# SP-028 Secure DevOps Pipeline Pattern

Status: active. Release 26.02. Modified 2026-02-06. Licence: CC BY-SA 4.0.

Scope: Security architecture for CI/CD pipelines, DevSecOps practices, and software delivery automation. Covers pipeline infrastructure hardening, secrets management, software supply chain integrity, automated security testing, artifact signing, deployment gates, infrastructure as code governance, and compliance automation.
Use when: Organisation develops and deploys software through CI/CD pipelines. Multiple teams contribute to shared codebases with automated build and test processes.
Not when: Organisation develops no software and operates no CI/CD pipelines.

## Controls (49, NIST SP 800-53 ids)
- Critical (16): AC-03, AC-05, AC-06, AU-02, AU-03, CA-07, CM-02, CM-03, CM-14, IA-05, RA-05, SA-10, SA-11, SI-07, SR-03, SR-04
- Important (24): AC-02, AC-04, AT-03, AU-06, AU-12, CA-02, CM-04, CM-06, CM-07, IA-02, IA-08, RA-03, SA-08, SA-09, SA-15, SC-07, SC-12, SC-28, SI-02, SI-03, SI-04, SI-10, SI-15, SR-02
- Standard (9): AC-01, AT-02, IA-04, IR-01, IR-06, SA-04, SC-08, SC-13, SR-01

## What each critical control mitigates (16)
- AC-03 Access Enforcement: T-DSO-003, T-DSO-006, T-DSO-014
- AC-05 Separation of Duties: T-DSO-003, T-DSO-006, T-DSO-009, T-DSO-010
- AC-06 Least Privilege: T-DSO-005, T-DSO-009, T-DSO-014
- AU-02 Event Logging: T-DSO-003, T-DSO-005, T-DSO-009, T-DSO-010, T-DSO-012
- AU-03 Content of Audit Records: T-DSO-002, T-DSO-012
- CA-07 Continuous Monitoring: T-DSO-007
- CM-02 Baseline Configuration: T-DSO-007
- CM-03 Configuration Change Control: T-DSO-003, T-DSO-006
- CM-14 Signed Components: T-DSO-004, T-DSO-008
- IA-05 Authenticator Management: T-DSO-002, T-DSO-005
- RA-05 Vulnerability Monitoring and Scanning: T-DSO-008
- SA-10 Developer Configuration Management: T-DSO-007
- SA-11 Developer Testing and Evaluation: T-DSO-001, T-DSO-006, T-DSO-013
- SI-07 Software, Firmware, and Information Integrity: T-DSO-001, T-DSO-004, T-DSO-008, T-DSO-011, T-DSO-012
- SR-03 Supply Chain Controls and Processes: T-DSO-001, T-DSO-008, T-DSO-011
- SR-04 Provenance: T-DSO-001, T-DSO-004, T-DSO-011

## Threats and the controls that mitigate them (15)
- T-DSO-001 Supply Chain Attack via Compromised Dependency: SR-03, SR-04, SI-07, SA-11
- T-DSO-002 Secret Exposure in Build Logs or Artifacts: IA-05, SC-12, SC-28, AU-03
- T-DSO-003 Pipeline Poisoning (Malicious Build Step Injection): CM-03, AC-03, AC-05, AU-02
- T-DSO-004 Artifact Tampering Between Build and Deployment: SI-07, CM-14, SR-04, SC-08
- T-DSO-005 Privilege Escalation via CI/CD Service Accounts: AC-06, AC-02, IA-05, AU-02
- T-DSO-006 Unauthorised Code Injection via Merge Request: AC-03, AC-05, CM-03, SA-11
- T-DSO-007 Infrastructure Drift from Declared State: CM-02, CM-06, CA-07, SA-10
- T-DSO-008 Container Image Supply Chain Compromise: SR-03, SI-07, CM-14, RA-05
- T-DSO-009 Insider Threat via Pipeline Access: AC-05, AC-06, AU-02, AU-06
- T-DSO-010 Deployment Without Security Gate Verification: CM-04, AC-05, CA-02, AU-02
- T-DSO-011 Dependency Confusion and Typosquatting Attacks: SR-03, SR-04, CM-07, SI-07
- T-DSO-012 Compliance Evidence Tampering: AU-02, AU-03, AU-12, SI-07
- T-DSO-013 Injection Attacks (SQL, NoSQL, Command, XSS) Through Unvalidated User Input: SI-10, SI-15, SA-11, SA-15
- T-DSO-014 Broken Authentication Enabling Session Hijacking, Credential Stuffing, or Privilege Escalation: AC-03, AC-06, IA-02, IA-08
- T-DSO-015 API Abuse via Unauthenticated, Unrate-Limited, or Improperly Validated Endpoints: SC-08, AC-04, SC-13, SI-10

## More
- The critical controls and what each mitigates, as JSON (a few KB): /api/v1/patterns/SP-028/crosswalk?emphasis=critical
- The same for every control, with its clauses in a framework: /api/v1/patterns/SP-028/crosswalk?framework={framework id}. Framework ids are listed in /llms.txt
- The pattern's prose, examples and references as JSON, 40 KB: /api/v1/patterns/SP-028
- Page for people: /patterns/sp-028/
- Found an error? Open an issue at https://github.com/opensecurityarchitecture/osa-data/issues with the id, what OSA says and what the source says.
- Related: SP-002 Server Module; SP-008 Public Web Server Pattern; SP-011 Cloud Computing Pattern; SP-012 Secure Software Development Lifecycle; SP-025 Advanced Monitoring and Detection; SP-027 Secure LLM Usage

This card, the API and the page are generated from one file. Checking one against another adds no evidence.
