerabilities. This unlocked efficiency gains allowing the team to focus on developing new features and improving customer satisfaction.
50% less time on security tasks for production deployments
Anchore Enterprise’s cloud native integration and proactive vulnerability management system streamlined ModuleQ’s production deployment process, cutting security task time in half. This allowed ModuleQ to maintain its rapid cadence of software delivery while maintaining the highest level of security.
Sinificantly increased confidence that newly shipped customer releases will meet the highest security requirements
Anchore’s experience with on-prem deployments gave ModuleQ the confidence that their software releases would meet the rigorous security standards of their financial services clients. This confidence translated into stronger customer relationships and trust in ModuleQ’s security posture.
“I can’t emphasize enough, there is a ton of scrutiny around security—especially around our containers. We deploy into large banks and financial institutions worldwide. You can imagine the security involved with these types of deployments. Anchore is a key component in making these deployments successful.”
—Joseph Zuromski, VP of Engineering, ModuleQ
By leveraging Anchore Enterprise, ModuleQ has positioned itself as the trusted partner with the expertise to meet the highest levels of security and regulatory compliance.
Download the PDF version of this case study for a complete look at how ModuleQ reduces vulnerability management time by 80% while meeting the highest regulatory compliance standards.
PEO Digital’s DevSecOps Platform “Black Pearl” enables US Navy programs to build and deploy software rapidly while maintaining the most stringent government security and compliance requirements.
Compliance reporting and maintenance are time intensive and so are managing vulnerabilities and risks through open- source software.
Challenges
Achieve RMF security and compliance requirements
Maintaining continuous compliance
Managing the risk of open-source software
Vulnerability overload for developers
Solutions
Anchore automates security and compliance to reduce risks in the software supply chain:
Policy packs to meet RMF security controls
Automated and continuous ATO compliance
Managing OSS risks with continuous monitoring (ConMon)
Automated prioritization of vulnerabilities
Results
Achieve authority to operate (ATO) for software under RMF framework:
Deploy a ready to be assessed DSOP in 3-5 days
Significantly reduced time spent on compliance reporting
Proactive OSS risk management
Reduced vulnerability overload with prioritized vulnerability reporting
Introduction
Black Pearl is a PEO Digital Enterprise DevSecOps Platform comprised of two offerings, Party Barge and Lighthouse. Lighthouse is a resilient, production-grade DevSecOps Platform, tailored to meet specific Mission Owner requirements whether it be on-prem or in a custom cloud deployment.
Party Barge is built from the Lighthouse baseline, designed as a Multi-tenant Development and Test environment (IL2/5) offering DevSecOps Tools as a Service using a simple per user licensing model, and is fully managed by the Black Pearl Party Barge Team
Challenges
For any software to be built, deployed and used by the warfighter it has to achieve ATO. To achieve ATO, all software developed for a DoD mission has to be built on a software development platform that meets the DoD DevSecOps Enterprise Reference Design.
Sigma Defense, a technology company that specializes in networking, security and software engineering for the public sector, faced a number of challenges while architecting the Black Pearl platform such as securing the software supply chain, ATO-compliance, open- source software (OSS) risk management and vulnerability management.
Achieving RMF security and compliance for both DSOP and customers
Not only does Black Pearl need to achieve ATO for itself, it has to help its customers achieve ATO for the applications that are built on it. In order to achieve both of these goals, they required a software supply chain security platform that could both scan the Black Pearl platform for compliance and all applications built by its customers.
Maintaining continuous compliance
With the advent of the RAISE 2.0 memo jointly signed by the Senior Information Security Officers of the Navy and Marine Corps in November 2022, continuous ATO-compliance is now a priority for all DON missions. Given the amount of time and effort that goes into achieving an ATO in the first place, automating the bulk of the compliance tasks is crucial.
Managing the risk of open-source software
The average application contains 500+ open- source components; this is a powerful source of leverage for developers when building applications but creates risk. Black Pearl has the dual problem of having to manage the risk of open-source dependencies in its own platform and provide tools to help its customers manage the OSS risk in their own applications. Finding a solution to manage this risk is not only a security prerogative for Black Pearl but a compliance requirement.
Vulnerability overload for developers
Identifying vulnerabilities is the first step to ATO but given the number of vulnerabilities that exist in typical open-source components, triaging vulnerabilities can rapidly consume all of a developer’s time and resources. This degrades the developer velocity gains that were achieved by adopting a DevSecOps practice. Being able to filter which vulnerabilities are priorities rather than noise is a key challenge to overcome in order to achieve compliance without sacrificing velocity.
Solutions
To address these challenges, Sigma Defense chose Anchore to protect Black Pearl’s software supply chain.
Policy packs to meet RMF security controls
Sigma Defense chose Anchore to secure both Black Pearl’s software supply chain and all DON applications that are built on Black Pearl. Anchore can identify, evaluate, prioritize, enforce and report on whether security controls meet the compliance requirements of the Risk Management Framework (RMF). Each software development platform must meet stringent security requirements such as RA-5 (Vulnerability Management), SI-3 (Malware Protection), and IA-5 (Credential Management). This process can be daunting and resource-intensive, requiring continuous attention to detail and expertise in compliance review. Anchore and Sigma Defense have demonstrated their expertise to help various DoD missions, including Platform One’s Big Bang and PEO IWS The Forge, pass their authorizing official (AO) reviews and achieve ATO, mitigating this typically massive undertaking.
“By using the Anchore and the Black Pearl platform, applications inherit 80 percent of RMF security controls…You can avoid all of the boring stuff and just get down to what everyone does well, which is write code.”
—Christopher Rennie, Black Pearl Product Growth Lead
Automated and continuous ATO compliance
Achieving ATO is just the beginning; maintaining continuous compliance is an ongoing challenge. This involves managing security findings, tracking plan of action and milestones (POA&Ms), and ensuring that all necessary security controls are continuously met. Manual processes for maintaining compliance can be error-prone and resource-intensive. Anchore offers automated ATO compliance, continuously managing findings and POA&Ms. This automation ensures that compliance is maintained with minimal manual intervention, reducing the risk of non-compliance and the associated penalties.
“The DoD has four different layers of authorizing officials in order to achieve ATO. You have to figure out how to make all of them happy. We want to innovate by automating the compliance process. Anchore helps us achieve this, so that we can build a full ATO package in an afternoon rather than taking a month or more.“
—Josiah Ritchie, DevSecOps Staff Engineer
Managing OSS risks with continuous monitoring (ConMon)
Open-source software is widely used in modern software development, but it comes with inherent risks, including potential security vulnerabilities. Anchore mitigates this risk by integrating a vulnerability scanner, policy enforcer and reporting system to continuously monitor OSS vulnerabilities and risk in any software supply chain. This enables proactive management and active defense of OSS risk ensuring that vulnerabilities are detected and addressed promptly; reducing the risk of security breaches.
Automated prioritization of vulnerabilities
Black Pearl integrates the Anchore Developer Bundle which automatically flags vulnerabilities that developers are able to address and move their application to ATO quicker. This shift-left security practice creates actionable feedback for developers to overcome compliance hurdles before the review process. The power of DevSecOps is developer velocity. By embedding security directly into the development process DON missions get access to rapid and secure deployments.
Results
Platform ATO in 3-5 days
The main advantage of adopting the Black Pearl platform is the accelerated timeline of having a fully operational DSOP. While DIY builds can take up to 6 months or longer, Black Pearl users are able to access a fully operational DSOP within 3-5 days. With Anchore fully integrated into Black Pearl and its pre-built RMF policy pack running, all software built on Black Pearl will dramatically reduce the time to application ATO. Non-compliant software design decisions can be identified in development which prevents unnecessary engineering cycles from being wasted. Security is not the only practice that can benefit from a shift left approach to software development.
Significantly reduced time spent on compliance reporting
Anchore automates compliance checks and compliance artifacts:
Reduces hours spent manually reviewing vulnerability reports and creating the compliance artifacts that will then be delivered to the authorizing officials (AOs).
Ensures that all of the data exists in the reports and is formatted in the way expected by the reviewer. This prevents delays due to the inconsistencies that inevitably occur as part of any manual process.
“Working alongside Anchore, we have customized the compliance artifacts that come from the Anchore API to look exactly how the AOs are expecting them to. This has created a good foundation for us to start building the POA&Ms that they’re expecting”.
—Josiah Ritchie, DevSecOps Staff Engineer
Proactive OSS risk management
By shifting security and compliance left, Black Pearl enables its customers to identify and remediate open-source vulnerabilities that would block an ATO as early as the development phase of the software development lifecycle (SDLC). This proactive approach to security and compliance ensures that OSS risk is mitigated, compliance is smooth and the benefits of composable software are available to the developers of the US Navy. The downstream benefit is that time to ATO is reduced.
Reduced vulnerability overload with prioritized vulnerability reporting
The less time developer’s spend remediating vulnerabilities that have no tangible security value, the more time they can spend writing software to help the warfighter. Anchore automatically prioritizes actionable vulnerabilities and alerts developers. This prevents vulnerability overload and accelerates the time to delivery of critical software and features.
Download the PDF version of this case study for a complete look at US Navy achieves ATO in days with continuous compliance and OSS risk management.
DreamFactory, an API generation platform serving highly regulated organizations required an air-gapped vulnerability scanning and management solution that didn’t slow down their productivity. Avoiding security breaches and compliance failures are non-negotiables for the team to maintain customer satisfaction.
Challenges
Secure deployments without cloud connectivity
Air-gapped vulnerability scans for highly regulated industries
Highly regulated industries require high trust partnerships
Solutions
Anchore Enterprise secures the software supply chain with:
Support for on-premises and air-gapped deployments
Comprehensive vulnerability scanning integrated into CI/CD pipeline
Automated SBOM generation to build trust fast
Results
75% reduction in time spent on vulnerability management and compliance requirements
70% faster production deployments with integrated security checks
Rapid trust development through transparency
Introduction
DreamFactory is an API generation platform that puts a REST API endpoint in front of every table, view, or stored procedure in a database. It then wraps every endpoint in enterprise-grade security, including role-based access control (RBAC), key management, authentication, and rate limiting. With industry estimates reporting that 70% of APIs are internal or private, DreamFactory’s solution is critical for organizations looking to streamline their API development process securely. Built on a Laravel (PHP) web application with Redis and MySQL, DreamFactory releases a new major version quarterly while running daily security scans. The DreamFactory product is designed for on-premises deployment. Anchore Enterprise is deployed in AWS and GitHub actions make callbacks to Anchore for security checks.
Challenges
DreamFactory faced several critical challenges in meeting the needs of its customers, particularly those in the defense community and other highly regulated industries:
Secure deployments without cloud connectivity
With the ascent of the cloud deployment pattern, always-on internet connectivity became a foundational assumption for customer deployments. Modern software supply chain security took this to heart by adopting continuous scanning strategies that required direct access to production services.
DreamFactory works with the DoD and other highly regulated organizations, such as Oil and Gas. The data that is processed by these organizations have the highest national security implications. The assumption of always-on connectivity no longer holds. On-premises deployments are mandatory, and air-gapping is almost always required. This broke the assumptions of modern software supply chain security strategies and required new solutions to deliver bulletproof security without cloud connectivity.
Air-gapped vulnerability scans for highly regulated industries
Typically, if software is run on-prem and air-gapped the need for vulnerability scanning is not required. If vulnerabilities do exist they are not considered a priority due to the fact that they have no external connectivity that gives an adversary remote access to the service.
While this is common practice in the enterprise world, this is not the case in highly regulated environments. Both air-gapping and vulnerability reporting are mandatory to protect the data that these organizations process.
Highly regulated industries demand high trust partnerships
In highly regulated industries, particularly those involved with national security or critical infrastructure trust is a necessity rather than a nice-to-have. Organizations like the DoD and critical infrastructure providers operate in high-stakes environments where security breaches or compliance failures can have catastrophic consequences. The potential to compromise national security, endangering lives, or cause severe financial damage is ever present.
These entities face constant, sophisticated threats from state-sponsored actors, cybercriminals, and other malicious entities. In this context, every software component, partnership, and integration point represents a potential vulnerability that adversaries could exploit, making rapid establishment of trust crucial.
Solutions
DreamFactory implemented Anchore Enterprise to address these challenges:
Comprehensive Vulnerability Scanning
In order to generate vulnerability reports without having access to the air-gapped deployments, Dreamfactory integrated Anchore Enterprise into its own build pipeline and ran daily vulnerability scans on all deployment versions. Dreamfactory then notifies their customer’s of urgent vulnerability updates, fulfilling their commitment to continuous vulnerability scanning and compliance.
By catching the vulnerabilities in our build pipeline, we can then inform our customers and prevent any of the APIs created by a Dreamfactory install from being leveraged to exploit our customer’s network. Anchore has helped us achieve this massive value-add for our customers.
—Terence Bennet, CEO, Dreamfactory
Automatic SBOM Generation
Anchore’s automated SBOM generation is directly integrated into Dreamfactory’s build pipeline so that every build is cataloged and stored for reference. An SBOM serves as a trust accelerator in a high-threat environment. It provides immediate transparency into the software’s ingredients which enables fast risk assessment and compliance verification.
Since the publication of Executive Order 14028, “Improving the Nation’s Cybersecurity” in 2021 all branches of the federal government have taken the “suggestion” that SBOMs are a necessary element of software supply chain security seriously.
We’re seeing a lot of traction with data warehousing use-cases. Security is absolutely critical for these environments. Being able to bring an SBOM to the conversation at the very beginning completely changes the conversation and allows CISOs to say, ‘let’s give this a go’.
—Terence Bennet, CEO, Dreamfactory
Results
The implementation of Anchore Enterprise transformed Dreamfactory’s security posture and business operations:
75% reduction in time spent on vulnerability management and compliance requirements:
Automated vulnerability scanning and reporting, even for air-gapped deployments frees up engineering cycles for mission critical work.
70% faster production deployments:
With vulnerability scans integrated into the CI/CD pipeline, Dreamfactory can deploy updates more rapidly without compromising security.
Rapid trust development through transparency:
An automated and complete SBOM record accelerates trust development in an environment where the stakes are unparalleled.
“Anchore has not only helped us meet the stringent requirements of organizations like the DoD,” concludes Bennet, “but it has also given us a competitive edge in the market. We’re now able to provide a level of transparency and security that our customers in highly regulated industries demand, all while maintaining the efficiency of our development and deployment processes.”
By leveraging Anchore Enterprise, Dreamfactory has positioned itself as a trusted partner for organizations requiring the highest levels of security and compliance in their API management solutions.
Download the PDF version of this case study for DreamFactory.
Infoblox, a leader in Enterprise DDI (DNS, DHCP, IPAM), required a reliable container vulnerability scanning and management solution to scale the program to 150 applications developed by 600+ engineers. Product security and compliance are critical business functions at Infoblox. The trust created by these teams are foundational to business success and continuity.
Challenges
Shift left security at scale; vulnerability detection & management to prevent vulnerabilities from entering production
Resourcing challenge; Automation needed to scale 15 Security FTEs to meet output of 600+ Engineering FTEs
Meet and maintain compliance certifications (FedRAMP moderate, SOC 2, StateRAMP, ISO 27001)
Enterprise integration into existing pipeline and infrastructure (e.g., Amazon EKS, Harbor registry, Jenkins CI, etc.)
Solutions
Anchore Enterprise secures the software supply chain with:
Container image scanning with low false positives
Vulnerability and CVE Management
Native integrations with Amazon EKS, Harbor and Jenkins
FedRAMP, SOC 2, StateRAMP, and ISO compliant platform
Results
75% reduction in time for manual vulnerability detection tasks
55% reduction in hours allocated to retroactive remediation of vulnerabilities
60% reduction in hours spent on compliance tasks
Empowered product security team to adopt proactive—shift left—security posture
Introduction
Infoblox, a leading provider in the enterprise DDI (DNS, DHCP, and IP Address Management) space, has been pioneering the DDI segment for over 25 years. The enterprise DDI space is crucial for managing and automating network services, ensuring seamless and secure network operations. Infoblox manages over 150 applications in production environments. With multiple deployments per day, this leads to 1000s of containers per month that need to be scanned for vulnerabilities; On top of that, they operate both a commercial and high compliance environment (e.g., FedRAMP, etc).
The Infoblox Product Security team faced a significant challenge due to the lack of an existing vulnerability detection and management program. Previously, apps were deployed to production without any knowledge of potential vulnerabilities or manually reviewed after the deployment.
Scaling security with low false positive rate
Given the scale of the software development program at Infoblox (i.e., 1000s of containers built monthly), manual scanning and review was not a viable strategy. Furthermore, the product security team, consisting of only 15 full-time employees (FTE), was vastly outnumbered by the 600 FTEs in engineering, resulting in a 40:1 ratio. This disparity made it essential to have a vulnerability scanning tool with a low false-positive rate to scale the vulnerability management program effectively.
Scaled security without friction
The existing development tools and infrastructure, such as Amazon EKS, Harbor registry, and Jenkins CI, required a solution that could seamlessly integrate without disrupting the current DevOps workflows.
“When I first started, I was manually searching GitHub repos for references to vulnerable libraries but it was impossible to tell whether the codebase was a test repo, staging or not even in use. Anchore’s SBOM inventory gave us certainty that a vulnerability was actually in production and needed to be fixed.”
—Sukhmani Sandhu, Product Security Engineer
Automation was necessary to manage the high volume of applications and deployments, ensuring vulnerabilities were detected and managed efficiently.
Compliance at scale
Another layer of complexity was added by the need to acquire and maintain multiple compliance certifications, including FedRAMP Moderate, SOC 2, StateRAMP, and ISO 27001. Infoblox required a secure and compliant vulnerability management system to meet existing compliance requirements and facilitate the attainment of new certifications. Not only did the organization prioritize these business critical certifications but the security team was charged with meeting these new requirements without dropping any of their existing responsibilities. They needed a solution that could not only meet compliance but allow the team to scale their efforts.
Solutions
To address these challenges, Infoblox chose Anchore Enterprise as their container vulnerability scanning and management solution.
Save time – more signal and less noise
Anchore Enterprise’s low false-positive rate was a critical factor in this decision, enabling the product security team to scale their efforts effectively despite the 1000s of containers being deployed every week. Every false positive eliminated means less time wasted by the Product Security team and more time dedicated to remediating actual threats to the organization
Less fire fighting in production
Centralized vulnerability and CVE management, allowed the Product Security team to proactively remediate vulnerabilities when a container image is checked-in to the container registry, Harbor. This early detection was a significant step in Infoblox’s shift-left strategy for product security. On top of this, developers from the engineering organization began to self-serve AnchoreCTL in order to scan their source code for vulnerabilities while they were authoring it. This helped Infoblox catch vulnerabilities even before the source code was sent to Jenkins for the build process.
Enterprise integration with DevOps speed
Anchore Enterprise seamlessly integrated with Infoblox’s existing software development infrastructure and tooling, including Amazon EKS, Jenkins CI, and Harbor. This integration ensured that the new vulnerability management processes did not disrupt the current workflows and still allowed the product security team to scale their vulnerability detection and management efforts in the high-output DevOps engineering environment.
FedRAMP, SOC 2 and ISO compliance in rapid deployment environment
Additionally, Anchore Enterprise helped Infoblox achieve and maintain compliance certifications, such as FedRAMP Moderate, SOC 2, StateRAMP, and ISO 27001. Not only does Anchore Enterprise meet existing compliance standards, it helps Infoblox meet compliance controls, specifically the NIST 800-53 control family (RA-5). Infoblox was able to take advantage of both of these benefits by choosing Anchore Enterprise for vulnerability scanning and compliance certification. All of this while not adding friction to the high-speed development cadence and speeding up the compliance process.
“We’re not trying to waste our team or other team’s time. We don’t want to report vulnerabilities that don’t exist. A low false-positive rate is paramount. FedRAMP is very stringent and we don’t want to create more work for ourselves given our limited resources.”
Anchore Enterprise transformed Infoblox’s product security program by enabling the team to scale their efforts, automate compliance and maintain the speed of deployments.
75% reduction in time for manual vulnerability detection tasks
55% reduction in hours allocated to retroactive remediation of vulnerabilities
60% reduction in hours spent on compliance tasks
By reducing the amount of time spent on manual security and compliance tasks, Infoblox opened the product security team up to focus on higher value initiatives like automating policy and remediation.
Developers self-adopted scanning tools during development, removing vulnerabilities before they entered the build pipeline. This proactive approach led to a 55% reduction in hours allocated to retroactive remediation. Both teams could now manage risk collaboratively, knowing about vulnerabilities before applications were pushed to production.
During incident response, a centralized inventory of all SBOMs enabled quick searches in Anchore Enterprise, reducing the need for extensive codebase searches. This automation reduced manual vulnerability detection time by 75%.
Additionally, the automation of compliance reporting artifacts resulted in a 60% reduction in hours spent on compliance tasks, dramatically improving how quickly compliance could be certified and the number of hours needed to meet the compliance requirements.
“We effectively had no tooling before Anchore. Everything was manual. We reduced the amount of time on vulnerability detection tasks by 75%.”
Iron Bank is a program within the Department of Defense (DoD) that enables easier adoption of DevSecOps solutions and provides transparency into containerized software throughout the DoD. It provides Platform One and any DoD agency with a hardened and centralized container image repository that supports the end-to-end lifecycle needed for secure and dynamic software development.
Challenges
Provide DoD agencies with hardened components for downstream software applications
Fulfill extremely rigorous security standards that ensure the safety and integrity of military systems
Low deployment frequency and policy compliance due to constantly changing security threats
High toil on false positives
Solutions
Anchore Enterprise secures the software supply chain of Iron Bank with:
An on premise and distributed container image scanner
A turnkey SBOM generation and management solution
Automated policy engine that evaluates and enforces security standards and compliance
Results
Reduced false positives on customer deployments without requiring administration changes or software updates
Delivered accurate SBOMs with improved mapping to vulnerabilities for hardening of downstream applications
Jointly developed a codified custom policy to enforce the DoD Container Hardening requirements
Enabled the systematic distribution of an always up-to-date Iron Bank DoD policy bundle to downstream users and projects
Introduction
Iron Bank is Platform One’s hardened container image repository that supports the end-to-end lifecycle needed for modern software development. Iron Bank runs on Cloud One, a DoD multi-cloud ecosystem, which runs in AWS GovCloud.
Iron Bank centralizes infrastructure tools and standardizes application hardening throughout the DoD to create a proactive security stance that protects modern military infrastructure, equipment, and the military workforce.
AWS Services: GovCloud
Challenges
Iron Bank faces the complex task of balancing deployment velocity, software, and policy compliance (according to the DoD Container Hardening Guide), all while maintaining rigorous security standards and adapting to new security threats. The Iron Bank development team is responsible for the integrity and security of 1,800 base images that are provided to build and create software applications across the DoD.
Iron Bank not only provides all software components that are used for Platform One but also distributes them across the DoD. It’s imperative that they can efficiently scan images and simultaneously adhere to rigorous security standards that guarantee the safety and integrity of military systems. Another challenge is addressing false positives effectively. Due to the high volume of images and vulnerability management the team needs to process, false positives are time intensive and can cause significant toil.
“Even though security is important for all organizations, the stakes are higher for the DoD. What we need is a repeatable development process. It’s imperative that we have a standardized way of building secure software across our military agencies.”
Camdon Cady Chief Technology Officer at Platform One
Solutions
Anchore’s engineering team was deeply embedded with the Iron Bank infrastructure and development team to improve and maintain critical components in the DevSecOps pipeline. This supported the Iron Bank team in getting hardened containers into the Iron Bank.
Custom policy for app checks and open source containers
Since the IronBank inception in 2020, Anchore Enterprise has been the software supply chain security tool of choice. After the first iteration of Iron Bank infrastructure, Anchore started scanning container images and implemented a custom policy pack to check all images for compliance against DoD’s Container Hardening Guide requirements. This custom policy encompasses general security best practices within containers as well as application specific checks for a set of open source containers maintained by the Iron Bank team.
Lower false positives with the exclusion feed
In collaboration with the Iron Bank team, Anchore developed the exclusions feed to remove findings that were known false positives. The exclusion feed reduces the security assessment load on the Iron Bank team while addressing false positives seamlessly. At the writing of this case study, the exclusion feed captured over 12,000 known false positives. Since 2020 the following joint engineering efforts between Iron Bank and Anchore resulted in:
Time-based Allowlisting – expire allowlisted findings after a defined period of time using Anchore policy
Content Hints – add or override container software content to improve vulnerability scanning coverage for Platform One
Binary Content Type – install checks for software binaries outside of a package manager to increase coverage of scans
False Positive Management – correct false positives through a fast-feedback mechanism
Clamav Support – more thorough container scanning of all artifacts through integrated malware scanning
Image Ancestry Comparison – provide rich content while determining image ancestry, informing vulnerabilities and policy evaluations inherited from previous layers
Windows Image Scanning – scan Windows based container images
“People want to be security minded, and they want to do the right thing. And what they really want is tooling that helps them to do that with all the necessary information in one place. That’s why we looked to Anchore for help.”
Camdon Cady Chief Technology Officer at Platform One
Results
Anchore Enterprise provided Iron Bank with quality vulnerability and compliance findings to ensure that container images go through a standardized and efficient process that adheres to the DoD’s Container Hardening Guide.
Streamlines process for accurate vulnerability scanning and compliance
Anchore Enterprise empowered Iron Bank to create a standardized and efficient process for container scanning that adheres to the DoD’s Container Hardening Guide and delivers quality vulnerability and compliance findings.
SBOM Hints and Corrections to increase accuracy
To address false positives and misidentified components in a streamlined and repeatable workflow, Anchore developed and delivered two custom capabilities, SBOM Hints and SBOM Corrections. SBOM Hints and SBOM Corrections allow Iron Bank customers to adjust metadata in order to create a more accurate generation of SBOMs and improved mapping to vulnerabilities.
Time savings and reduced overhead with exclusion feed
The Anchore Vulnerability Feed enabled the Iron Bank team to reduce the occurrence of false positives and incomplete data in public feeds. To launch the vulnerability feed, the Iron Bank team handed Anchore a list of 10,000 false positives for analysis and inclusion. Iron Bank customers now benefit from live updates that immediately reduce false positives without any need for administration changes or software updates. This is made possible through the continuous monitoring and updating of the data feed. For example, all Iron Bank customers can request an assessment of potential false positives through the Anchore support portal to add new data to the feed.
In addition, Anchore enabled support for time-based allowlisting, now Iron Bank can expire allowlisted findings after a defined period of time using the Anchore policy engine.
From 2020 until today Anchore has provided ongoing support to the engineering team at Iron Bank, like providing them with custom DoD policy packs. The collaboration between Iron Bank and Anchore continues to expand and advance towards the shared goal of protecting modern military infrastructure, equipment and workforce.
Download the PDF version of this case study for Iron Bank.
Cisco Umbrella for Government is a cloud-native security solution tailored to meet the unique security and compliance needs of government agencies. It integrates multiple security functions into a single, easy-to-manage solution, ensuring comprehensive protection across various environments, including remote work settings.
Challenges
Meet all 6 FedRAMP vulnerability scanning requirements
Maintain and automate STIG & FIPS compliance for Amazon EC2 virtual machines
Meet SBOM requirement for White House Executive Order (EO 14028)
Solutions
Anchore Enterprise secures the software supply chain with:
Distributed container security scanner
Automated policy engine (security & compliance evaluation and enforcement)
Turnkey SBOM generation and management
On-prem cloud deployment model
Results
Achieved FedRAMP, FIPS and STIG compliance in weeks versus months
Reduced implementation time
Improved developer experience by integrating directly into existing workflow
Future-proofed compliance against anticipated requirements
Introduction
Cisco Umbrella is an AI powered cloud security platform that delivers a holistic security suite for enterprises. This includes security service edge (SSE), cloud application security, endpoint protection and incident response services to defend organizations from internal and external threats. Cisco Umbrella manages a complex environment with a number of different compliance requirements. They utilize AWS GovCloud to provide their services to federal agencies and need to meet FedRAMP, FIPS, STIG and EO 14028 compliance for their entire GovCloud deployment.
Build and deployment environment:
AWS Code Pipeline
AWS Elastic Container Registry (ECR)
Amazon Elastic Kubernetes Service (EKS)
Amazon Elastic Container Service (ECS)
Challenges
FedRAMP compliance is table stakes for the Cisco Umbrella organization in order to serve their customer base. Over the past decade FedRAMP has become more complex and comprehensive—its high impact level has over 400 controls alone.
The challenge was ensuring Cisco Umbrella’s complex cloud infrastructure met all of the relevant compliance objectives and maintained compliance over time. Of particular concern was securing the software supply chain for container vulnerabilities that could potentially leak into their applications via 3rd-party dependencies.
In order to achieve FedRAMP compliance, Cisco had to meet the following 6 vulnerability scanning requirements for containers:
Hardened and compliant container images
Automated build pipeline with policy enforcement
Vulnerability scanning in the build pipeline and container registry
Security sensors to prevent malware in the pipeline, registry, and in production
Container registry monitoring with notifications on non-compliant images
Asset management with a full inventory of containers in production
Additional high-security requirements
Furthermore to meeting FedRAMP compliance, Cisco Umbrella’s container vulnerability scanning solution is also required to be deployed into a High-Security environment. This came with the additional requirements that:
STIG compliance for compute infrastructure
FIPS compliance for compute infrastructure
EO 14028 compliance for software supply chain
Solutions
Cisco Umbrella selected Anchore, the leading software supply chain security platform specializing in container security, vulnerability management and the automation of compliance standards to solve their challenge. Anchore Enterprise integrated seamlessly with Cisco’s existing infrastructure and empowered them to meet all six FedRAMP requirements for vulnerability scanning and the additional STIG, FIPS and EO 14028 compliance within the project deadline that was only weeks out.
Proactive vulnerability detection
After Cisco Umbrella integrated Anchore Enterprise into its developer’s workflows, engineers were able to proactively uncover vulnerabilities at the time of development. This saved hours of developer time by alerting them to problematic dependencies before they began writing application code that would need to be remediated at deployment time.
Save time with built-in policy packs
Cisco Umbrella takes advantage of Anchore Enterprise’s built-in FedRAMP compliance policy pack to evaluate each scanned container for FedRAMP compliance. With the pre-build policies the Cisco Umbrella team can focus on resolving the non-compliance rather than translating NIST documentation into software checks. Anchore’s policy engine manages the process of evaluating a container against these policies and returning a PASS or FAIL signal back to the CI/CD process that then either gates the deployment or allows it to continue through the pipeline.
Automated security data management
As with many modern DevSecOps platforms, Cisco Umbrella also generates hundreds or even thousands of containers daily. Complying with EO 14028 requires an SBOM for each container. This quickly becomes a data management nightmare. As a turnkey solution, Anchore Enterprise includes a complete SBOM management solution to store and analyze this security data. This saves the security team time from having to manually collect and manage the data.
Simplified compliance via inheritance
Different from most cloud-based security solutions, Anchore Enterprise is deployed on-prem within a customer’s own cloud environment. The key advantage is that customers have full control over the system and can inherit the underlying compliance standards that the cloud provider has achieved. This is how Cisco Umbrella was able to take advantage of the FedRAMP compliance aspects of Anchore Enterprise without jeopardizing the FIPS compliance that their cloud infrastructure provider had achieved. This isn’t possible with traditional SaaS-based cloud security providers and is a unique advantage that is valued by Anchore’s enterprise and public sector customers worldwide.
Outcome
Cisco Umbrella was able to significantly reduce implementation time of FedRAMP compliance requirements. The time to compliance was reduced to weeks versus the more typical months. The team was able to overcome 4 compliance hurdles in parallel; FedRAMP, STIG, FIPS and EO 14028. The security team improved developer experience for container security vulnerability by integrating directly into existing development workflows. This both reduced the friction of security testing and enabled developers to discover vulnerabilities in development rather than production. Finally, Cisco Umbrella has ensured compliance with anticipated requirements. This increased confidence that there won’t be unexpected compliance work in the future.
The NVIDIA Product Security organization transitioned from Anchore open source to Anchore Enterprise for continuous container security, driving increased scalability and productivity, policy-based compliance, and role-based reporting for business units and security teams.
Challenges
Significant container use with thousands of containerized apps, and hundreds of thousands of containers
Provide a scalable security process to support growing container adoption with diverse requirements across business units, including large containers of up to 25 GB+
Address the critical security requirements of NVIDIA GPU Cloud (NGC), a curated catalog of GPU-optimized software containers for NVIDIA customers
Current security scanning tools for traditional software didn’t work for containers. They were complicated to use, time consuming to run, and generated too many false positives
Automate security checks across multiple CI/CD toolchains, registries, and Kubernetes platforms used by different business units
Solutions
Anchore Enterprise
Anchore Syft
Results
Improved developer and security team productivity with a centrally-hosted version of Anchore Enterprise
Ability to ramp up scanning and speed CI/ CD pipelines due to scalable architecture of Anchore
Robust, fully-documented APIs for Anchore made it quick and easy to integrate with multiple CI/CD tools and registries as well as existing product security processes
Improved inline scanning for CI/CD pipelines to enable vulnerabilities to be identified early in the cycle, avoiding delays
Reduced number of false positives due to Anchore’s optimized use of vendor-specific vulnerability feeds
Utilized Anchore’s flexible policy engine to allow each business unit to create and run their own compliance checks
Centralized metrics for the security team on container scans and results
Introduction
NVIDIA is an organization known for its GPUs utilized in computing tasks as diverse as computer graphics rendering and cryptocurrency mining. The most important new use case that GPUs have been utilized to solve is artificial intelligence (AI) and machine learning (ML) tasks. NVIDIA has invested in this segment from both a hardware and software perspective. In 2017 they launched NVIDIA GPU Cloud (NGC) a cloud platform that is specifically designed to power AI/ML workloads. NGC brings together NVIDIA managed GPU infrastructure as well as the AI/ML software components that are industry standard to create a platform that makes it simple to train generative large language models, object detection models, text-to-speech models, and more.
“Our goal was to integrate DevSecOps principles into our SDLC and build an “easy button” for developers to get their code scanned and secured.”
The NGC platform is a curated container catalog that hosts a broad range of software including generative AI models, deep learning frameworks, high performance computing (HPC) and visualization applications that maximize the utilization of NVIDIA’s GPU environments. Given that NGC is publicly available for NVIDIA users and customers, software hosted on NGC must undergo scans by Anchore against an aggregated set of common vulnerabilities and exposures (CVEs), as well as secrets and private keys.
“We were able to actually scale our container security program while saving money.”
The results of security scans from Anchore Enterprise are housed in nSpect, an enterprise- wide reporting platform where the product security team collects data from each software development team about known vulnerabilities and dependencies in their applications. Anchore Enterprise will be used across development teams to enable inline scanning of containers during the CI/CD process, providing vulnerability reports to nSpect via API. The nSPect data is used to deliver security reports to the VPs of each business unit showing their risk profile.
The NVIDIA Product Security organization — an arm of the Software GPU division that reports directly to NVIDIA’s CEO — transitioned from Anchore open source to Anchore Enterprise to provide scalable inline container scanning in their CI/CD pipeline, centralized container security reporting, and an API-friendly solution that would integrate into the myriad of different DevOps tools used across their business units.
Previously, NVIDIA was using Anchore open source. However, NVIDIA had not set up a centrally-hosted version of Anchore, creating overhead for each development team. By deploying a centrally-hosted version of Anchore Enterprise, the NVIDIA product security team created a scalable solution, a better experience for development teams, with a goal for providing each business unit VP visibility into their risk profile.
Challenges
As container adoption accelerated, NVIDIA needed a way to implement security scans for containerized apps throughout the development process. NVIDIA uses containers at a large scale with thousands of containerized apps, and hundreds of thousands of containers. One of their larger teams pushes tens of thousands of containers a day through the development pipeline. NVIDIA also faced a unique challenge because of the large container image sizes they must scan in their pipelines. It was critical that they choose a container security solution that they could easily embed in their development process and scale effectively to avoid creating any bottlenecks.
“Anchore gives us a centralized point with logging and metrics for a complete picture of our container security. We know exactly how many teams are scanning and what sort of images are failing.”
Each application team at NVIDIA selects their own tools. This constraint focused the product security team on sourcing a container scanning tool that could easily integrate via APIs with a broad range of CI/CD pipelines including TeamCity, GitLab, Jenkins, Azure, Google Cloud and homegrown solutions. The tool also had to integrate with registries including Docker Hub, Quay, GitLab, and NGC.
“We are API-driven so our end users do not use the UI. The Anchore API is completely documented and provides nice REST response codes that are much more obvious to the developers.”
While NVIDIA already had security scanning tools for traditional software, these tools didn’t work for containers. They were complicated to use, time consuming to run, and generated too many false positives. Reducing false positives was an important requirement for the NVIDIA product security team and the developers they support. While almost every scanning solution can identify a Python package and provide a list of vulnerabilities, NVIDIA needed the ability to identify vendor-specific variants (such as Ubuntu with OpenSSL patches) and then to include only vulnerabilities that had not been patched in the version that was being used. Without granular identification, developers receive too many false positives, leading them to ignore the security team.
Solutions
The NVIDIA team got Anchore Enterprise up and running within an hour using the Helm charts and documentation provided by Anchore. With a scalable architecture, Anchore Enterprise can scan high volumes of containers without causing large delays in development pipelines
“Almost anyone can identify a pipeline package, but if you can’t tie it back to a vendor’s versions, you get a huge list of false positives. Anchore is way ahead of the game, leveraging vendor-specific vulnerability feeds which results in fewer false positives.”
NVIDIA is API-driven and developers use the Anchore Enterprise API to integrate directly into their CI/CD pipelines. NVIDIA was able to leverage Anchore’s robust, fully-documented APIs and REST response codes that are meaningful to developers.
NVIDIA wanted to decentralize security policies, allowing each business unit to set their own policies. Teams can define policy documents tied to the SHA of individual files, and if teams choose to bypass a vulnerability, they can adjust their policy and document the exception.
Anchore Enterprise provides NVIDIA with a centralized point where the security team can get logs and metrics that show how many people are conducting scans, what images are failing, and related information. NVIDIA uses the Anchore’s command line tool, AnchoreCTL (based on the open source project Syft), to generate SBOMs from the pipeline and then post them in Anchore Enterprise.
“Anchore’s architecture has worker threads that can scale up and scan quickly, keeping the development pipeline moving as the number of containers increases.”
Results
By implementing Anchore Enterprise, NVIDIA teams can scan containers during the development process before they ship to internal and external customers. This ensures a high level of security and empowers development teams with the responsibility of resolving security issues prior to release time.
Moving to a hosted solution and Anchore Enterprise enables the NVIDIA product security team to provide a scalable solution that addresses the scanning challenges that the large containers in the NGC pose without a loss in developer or security team productivity. The move also lets them get their false positive challenges under control, saving developers and the security team time.
“I was able to get up and running in an hour with Anchore Enterprise using just the documentation and the Helm charts provided by Anchore. When I found areas for improvement in the docs, I was able to submit merge requests and they were quickly approved.”
Download the PDF version of this case study for NVIDIA Secures Containers with Anchore.
The United States Department of Defense (DoD) is taking a completely new approach to building, deploying, and operating software.
On the way out: slow-moving, waterfall-driven development processes that result in monolithic, hard to manage applications. They have come to the conclusion that the traditional way of delivering software is expensive and inflexible, and the situation for today’s warfighters demands maximum efficiency. There are too many lives at risk if the DoD fails to innovate, and too much geopolitical competition.
Advanced enterprises solve this problem through the implementation of cloud-native technologies such as Kubernetes and the implementation of DevOps practices. Using this combination of tools and tactics, software can be delivered in much smaller components and updated frequently. This results in a very quick pace of development, and allows for frictionless reuse of components between teams and communities. Automated build, integration, and deployment can reduce the lead time to deliver warfighter capabilities from months to minutes.
The DoD needs to deliver software to the warfighter at the speed of operations, so they have built a new platform and software supply chain to remove bottlenecks on their cloud-native journey. The foundation of this platform is an automated DevSecOps pipeline that bakes in automated security and compliance checks before delivering to a CNCF compliant Kubernetes cluster. This allows them to build and consume software at the pace required to maintain their competitive edge. However, even though security is important for all enterprises, the stakes are higher for the DoD. So while they could build on commercial best practices, there are several additional steps required to meet security standards. There is also a need to deploy in a standardized way across various disparate environments, from traditional on-premise environments to special regions of public cloud and even small footprints at the tactical edge.
Over the past 12-months, Anchore and Red Hat have worked side by side to develop and implement an automated process for hardening and securing containerized software within the United States Air Force. Anchore is the only container security vendor providing hands-on support as part of the U.S. Department of Defense DevSecOps Platform (DSOP) initiative. The beating heart of the DSOP initiative is a powerful Kubernetes cluster that can run on any infrastructure. In many cases, including this one, the Kubernetes cluster is powered by Red Hat OpenShift. This paper, based on hands-on experience working with our government partners in the U.S. Department of Defense and United States Air Force, provides valuable insight and guidance on best practices for secure, high-velocity software delivery.
Automated build, integration, and deployment can reduce the time from invention to production – from months to minutes.
Audience
This paper is for security teams, DevSecOps engineers, and information system security leaders who would like to learn from the steps the DoD has taken to establish high-velocity development and deployment of new services in a context where security can have life-or-death consequences. Over the past decade, the Federal Government has issued numerous executive orders and memorandums that task IT leaders to efficiently transform software development using DevOps and DevSecOps deployment models at their various agencies. We aim to provide an overview of this transformation, showing how it can be done at scale within large enterprises.
Purpose
The purpose of this paper is to understand the importance of adopting and utilizing approved hardened containers in the US Government. This paper will describe the hazards of historical DoD software deployment lifecycles and how the United States Air Force migrated away from risky development practices, relying on hardened containers running on Kubernetes as the backbone to the success of its DevSecOps Platform. Our goal is to document the USAF DevSecOps model, describe the container-hardening process currently used by USAF, and demonstrate to federal audiences how they can instantiate or augment their own DevSecOps pipelines using DoD-approved, hardened containers.
Problem Statement
The DoD, similar to other large enterprises, faces the complex task of balancing deployment velocity, compliance and security. However, they are unique from other large enterprises in that the applications they build and maintain are military systems where human lives are at stake 24/7/365.
In the past, software development at the DoD used a traditional “waterfall” development methodology with a heavy emphasis on planning and requirements gathering. As a result, the pace of innovation was slow. Both private and public industries have moved to more iterative, agile development models due to several factors. Not only are these new methodologies quicker, they also incorporate end-user buy-in from an early stage. Often, the waterfall methodology can result in a product that does not adapt to rapidly-changing requirements and operational conditions.
For those who use traditional waterfall processes, compliance often becomes a game of catch-up. When development moves slowly, security teams often rush to validate software within contract deadlines. Additionally, once a program has exhausted its budget in the development phase, it is faced with the burden of obtaining a DoD Authority to Operate (ATO). This can take at least 9 months, causing the technology that was leading-edge at the inception of the program to become out of date.
For those who use traditional waterfall processes, compliance often becomes a game of catch-up.
The economic and programmatic risks of the waterfall delivery lifecycle are clear, but the cybersecurity risks are even more detrimental. By following the model prescribed above, software teams are locked into older, often deprecated software that can’t be effectively hardened or protected. As a result, they are leaving systems open to hundreds – or even thousands – of vulnerabilities within outdated software that is no longer being maintained. Worse, these teams are often locked into contracts with third parties who deliver software slowly and make it extraordinarily challenging to stay on top of emerging vulnerabilities.
As security teams work to protect government systems, they lack the full breadth of options within the marketplace that can help them gain the upper hand against adversaries. Software designed and consumed by the DoD needs to be developed at a higher velocity, with greater efficiency, and with a focus on security in order to maintain dominance in the current cybersecurity landscape.
DevSecOps at the Department of Defense
DevSecOps is quickly becoming an optimal mode of operation for consumers of container-based technologies, from early adopters to long-time users. As enterprises move towards more agile development by implementing modern DevOps, the rate of change increases and attack surfaces become more fragmented and dynamic. The integration of security into each stage of the software development life cycle, a practice known as DevSecOps, is now critical for organizations operating in today’s cloud-native environments.
The DoD codified their new approach to software creation and management in the DevSecOps Reference Design. This document, hosted at software.af.mil and linked from the Anchore Federal web page, contains a roadmap for various defense agencies and programs to dramatically overhaul the traditional waterfall software development practices in common use. It has resulted in the creation of a new platform for DevSecOps known as Platform One.
In their DevSecOps Reference Design, the DoD defines DevSecOps as “a collection of software-integrated tools, services, and standards that enable partners and programs to develop, deploy, and operate applications in a secure, flexible and interoperable fashion”. Championed by Nicolas Chaillan, Chief Software Officer of the United States Air Force (USAF), the DoD DevSecOps Initiative is charged with creating a platform that can be easily reused and implemented across all branches of the DoD.
For more information on the mission of Platform One, view this video created by members of the Platform One team.
Separating itself from DoD operational systems of the past, this new Reference Design prescribes comprehensive use of industry standards such as Open Container Initiative (OCI) containers and Kubernetes to develop and deploy software. The use of containers deployed on Red Hat OpenShift is familiar to the teams at Anchore and Red Hat, as it is the same approach taken by many of the Fortune 500 enterprises we support. Containers offer multiple advantages of particular interest to the Department of Defense. These include:
Velocity: Provisioning containers is extremely fast when compared to virtual machines or bare-metal systems. An operator can deploy, scale up, scale down, and destroy a container workload easily, and each operation takes a matter of seconds.
Cost-efficiency: Containers allow for better allocation of computing resources for specific workloads with minimal overhead. They run on readily-available, standard hardware that can be sized to support a variety of requirements and are lower cost than traditional scale-up systems.
Immutability: Once a container image is created, a hash is created that ensures it can be uniquely identified and cannot be altered as it proceeds through the development and deployment process.
Scalability: Containerized applications and environments horizontally scale with ease, reducing the costs associated with discrete hardware. Individual services can be managed and scaled separately, helping to realize a core benefit of microservices architectures.
Consistency: Platforms like Kubernetes offer a consistent control plane for applications, reducing operational costs and increasing agility. Applications are defined, deployed, and managed using a single operational toolset.
Control: Container images are layered, building upon base images that provide basic environments for applications to run within. This allows the DoD to approve and reject base images based on security best practices, providing fine-grained control over the software that is deployed.
Establishing Continuous Security
Platform One includes a prescribed set of software and capabilities known as the Sidecar Container Security Stack (SCSS), which ensures a high level of runtime security. The SCSS model offers the ability to deliver correlated and centralized logs, fully-integrated container security, whitelisting, Role-Based Access Control (RBAC), continuous monitoring, signature-based scanning based on Common Vulnerabilities and Exposures (CVEs), and policy enforcement.
Continuous monitoring and scanning of runtime systems is a critical part of a comprehensive security strategy, but it is not enough. After all, a vulnerability discovered in a running application has already created an opportunity for an opponent to inflict damage. That’s why Platform One includes processes that harden software containers before they are deployed in a mission setting. These hardening steps are integrated into the development pipeline and performed by Anchore and the Platform One team. Platform One will ultimately make hundreds of approved, hardened containers available for use.
Working in collaboration with the USAF, Anchore has developed custom policy checks for all images in the pipeline to harden them to meet the security and compliance baselines of the DoD. These policies were implemented by Anchore engineers, who work within the Platform One team to validate new images and deliver them into the DoD Centralized Artifact Registry, also known as “Iron Bank”.
The DevSecOps Reference Design specifies three main categories of container images that will be hardened and maintained:
Container images used to power the DevSecOps platform, including: CI/CD systems, code and artifact repository platforms, and tools for developers and operators
Sidecar Container Security Stack containers to be used in runtime environments for continuous monitoring and scanning of container security
Common containers to be used as a baselines for software development by engaged agencies and programs
The container hardening process also applies to common containers from third party Independent Software Vendors (ISVs) looking to provide software to the DoD. In order to do so, ISVs will be required to interact with several key infrastructure services: Repo One and Iron Bank. More information about these services can be found in the following sections.
Continuous monitoring and scanning of runtime systems is a critical part of a comprehensive security strategy, but it is not enough.
The Container Hardening Process
The container hardening process is initiated with a code push into the DoD Centralized Container Source Code Repository, also known as Repo One.
Above: Example ISV project in Repo One
This repository is used to store the instruction files required to build container images (the “Dockerfiles”), along with their associated checksums and various forms of documentation. Anchore and Red Hat work together closely within the Platform One team to manage Repo One, with the ultimate goal of bringing over 170+ container images into the hardening pipeline. Anchore is a key contributor on the Platform One Container Hardening Team, which validates containers for use.
As part of the onboarding process, the Platform One team grants permissions which will allow an ISV to create a project and submit merge requests for review. Once a merge request has been submitted containing a new container image, the Container Hardening Team performs build, test, and validation steps specified in the DoD Container Hardening Guidelines document.
ISVs can find detailed information in the vendor contributors guide that can help them understand the process and get started.
A hardened container image is one that adheres to the container format published by the OCI and is made compliant with the DoD Container Hardening Security Requirements Guide. The container hardening process consists of a Jenkins job that pulls the Dockerfile from Repo One, builds an OCI-compliant container image, and pushes that image to the Repo One image registry. This automatically triggers the container scanning pipeline. The DSOP team validates that the ISV has staged their files correctly in Repo One by following the contributor onboarding process. Once validated and merged into the proper branch, an automatic pipeline job is triggered to kick off the image build and scanning processes.
The Container Hardening Team uses Anchore and OSCAP to automatically review the compliance and security baseline of the container image following the build process. Anchore performs a series of policy specific and best-practice checks on every image built in our pipeline which is explored further below. The container hardening pipeline consists of Anchore and OpenSCAP. These tools each perform different functions, and enforce container image security best practices in unique ways.
Anchore is a policy-based container workflow platform that analyzes container images, maintains a centralized bill of materials, and continuously scans for known vulnerabilities and policy violations. One of the key purposes of Anchore is to mitigate insider threat within the DevSecOps lifecycle by detecting unapproved changes to Dockerfiles.
One of the key purposes of Anchore is the mitigation of insider threat within the DevSecOps lifecycle by detecting unapproved changes to Dockerfiles.
It is important to detect when a developer intentionally makes changes to a Dockerfile that are erroneous or malicious.
For example, an insider could edit a Dockerfile and cause it to make an external call to a malicious database, or download and execute a malicious Java archive. These examples can be automatically detected and stopped with Anchore using a set of flexible policies that govern the contents of Dockerfiles. This prevents malicious Dockerfiles from becoming deployable images inside an operational environment.
Once an image is built, it can contain a large amount of third party operating system packages and language artifacts like Ruby GEMs, Java JARs, Python packages, and npm modules. Anchore also performs policy checks on the contents of container images after they have been built, providing automatic application-level enforcement. Compliance requirements on software configuration, such as those required by various Security Technical Implementation Guides (STIGs), can be enforced using Anchore’s policies. For example, the STIG that provides guidance on using a PostgreSQL database requires specific lines to exist in the configuration file. Anchore can validate configuration files through policy rules that, in the case of this example, ensure that certain lines exist. If they don’t, it can prevent the image from proceeding to the next stage of the development pipeline.
OpenSCAP serves two distinct purposes. First, it performs scanning to ensure that the application that runs within a container is configured in accordance with published policy. Second, it evaluates container images against the Red Hat OVAL feed to ensure that it does not contain vulnerabilities without corresponding patches installed. The OVAL feed from Red Hat provides information on every known vulnerability that affects Red Hat Enterprise Linux, including UBI containers, as well as any mitigations or patches that are available to address exploits. OpenSCAP generates reports that reflect the overall health of the container in which an application will be run or developed.
One container hardening has been successfully completed, all scanning results and the images themselves are uploaded to the Iron Bank.
Above: the Iron Bank login screen
Iron Bank: A Stronghold For Hardened Container Images
The Iron Bank is an artifact repository that holds all hardened container images produced by the Platform One software factory. These container images have all been validated against DoD security and compliance policies defined in the DoD Container Hardening Security Requirements Guide. They have also been comprehensively analyzed by Anchore, which identifies known vulnerabilities and unsafe practices in OS & non-OS packages, libraries, licenses, binaries, credentials, secrets, and metadata.
For end users, creating an account with Iron Bank to download hardened container images is a quick and painless process that takes only a few seconds. Once authenticated, Iron Bank displays a dashboard that contains the images available for use, their approval status, and the scanning reports generated by Anchore, OpenSCAP, and the runtime scanning tools within the SCSS.
Iron Bank also shows a list of vendors whose container images are available, which grows daily as new software is hardened to the DoD standard
Above: the list of vendors in the Iron Bank, as of this writing
By drilling down on a particular container image, users can view specific instructions for downloading and sideloading the image into their own repository.
Above: the detail provided by Iron Bank for a particular image
Users can also inspect the scanning artifacts produced as a part of the container hardening process. These are formatted as a collection of CSV files with detailed pass/fail status for specific policy gates. This gives end users the ability to validate compliance in detail before downloading and deploying images.
Current Status
The images are already available for use. By following the steps above, a DoD end user can begin setting up their own DevSecOps pipeline. The scanning artifacts generated by Anchore serve as a critical component for the program achieving and maintaining Continuous ATO. As a result, this allows the program to overcome the 9-12 month timelines it takes to receive authorization to operate as it was in the past. The increased time to production greatly reduces financial burden and ultimately allows the developers to focus on increasing automation and building out new features quicker than before.
The repository already has numerous different products for programs to begin using and building their own pipelines using already approved and hardened containers. Ranging from service mesh products such as Istio, logging tools such as Elasticsearch/FluentD/Kibana (EFK), configuration management tools such as Ansible or Chef, continuous integration and source code management in Gitlab, and container security in Anchore Federal. Vendors will continue to be on-boarded into Repo1 and Iron Bank, providing the best software available for immediate use by DoD programs.
Conclusion
The Iron Bank alleviates a huge burden for developers on DoD systems, allowing them to abandon lengthy software development lifecycles of the past. By taking advantage of the DoD DevSecOps Platform and using hardened images from Iron Bank, users gain the following:
Speed: Signing up for the Iron Bank and consuming images is an easy process, and can result in hardened containers running in an end-user cluster within minutes.
Security: All images have already been hardened based on guidelines and requirements that establish a baseline of security and prevent bad practices during the build stage.
Flexibility: Iron Bank contains software from over 100 vendors, allowing users to avoid being locked-in and reliant on a single vendor in their stack. This allows end users across various DoD programs to choose the best vendor software for their own environment.
Compliance: The Iron Bank provides a record of all scans, along with a complete set of scanning artifacts for each image. Additionally, the USAF reviews vulnerability findings for each image in the Iron Bank. For images that fail to meet certain requirements, justifications with specific plan of action in order for software to remain available.
Download the PDF version of this case study for a complete look at How Anchore and Red Hat teamed up to build a DevSecOps pipeline for the Department of Defense.
Established in 2010, CloudBees is a provider of continuous integration/continuous delivery (CI/CD) tools for customers in the commercial and public sectors. Based on Jenkins open source, CloudBees CI is considered an industry-standard in the DevOps community.
CloudBees has about 500 employees worldwide, most of whom work remotely. The product development (engineering and product management) organization is about 167 employees. Product security and Jenkins security are two separate teams in this organization.
The product security team builds libraries or tools for other teams to consume and easily integrate into their pipelines. By lowering the effort needed to integrate scanning in their environment, teams could incorporate it easily into their toolchains and development life cycles.
Summary
Challenges
Industry concerns around container security in Docker images
Wanted a solution that enabled their security team to resolve Docker container security issues proactively
CloudBees allows their teams to be flexible in their choice of parent Docker images, thus wanted more governance to ensure security
Solutions
Provide container governance across projects
Lower the effort to integrate container scanning in the DevOps toolchain
All CloudBees products that generate Docker container images have to use
Anchore Enterprise as per internal corporate policy
Results
New container governance model for the company born from a greenfield project
Improved transparency into container security and compliance issues in their container supply chains corporate-wide
Capability to support customers who work in government, financial services, healthcare, and other industries with compliance mandates
Challenges
Several CloudBees customers raised concerns about the dire state of security within their Docker container images. Thus it became essential for them to have a policy feature to secure their container images. During this time, CloudBees began working with the United States Department of Defense (DoD), which currently uses Anchore Enterprise. The DoD requested CloudBees to validate their solutions against their policies proactively.
At a corporate level, CloudBees wanted to implement consistent standards for Docker container security across different products. Teams had been choosing their own parent Docker images, which had the potential to grow into a security challenge of its own.
The team decided that a best-in-class solution was necessary because CloudBees engineering management wanted to keep the product development organization focused on delivering innovation for CloudBees customers – not reinventing a wheel that was already well-made. This consideration made their “build vs. buy” decision easy.
“Scanning at scale can surface issues and help to identify things such as prioritizing specific scans over others for immediate examination.”
Solutions
Many on the CloudBees team were Anchore open source users and knew of its efficacy. These engineers advocated for an Anchore Enterprise solution. Their positive Anchore open source experience, the product’s ease of use, and a common customer in the US DoD made Anchore Enterprise a natural choice. The Anchore Policy Engine was also attractive to the CloudBees team.
The key criteria for selecting Anchore Enterprise was its policy engine and the role-based access control (RBAC) provided within the solution. Additionally, CloudBees requires that all software vendors possess a well-made API to integrate third-party tools into software pipelines.
CloudBees considered a solution from Twistlock before selecting Anchore Enterprise. However, Anchore Enterprise made better sense and was more suited to the use-cases at hand.
Results
All CloudBees software delivery pipelines that generate Docker container images now have to use Anchore Enterprise, per internal product security policy. Findings are consolidated in a central vulnerability repository for teams to triage, review, and fix within internal SLA time.
Both security and policy findings that Anchore identifies are automatically uploaded with the help of CloudBees internal tooling to DefectDojo, an open-source application vulnerability management tool in which CloudBees is actively involved.
CloudBees experienced a rise in the number of scan findings, showing the power of deep scanning using Anchore Enterprise. This new level of transparency into their container security positions allows them to remediate critical issues more quickly than before using Anchore Enterprise.
Implementing Anchore Enterprise was a Greenfield project for CloudBees. It led to a new Docker image governance model that reduced base images to better secure products that their developers build with containers.
CloudBees is now using Anchore Enterprise to bake in the right policies to support their customer needs across many different industries and government.
Download the PDF version of this case study for CloudBees.
Pitney Bowes is a global technology company providing commerce solutions that power billions of transactions in the United States and internationally. The company operates through Global Ecommerce, Presort Services, and SendTech Solutions segments. In providing such solutions, Pitney Bowes must comply with all applicable regulations and standards, including the Payment Card Industry Data Security Standard (PCI DSS).
The Pitney Bowes Product Security Team supports compliance programs across the company, starting with standard operating procedure (SOP) compliance. As part of these compliance programs, Pitney Bowes conducts PCI DSS audits. As a corporation, Pitney Bowes also supports the National Institute of Standards and Technology (NIST) Cyber Security Framework (CSF). Pitney Bowes is looking at Anchore’s suite of products, including Anchore Enterprise, for scanning their cloud environment to ensure their cloud meets International Standards Organization (ISO) standards.
Quick summary
Challenges
Implementing whitelisting for open source analysis and software composition analysis
Container deployments across a hybrid and multi-solution environment
Solutions
Anchore Enterprise enables Pitney Bowes Product Security Teams to support container compliance best practices
Results
Generate reports for review by Pitney Bowes auditors
Patch detection for Docker Containers
Customer requirements satisfied
Challenges
Pitney Bowes runs various container deployments across their enterprise, including AWS EC2 instances for Docker Containers. They are also running Amazon Elastic Container Service (ECS), Google Kubernetes Engine (GKE), and other deployments.
Solutions
The Pitney Bowes Product Security Team has been using Anchore Enterprise for two years now. They spent the first year evaluating the various enterprise features while looking internally at the best ways to implement Anchore Enterprise across teams considering using containers in their cloud environment. In year 2 of their Anchore Enterprise usage, Pitney Bowes teams have increased their use of runtime container architectures. Their teams are also using ECS and EKS more effectively than before their Anchore Enterprise implementation.
Pitney Bowes is looking at Anchore Enterprise to clarify their software composition analysis of their containers’ layers. Anchore Enterprise also helps Pitney Bowes IT leaders understand their DevOps teams’ maturity and understanding of containers. For example, the Anchore Engine provided DevOps team leads with actionable data that prompted them to review container best practices with their teams. While in the past leadership spoke to their development teams about containerization approaches, they now have the data to understand what their teams are doing with containers across their CI/CD toolchain. As a result, the development teams have the actionable insights from Anchore’s reporting tool to streamline delivery and improve security.
Results
Pitney Bowes makes use of Anchore scanning and reporting inside their security organization.
They also use Anchore Enterprise as a patch detection tool for their Docker container deployments. The Product Security Team saves these reports for auditor review.
Pitney Bowes is leveraging the new Anchore policy for malware scans and is seeing the value in the new policy as part of their container security checks.
About Pitney Bowes
Pitney Bowes (NYSE:PBI) is a global technology company providing commerce solutions that power billions of transactions. Clients around the world, including 90 percent of the Fortune 500, rely on the accuracy and precision delivered by Pitney Bowes solutions, analytics, and APIs in the areas of ecommerce fulfillment, shipping and returns; cross-border ecommerce; office mailing and shipping; presort services; and financing. For 100 years Pitney Bowes has been innovating and delivering technologies that remove the complexity of getting commerce transactions precisely right. For additional information visit Pitney Bowes, the Craftsmen of Commerce, at www.pitneybowes.com.
Download the PDF version of this case study for Pitney Bowes.
Lark extends the concepts of smart health and lifestyle hacking beyond a traditional consumer fitness tracker to significantly improve patient outcomes in clinical medicine. By combining smart, connected-health devices with a powerful artificial intelligence (AI) platform, Lark provides personalized, interactive health coaching for pre-diabetes and hypertension patients. The health tech market, mostly having to maintain compliance, temper Lark’s need for agility. Alongside the usual challenges of creating a superlative product, medical startups also have to operate within a harsh regulatory environment, with long lead-times to market and some of the highest testing and security standards.
In the United States, state and federal regulations govern medical products. Health Tech firms such as Lark must consider The Health Insurance Portability and Accountability Act (HIPAA) at every development stage. Failure to comply with HIPAA is a serious offense, carrying a maximum of a $50,000 fine per violation. In 2019, the average cost of a data breach in the US medical industry was $6.45 million.
For health tech startups, a security breach can be an existential threat. Even without the risk of substantial fines, the public views medical data as being sacrosanct. Losing any medical data risks irrecoverable reputational impact.
At a glance
Challenges
An explosion of containers and tags.
Each additional container and tag had the possibility of introducing new common vulnerabilities and exposures (CVEs) and security issues into their system, either from a directly installed application.
Scanning Lark images in production.
Solutions
Implement Anchore Enterprise in Passive Analysis Trigger Mode in their development environment to allow continuous container deployment and. scanning of only the images in production.
Results
Utilizing Anchore, Lark was able to replace a manual and labor-intensive task with an automated, developer-friendly workflow.
With Anchore Enterprise and its reporting, the company connected the security team to the application development lifecycle without burdening them with additional manual work or slowing down development.
Challenges
Lark faced a common problem many container-first development teams face: an explosion of both containers and container tags to manage.
Most container workflows will naturally produce a constant stream of new containers. After passing through a CI pipeline, it is common practice for every application or service to have a container created, tagged, and then pushed to a container repository. They exacerbate this challenge in platforms that have adopted a microservices pattern, where many components contribute to the overall scale and pace of container sprawl.
The judicious use of automated life cycle policies (where these exist) can reduce container sprawl. However, it is still commonplace for companies to have hundreds, if not thousands, of images and tags.
For Lark, the real problem was that each additional container and tag had the possibility of introducing new common vulnerabilities and exposures (CVEs) and security issues into their system, either from a directly installed application dependency or from an inherited base container.
“With Anchore Enterprise and its powerful reporting, Lark connected their security team to the application development lifecycle without burdening them with additional manual work or slowing down development.”
Solutions
The team’s approach to implementing Anchore was to minimize the disruption of introducing a new tool. Rather than re-writing the many CI/CD pipelines in use at Lark, Tyler took the approach of leveraging the Kubernetes admission controller together with a tiered approach to policies, getting more permissive with each step further left:
Production: The DevOps team implements Anchore in production to scan all images in production. Anchore provides reports of the vulnerabilities that are in production allowing the Security and Eng teams to review and remediate them.
Result
With Anchore Enterprise and its powerful reporting, Lark connected their security team to the application development lifecycle without burdening them with additional manual work or slowing down development.
Anchore has allowed Lark to substantially increase visibility into potential security issues without requiring massive amounts of operational effort. It is integrated into existing workflows without necessitating a change of procedures and offered valuable insights into how containers are being used.
“By adopting a graduated application of modes, the Lark DevOps team could guarantee Lark’s platform’s operational safety while ensuring that development cadence was uninterrupted.”
Download the PDF version of this case study for Lark.
Hypothekarbank Lenzburg (HBL) was founded in 1868, and while the bank is deeply rooted in Swiss banking history, it is definitely not stuck there.
HBL delivers cutting edge-products and services to its customers, from hybrid banking offices to block chain accounts. The bank’s technology team also operates as a growing technology service provider in its own right, and is widely recognized as a pioneer of open banking within the Swiss financial sector.
HBL is constantly looking to support its development team, embracing technological progress and smoothing processes to increase the pace of innovation. One example is the adoption of a language agnostic approach, with multiple programming languages in use throughout its own infrastructure. And HBL has also jumped at the opportunities presented by containerization, implementing Red Hat’s OpenShift platform to run containerized workloads in Kubernetes.
HBL has jumped at the opportunities presented by containerization
However, the bank’s progressive attitude to technology has brought with it significant new challenges for the internal security team. In common with many banks, HBL formerly maintained a firm framework around the auditing, automation and scanning of servers for security issues. Aspects such as user permissions, service accounts and which software packages are installed, were all monitored and tightly controlled within the bank’s traditional infrastructure.
Containerization can deliver massive benefits for any organization, dramatically speeding development, encouraging reuse and standardization, and often forming the core of an effective DevOps strategy. However, containers can also be challenging for organizations that have existing and mature processes around server management. The ease with which containers can be both built and distributed makes it impossible to manually keep track of what software is being introduced into your environment.
“More and more of our software, from both internal and external developers, is now delivered as containers. This made it very hard for our traditional vulnerability management solution to keep up because it couldn’t scan containers efficiently,” said Sascha Kaufmann, Head of IT Security at HBL. “We also needed a way to ensure a level of compliance on container deployment – such as enforcing certain base images or ensuring that no root user was allowed.”
More and more of our software, from both internal and external developers, is now delivered as containers
Traditional asset registries were built for a time of ‘fixed’ servers. They ‘fixed’ servers. They on custom agents or, at least, an SSH connection tobe present. And neither of these are likely to be available within a container. Even where teams have the considerable resources needed to manually audit containers with existing tools, most will struggle to keep pace with the rapid rate of change inherent in containerized workflows. This leads to these legacy systems delivering a view that is outdated at best, and at worst, wildly misleading.
Together, these challenges presented a major issue for HBL. Especially, since one of the many rules of the Swiss Financial Market Supervisory Authority (FINMA) requires regular, and accurate, security auditing of all software running in production.
It was obvious that HBL’s existing software scanning tools and processes could no longer offer a secure solution, so the bank started by considering the larger security suites including Aquasec and Twistlock.
“At the beginning of our container journey, we were looking for a suite of tools that would cover firewalling, intrusion prevention, policy enforcement, and vulnerability management across our whole environment.” Kaufmann explains, “But for a team like ours, the problem with this approach was human resourcing. Even where a vendor can offer you an all-in-one solution, it takes a lot of time to plan, deploy, maintain and monitor all these aspects.”
A search into newer, more agile, open source solutions led HBL to Anchore. This offered a focused solution for HBL’s main concern: container security.
“Anchore didn’t try to solve all of our security problems at once. It has a clear focus on a core aspect: vulnerability management and policy enforcement in containerized software,” Kaufmann continues. “If you have a small team, pick your biggest pain point and then focus on fixing this. It’s a lot faster and more straightforward to deploy a focused solution.”
Anchore’s focus on solving one core requirement allowed HBL to implement container scanning almost immediately.
After a short evaluation of Anchore’s open source solution to get a feel for things, the team at HBL were convinced. The software offered a lot more than just a quick win, giving Kaufmann the missing visibility into any vulnerabilities within HBL’s container environment. In contrast to other tools offering container scanning, Anchore seemed to be tailor made to fit a container-focused development workflow and to foster a workable DevSecOps process.
“Anchore is a real ally for our developers. With any security solution, it’s important that we are not just ‘shifting an additional burden left’ and dumping it on them,” explains Valeriano Piromalli, senior software engineer at HBL. “Our developers have always been responsible for resolving security issues. But with Anchore they are in control of the process and the timing. It removes the irritation.”
“Security is no longer an afterthought: with a pile of vulnerabilities getting dumped on some developer who thought they had finished the job. Anchore makes security part of a smooth, ongoing DevSecOps process that starts from the earliest stages of design and development.”
Impressed from the outset, HBL quickly realised the potential value of some of the additional features offered by Anchore Enterprise. These included the integration into the bank’s existing authentication systems (LDAP), the intuitive enterprise UI and the enhanced vulnerability database.
But by far the biggest benefit of Anchore Enterprise was the dedicated policy interface for HBL’s security team. This has allowed Kaufmann and his team to create policies that ensure compliance in the tightly regulated Swiss finance industry. It has allowed the team to create and implement a workable baseline for container security, from where they can iterate and advance policy over time towards an evolving best practice approach.
As an implementation strategy, HBL took a two pronged approach. Firstly, Anchore has been pushed left to developers, allowing them to run ad-hoc, local scans on containers prior to deploying them. This now provides the developers with a view of any fixes needed without compelling instant action and interrupting the development process. It has helped turn security into a collaborative effort that both spreads the workload, and also engages developers to be part of the security efforts. The approach also provided the HBL security team with some immediate, valuable insights, while the work of amending the CI/CD pipelines took place in the background.
As a second part of the approach, HBL applied greater central control by adding Anchore into their CI/CD pipelines. HBL applied strict pass/fail gating to new containers as part of the publishing process. This gave developers instant feedback if their container had a high impact CVE.
“For the developers the major impact is the required change in mindset, to think of security from the outset as a part of our software development process. It is DevSecOps at work. Security is now a seamless part of our fast, smooth container-based development process,” Piromalli reflects. “We are fostering a healthy attitude that security is an ongoing issue for everyone, not a problem that the security team dumps on developers as an afterthought.”
“It is DevSecOps at work. Security is now a seamless part of our fast, smooth container-based development process”
For HBL, Anchore has been an invaluable tool on its container security journey. “Without Anchore we would still be completely in the dark about our container environment. We wouldn’t know what kind of vulnerabilities we’re facing or if a developer is running the container as root. Having a blind spot in an important part of our network wasn’t a risk we were willing to take,” Kaufmann admits.
Anchore’s focused approach on delivering a solution around container scanning and compliance, has provided HBL with a rapid fix for what had initially seemed an almost overwhelming challenge. It also allowed Kaufmann to demonstrate the criticality of security to a wider audience.
“A more focused solution is a lot faster to deploy, you’ll get your first wins, and you can show both management and developers that security in a container environment is as important as on a virtual machine in a datacenter.”
Moreover, Anchore has provided a security solution that is more in-tune with HBL’s development processes, delivering smooth, almost painless DevSecOps.
HBL is still at the start of its journey to create a full set of systems and policies around container security. Anchore has given them a running start, ensuring that the bank complies with legislation and guidance in one of the most tightly regulated industries. The work of Kaufmann and his team will underpin HBL’s container landscape for a considerable time to come, and provide them with a platform to progress their container security from compliance to industry-leading best practice.
Download the PDF version of this case study for a complete look at Hypothekarbank Lenzburg.
INDUSTRY FinTech | Infrastructure | Data Intelligence
Introduction
Named the 30th fastest-growing private software company in America on the Inc. 5000, Ocrolus’ fintech intelligence automation platform analyzes financial documents with more than 99 percent accuracy for customers in the banking and financial services sector, while transforming documents into actionable data.
Since its founding in 2014, Ocrolus has experienced impressive growth and revenue gains, which have allowed it to expand service offerings to include built-in fraud detection and analytics, that enable its customers to make smarter and faster business decisions with unprecedented precision.
At a glance
Challenges
Organization compliance policies
Default-deny whitelisting process
Lack of insight for audit & non-technical teams
Container vulnerability scanning
Solutions
Automate whitelisting
Complete vulnerability & compliance reporting
Improve stakeholder accessibility
Results
Transparent communication around compliance
Visibility on reporting for auditors
Increased productivity through automation
Customer requirements satisfied
Challenges
Ocrolus’ site reliability engineering (SRE) team is responsible for adhering to the organization’s compliance policies to ensure specific security and auditable controls around the software development lifecycle. This encompasses code review, security scanning as part of development and continuous monitoring of production.
Observing strict compliance protocols to secure personal and financial identifiable information, as well as provide visibility to the internal compliance department on security outputs was imperative. Equally important was the ability to provide transparency around the SRE team’s whitelisting process, while maintaining visibility to other Ocrolus business groups that weren’t directly involved with solution implementation. And lastly, needing continuous scanning on newly published vulnerabilities for deployed applications was critical.
“Anchore has brought a tremendous amount of value to Ocrolus.”
Solutions
A longtime open-source Anchore Engine user, the Ocrolus SRE team recognized the tremendous value that Anchore Engine brought to the organization early on. The team’s decision to upgrade to Anchore Enterprise was spurred by the need for transparent communication with organizational stakeholders around compliance; and by the importance to increase productivity and streamline other processes, such as whitelisting, among others.
Adding the full-service capabilities of Anchore Enterprise to the Ocrolus environment was an effortless and seamless process. The simplicity of implementation was based on:
Easy access to documentation, which resulted in effortless onboarding.
Product communication served in familiar language for DevOps teams.
Zero custom tooling requirements needed for system setup.
Anchore’s straightforward user interface gave auditors instant access to information when they needed it. By clicking the compliance tab, compliance data was presented that was digestible and timely. For non-technical users at Ocrolus, this solution established confidence in the SRE team and the system.
Results
Post-implementation, the SRE team was able to empower audit team members by inviting and training them with the Anchore Enterprise platform for on-demand access to security and vulnerability reporting. Through the Anchore user-interface, non-technical colleagues have greater insight into projects, which built trust with the overall system.
SRE team resource constraints were lifted and productivity dramatically improved by reducing dependencies on a single individual to provide answers to audit questions. Furthermore, other processes, like whitelisting, were made more efficient. In particular, Anchore Enterprise made image whitelisting easier helping the SRE team improve its operational efficiency.
In addition, Anchore Enterprise prevented false-negatives from vulnerability scans, which saved the SRE team time and money. Without false negatives, the focus was shifted to fixing true vulnerabilities to improve its enterprise performance and application security architecture.
With Anchore Enterprise, the organization was able to meet and exceed customer container security requirements to win new logos and business. Having Anchore Enterprise in place allowed Ocrolus to achieve customer expectations around container security scanners and demonstrate a strong security posture in the fintech space.
“Based on the amount of time our team has saved, Anchore Enterprise has paid for itself 20 times over.”
~10
Hours
Average Time Saved (Monthly) Responding to Audit Requests
5
Hours
Average Time Saved (Monthly) Whitelisting Applications
10
Minutes
Start to Finish Configuration ACL SAML
“Implementing application-specific whitelists take less time to implement with Anchore Enterprise user interface than a global whitelist manually in Anchore Engine.”
Download the PDF version of this case study for a complete look at Ocrolus.