implementing-infrastructure-as-code-security-scanning - IaC Security Scanning with Checkov, tfsec, and KICS
Automated security scanning for IaC templates (Terraform, CloudFormation, Kubernetes, Helm) using Checkov, tfsec, and KICS to detect misconfigurations before deployment.
Tags
Updated: 2026-06-30Capabilities
Typical Inputs
Typical Outputs
What this skill does
- scan Terraform files
- scan CloudFormation templates
- scan Kubernetes manifests
- scan Helm charts
- scan Terraform plan JSON
- create custom Checkov policies
- configure scan baselines and suppressions
- integrate IaC scanning into CI/CD pipelines
- upload SARIF scan results
- run KICS scans via Docker
Inputs
- Terraform files
- CloudFormation templates
- Kubernetes manifests
- Helm charts
- CI/CD pipeline configuration
- Bridgecrew API key (optional)
Outputs
- IaC security scan reports
- SARIF scan result files
- CI/CD pipeline gate status
- Custom security policy definitions
Requirements
- Checkov v3.x installed
- tfsec installed
- Terraform, CloudFormation, or Kubernetes IaC files in repository
- CI/CD pipeline with access to IaC directories
