Submind YouTube summaries
Thumbnail for Compliance-As-Code For API Security - Kamalika Majumder apidays India 2025 session preview

Compliance-As-Code For API Security - Kamalika Majumder apidays India 2025 session preview

Watch on YouTube

Video summary

Kamalika Majumder begins by outlining her professional journey from a system administrator to a DevOps consultant and now an entrepreneur focused on digital transformation through APIs. Her current work centers specifically on API security, addressing the overwhelming challenge that both new businesses and established organizations face when trying to navigate complex regulatory landscapes. She identifies ISO 27001 as a foundational framework because it serves as the umbrella for approximately ninety percent of global security compliance standards, with many other regulations acting merely as derivatives or specific implementations of its core principles. The core argument presented is that relying solely on documentation and certificates does not guarantee actual security; instead, organizations often suffer breaches despite holding multiple certifications like Oracle or CrowdStrike because they fail to translate regulatory requirements into their infrastructure configurations. Majumder emphasizes the critical need for collaboration between auditors who require policies and documents and developers who work with code, arguing that compliance must be embedded directly into the development lifecycle rather than treated as a separate administrative task signed off on by management. To bridge this gap, she proposes the concept of Compliance-as-Code, which moves beyond traditional Infrastructure-as-Code or Pipeline-as-Code approaches to encompass Security-as-Code and Policy-as-Code. This methodology involves codifying compliance controls into programmatic languages that developers can understand and implement directly within their API architectures. By translating complex regulatory language into executable code, this approach ensures that security policies are not just theoretical documents but active components of the system that prevent breaches before they occur. Ultimately, the session aims to provide a practical solution for those struggling with the disconnect between high-level regulations and technical implementation details. Majumder concludes by highlighting that true compliance requires more than obtaining certificates; it demands an operational shift where rules are written into code itself. This ensures that whether one is starting a new venture or managing an existing business, security measures are inherently built into the infrastructure rather than being added as an afterthought to satisfy audit requirements.
Read the full video transcript
I started with thought works uh as a system administrator. Then uh eventually when the whole uh devops uh movement started, it was quite natural for us to move in that uh direction. So uh then I transitioned on to a consultant in a consulting role uh as a devops consultant. Um and that's how my journey have been since then. I'm a soloreneur now and from 2017 uh so far I am uh working with the clients and helping them build their uh infrastructure in their digital transformation and a big part of it is uh APIs. I am talking about very specific thing on the API security which is compliance as code who is starting new or even someone uh who who is already running a business and uh is facing difficulty in uh you know identifying what can I do you know it might seem overwhelming for them in in the pool of security like what to do you know that where do I start off where can I start with API security so to make that uh decision easier that's where my focus of my talk would be that's why I chose ISO 27,0001 because it's like the umbrella compliance of I would say 90% of global security compliances so uh most of the other compliances that have come along they are sort of derivatives of ISO 2701 and I have been recently codifying the compliance control so my talk is would be unique to bridge the gaps between uh you know complex um difficult compliance language and translating it to uh a codified programmatic language so that we can bridge the gaps for people who are building APIs but who are not really aware about rules and regulation and complic complicated languages of compliances but at the same time the regulatory world which may not understand the nitty-g gritties of uh infrastructure and the APIs how do they uh you know also understand what it translates relates into it because uh as I say like auditors need policies and documents and developers needs codes but um at some point both have to collaborate together and to make sure that it's not just a bunch of documents which are getting signed off it's actually getting embedded uh so that the value comes out of it otherwise we can have and even to today we are seeing that in in front of our page in larger organizations we are certified with 10 different compliance uh regulatory certificates. They are the one who are seen to be you know breached by all these attacks. Uh and the next question are why aren't they isn't Oracle certified with this? Isn't uh you know cloud crowd strike certified with that? But why are they getting attacked? That that's because they people are just following documentations. you know they they are they're racing ahead times to get a certificate but they are not really translating it into their infrastructure uh or the configurations. So that will be my the essence of my talk. It's beyond infrastructure as code, beyond pipelines as code, it's security as code, policy as code. How do you codify them? What does it mean?