The pipeline used cloud-native services along with a few open-source security tools.
It defines a software factory using Kubernetes along with necessary AWS Cloud-native services and open-source third-party tools.
In this architecture, we use AWS services to address the security of the software factory, and use third-party tools along with AWS services to address the security in the software factory.
The following table is the high-level mapping of the NIST 800-53 security control families and AWS services that are used in this DevSecOps reference architecture.
This post also talked about how to implement security of the pipeline and in the pipeline using AWS Cloud-native services.