Continuous Integration Security Assessment Form
Use this form to assess the security posture of your CI pipeline, from source control and secrets handling to scanning, deployment protections, and incident readiness.
CI Environment Overview
CI platform or tool name
*
Repository or project name
*
Primary programming language or stack
*
JavaScript/TypeScript
Python
Java
C#/.NET
Go
Ruby
PHP
C/C++
Scala
Kotlin
Swift
Shell/Scripts
Other
Deployment target or environment
*
Please Select
Development
Test/QA
Staging
Production
Multiple environments
Other
Team or owner group responsible for the pipeline
*
Source Control and Access Controls
Branch protection enabled?
*
Yes
No
Partially
Not sure
Required reviews enforced for changes?
*
Yes
No
Partially
Not sure
Commit signing used?
Yes
No
Partially
Not sure
Least-privilege access applied?
*
Yes
No
Partially
Not sure
Rate access control strength by area
Rows
Weak
Adequate
Strong
Repository
1
2
3
CI system
4
5
6
Deployment environment
7
8
9
Build Configuration and Secrets Handling
Are build scripts reviewed before changes are merged?
*
Always
Usually
Sometimes
Rarely
Never
Do builds run in isolated or ephemeral environments?
*
Always
Usually
Sometimes
Rarely
Never
Are secrets stored securely and injected at runtime?
*
Always
Usually
Sometimes
Rarely
Never
Which secret-handling issues have been identified?
*
Secrets hard-coded in build files
Secrets stored in source control
Secrets exposed in logs
Secrets exposed in environment files
No issues identified
Other
How are environment variables managed in builds?
*
Centralized secret manager
CI-managed variables
Encrypted configuration files
Manual ad hoc setup
Other
Dependency and Artifact Security
Dependency update strategy
*
Always latest
Scheduled updates
Manual updates
Automated with review
Other
Dependency scanning enabled
*
Yes
No
Partially
Planned
Lockfiles used in builds
*
Yes, consistently
Sometimes
No
Not applicable
Artifact integrity verified before release
*
Yes
No
For some artifacts
Planned
Artifact validation methods used
Signature validation
Checksum validation
Source provenance verification
Build attestation
Other
Approval process for third-party packages
*
Pipeline Security Checks and Monitoring
SAST status
*
Enabled
Partially enabled
Disabled
Planned
Secret scanning status
*
Enabled
Partially enabled
Disabled
Planned
SCA / dependency scanning status
*
Enabled
Partially enabled
Disabled
Planned
Container/image scanning status
*
Enabled
Partially enabled
Disabled
Planned
IaC scanning status
*
Enabled
Partially enabled
Disabled
Planned
Policy checks status
*
Enabled
Partially enabled
Disabled
Planned
Where are security findings reviewed or triaged?
*
Deployment Protections and Incident Readiness
Are approvals required before deployment?
*
Yes
No
Conditional
Other
How strict are environment restrictions for deployments?
*
None
1
2
3
4
5
6
7
8
9
Very strict
10
1 is None, 10 is Very strict
Are rollback procedures available and documented?
*
Yes
No
Partial
Other
Do failed security checks block releases?
*
Always
Sometimes
Never
Other
Known security gaps or follow-up actions
Remediation priorities
Submit Assessment
Should be Empty: