• Continuous Integration Security Assessment Form

    Use this form to assess the security posture of your CI pipeline, from source control and secrets handling to scanning, deployment protections, and incident readiness.
  • CI Environment Overview

  • Primary programming language or stack*
  • Source Control and Access Controls

  • Branch protection enabled?*
  • Required reviews enforced for changes?*
  • Commit signing used?
  • Least-privilege access applied?*
  • Rows
  • Build Configuration and Secrets Handling

  • Are build scripts reviewed before changes are merged?*
  • Do builds run in isolated or ephemeral environments?*
  • Are secrets stored securely and injected at runtime?*
  • Which secret-handling issues have been identified?*
  • How are environment variables managed in builds?*
  • Dependency and Artifact Security

  • Dependency update strategy*
  • Dependency scanning enabled*
  • Lockfiles used in builds*
  • Artifact integrity verified before release*
  • Artifact validation methods used
  • Pipeline Security Checks and Monitoring

  • SAST status*
  • Secret scanning status*
  • SCA / dependency scanning status*
  • Container/image scanning status*
  • IaC scanning status*
  • Policy checks status*
  • Deployment Protections and Incident Readiness

  • Are approvals required before deployment?*
  • Are rollback procedures available and documented?*
  • Do failed security checks block releases?*
  • Should be Empty:
Select theme:
  • Default
  • Blue
  • Red
  • Brown
  • Green
  • Black
  • Pink
  • Dark Blue
  • Purple