Skip to content

DevSecOps policy-as-code: Detecting and remediating over-privileged access tokens in SDLC tools

2026 · CSDP · pp. 290-299 · 0 citations · 20 references
Computer Science

TL;DR

The article represents a Proof of Concept (PoC) for policy-as-code methodology designed to detect “Privilege Sprawl” in GitLab CI/CD environments and showed how teams can reduce their organisational exposure by 73% and get back into compliance with Least Privilege.

View source

Similar papers

Review Open access Aug 2026

Securing CI/CD Pipelines: A DevSecOps Framework for Preventing Credential Leaks and Misconfigurations

This study investigates security risks in Dock-er-based GitHub Actions workflows and proposes a tailored, DevSecOps-aligned security checklist to mitigate these threats, offering practical protection against supply-chain threats while preserving delivery speed and scalability.

A. Amirova · 0 citations
Open access Jul 2026

Privileged Access Management for z/OS System Programmers: A Zero-Trust Control Framework for RACF, TSO, and SDSF Administrative Sessions

A new control approach for PAM known as the Zero-Trust Control Framework, based on behavioural analysis, graph theory, and entropy calculations is proposed, based on behavioural analysis, graph theory, and entropy calculations for enhancing zero trust enforcement in z/OS administration.

R. Shaw · 0 citations
Open access Jul 2026

Tool Calling Behind the Curtain: Secure Function Execution for Agentic LLMs Inside Confidential VMs

Confidential MCP is presented, a set of backward-compatible extensions to MCP that enable standardized, auditable tool calling within and across TEE boundaries and introduces a three-zone enclave-partitioned server topology, a programmable Anonymization Transform Layer (ATL) with formal parameter classification and ent...

Ankur Aggarwal · 0 citations
Jul 2026

CHARGE: Leveraging CWE Hierarchies for Hardware Security SystemVerilog Assertion Generation

CHARGE is an automated framework for generating security properties for unverified RTL modules using CWEs and large language models using CWEs and large language models that leverages the hierarchical nature of CWE entries to improve accuracy when identifying security-critical assets in unverified RTL modules.

Xiao Tan, C. Sturton · 0 citations
Preprint Sep 2026

Access Control as Verified Parse Constraints

This work encodes a bounded policy language's decision function into a fixed-size byte buffer and verify the enforcement code once, proving the validator accepts if and only if the decision function accepts, for every policy, request, and session.

Saranachon Iammongkol, Zhi-Yi Huang, D. Eyers · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.