Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Consider adding HIPAA partners #531

Open
ebeneliason opened this issue Aug 2, 2021 · 1 comment
Open

Consider adding HIPAA partners #531

ebeneliason opened this issue Aug 2, 2021 · 1 comment
Assignees

Comments

@ebeneliason
Copy link
Contributor

From this slack message:

I don’t really want to advertise that we are partnered with someone we’re not. But perhaps we could do a little research on the partners, figure out what we would do to have a first-class integration with them, and add that to our features? For example, for Vanta, I believe you install an agent in AWS somehow that scans all your traffic for compliance. Maybe we pre-install the agent for you.

@zackproser zackproser self-assigned this Aug 3, 2021
@zackproser
Copy link
Contributor

zackproser commented Aug 3, 2021

Vanta offers ECR image vulnerability scanning as described here. The setup involves:

  • Creating an IAM user for Vanta
  • Creating IAM policies granting the IAM Vanta user access to ECR image scanning, and other permissions
  • Enabling "Scan on Push" for all target ECR repositories

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants