Skip to content

docs: Add Compliance Frameworks Guide#7477

Open
vincent067 wants to merge 1 commit intobridgecrewio:mainfrom
vincent067:docs/chinese-compliance-guide
Open

docs: Add Compliance Frameworks Guide#7477
vincent067 wants to merge 1 commit intobridgecrewio:mainfrom
vincent067:docs/chinese-compliance-guide

Conversation

@vincent067
Copy link
Copy Markdown

Summary

This PR adds a comprehensive guide for using Checkov with compliance frameworks including CIS, SOC2, NIST, ISO27001, and PCI DSS.

What's Included

  • Detailed instructions on how to run compliance scans with Checkov
  • How to filter and interpret compliance scan results
  • Best practices for integrating compliance checks into CI/CD pipelines
  • Examples for each supported compliance framework

Benefits

This guide helps users:

  • Understand how to leverage Checkov for compliance auditing
  • Quickly identify non-compliant resources in their infrastructure
  • Seamlessly integrate compliance scanning into their development workflows

By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 license.

Add comprehensive guide for using Checkov with compliance frameworks including:
- Supported frameworks overview (CIS, SOC2, NIST, ISO27001, PCI DSS)
- How to run compliance-specific scans
- Understanding and filtering results by severity
- CI/CD integration best practices
- Framework-specific guidance for CIS and SOC2
- Report generation in multiple formats
- Progressive enforcement strategies for teams

This helps users better understand and implement compliance
checks in their infrastructure as code workflows.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant