Assessing the adoption of security policies by developers in terraform across different cloud providers

dc.contributor.authorVerdet, Alexandre
dc.contributor.authorHamdaqa, Mohammad
dc.contributor.authorSilva, Leuson Da
dc.contributor.authorKhomh, Foutse
dc.date.accessioned2026-09-23T14:10:01Z
dc.date.available2026-09-23T14:10:01Z
dc.date.issued2025-06
dc.descriptionPublisher Copyright: © The Author(s) 2025.en
dc.description.abstractCloud computing has become popular thanks to the widespread use of Infrastructure as Code (IaC) tools, allowing the community to manage and configure cloud infrastructure using scripts. However, the scripting process does not automatically prevent practitioners from introducing misconfigurations, vulnerabilities, or privacy risks. As a result, ensuring security relies on practitioners’ understanding and the adoption of explicit policies. To understand how practitioners deal with this problem, we perform an empirical study analyzing the adoption of scripted security best practices present in Terraform files, applied on AWS, Azure, and Google Cloud. We assess the adoption of these practices by analyzing a sample of 812 open-source GitHub projects. We scan each project’s configuration files, looking for policy implementation through static analysis (Checkov and Tfsec). The category Access policy emerges as the most widely adopted in all providers, while Encryption at rest presents the most neglected policies. Regarding the cloud providers, we observe that AWS and Azure present similar behavior regarding attended and neglected policies. Finally, we provide guidelines for cloud practitioners to limit infrastructure vulnerability and discuss further aspects associated with policies that have yet to be extensively embraced within the industry.en
dc.description.versionPeer revieweden
dc.format.extent1696303
dc.format.extent
dc.identifier.citationVerdet, A, Hamdaqa, M, Silva, L D & Khomh, F 2025, 'Assessing the adoption of security policies by developers in terraform across different cloud providers', Empirical Software Engineering, vol. 30, no. 3, 74. https://doi.org/10.1007/s10664-024-10610-0en
dc.identifier.doi10.1007/s10664-024-10610-0
dc.identifier.issn1382-3256
dc.identifier.other251043920
dc.identifier.other8c201cc0-8adc-41b0-95b2-4d4f8a899af8
dc.identifier.other85219591464
dc.identifier.urihttps://hdl.handle.net/20.500.11815/8315
dc.language.isoen
dc.relation.ispartofseriesEmpirical Software Engineering; 30(3)en
dc.relation.urlhttps://www.scopus.com/pages/publications/85219591464en
dc.rightsinfo:eu-repo/semantics/openAccessen
dc.subjectInfrastructure as codeen
dc.subjectPolicy misconfigurationen
dc.subjectSecurity vulnerabilitiesen
dc.subjectSoftwareen
dc.titleAssessing the adoption of security policies by developers in terraform across different cloud providersen
dc.type/dk/atira/pure/researchoutput/researchoutputtypes/contributiontojournal/articleen

Skrár

Original bundle

Niðurstöður 1 - 1 af 1
Nafn:
41e49791-9665-440e-a844-b1d3acbd9eca.pdf
Stærð:
1.62 MB
Snið:
Adobe Portable Document Format