Compliance-As-Code For API Security - Kamalika Majumder apidays India 2025 session preview
Watch on YouTubeVideo summary
Kamalika Majumder begins by outlining her professional journey from a system administrator to a DevOps consultant and now an entrepreneur focused on digital transformation through APIs. Her current work centers specifically on API security, addressing the overwhelming challenge that both new businesses and established organizations face when trying to navigate complex regulatory landscapes. She identifies ISO 27001 as a foundational framework because it serves as the umbrella for approximately ninety percent of global security compliance standards, with many other regulations acting merely as derivatives or specific implementations of its core principles.
The core argument presented is that relying solely on documentation and certificates does not guarantee actual security; instead, organizations often suffer breaches despite holding multiple certifications like Oracle or CrowdStrike because they fail to translate regulatory requirements into their infrastructure configurations. Majumder emphasizes the critical need for collaboration between auditors who require policies and documents and developers who work with code, arguing that compliance must be embedded directly into the development lifecycle rather than treated as a separate administrative task signed off on by management.
To bridge this gap, she proposes the concept of Compliance-as-Code, which moves beyond traditional Infrastructure-as-Code or Pipeline-as-Code approaches to encompass Security-as-Code and Policy-as-Code. This methodology involves codifying compliance controls into programmatic languages that developers can understand and implement directly within their API architectures. By translating complex regulatory language into executable code, this approach ensures that security policies are not just theoretical documents but active components of the system that prevent breaches before they occur.
Ultimately, the session aims to provide a practical solution for those struggling with the disconnect between high-level regulations and technical implementation details. Majumder concludes by highlighting that true compliance requires more than obtaining certificates; it demands an operational shift where rules are written into code itself. This ensures that whether one is starting a new venture or managing an existing business, security measures are inherently built into the infrastructure rather than being added as an afterthought to satisfy audit requirements.
Read the full video transcript
I started with thought works uh as a
system administrator. Then uh eventually
when the whole uh devops uh movement
started, it was quite natural for us to
move in that uh direction. So uh then I
transitioned on to a consultant in a
consulting role uh as a devops
consultant. Um and that's how my journey
have been since then. I'm a soloreneur
now and from 2017 uh so far I am uh
working with the clients and helping
them build their uh infrastructure in
their digital transformation and a big
part of it is uh APIs. I am talking
about very specific thing on the API
security which is compliance as code who
is starting new or even someone uh who
who is already running a business and uh
is facing difficulty in uh you know
identifying what can I do you know it
might seem overwhelming for them in in
the pool of security like what to do you
know that where do I start off where can
I start with API security so to make
that uh decision easier that's where my
focus of my talk would be that's why I
chose ISO 27,0001 because it's like the
umbrella compliance of I would say 90%
of global security compliances so uh
most of the other compliances that have
come along they are sort of derivatives
of ISO 2701 and I have been recently
codifying the compliance control so my
talk is would be unique to bridge the
gaps between uh you know complex um
difficult compliance language and
translating it to uh a codified
programmatic language so that we can
bridge the gaps for people who are
building APIs but who are not really
aware about rules and regulation and
complic complicated languages of
compliances but at the same time the
regulatory world which may not
understand the nitty-g gritties of uh
infrastructure and the APIs how do they
uh you know also understand what it
translates relates into it because uh as
I say like auditors need policies and
documents and developers needs codes but
um at some point both have to
collaborate together and to make sure
that it's not just a bunch of documents
which are getting signed off it's
actually getting embedded uh so that the
value comes out of it otherwise we can
have and even to today we are seeing
that in in front of our page in larger
organizations we are certified with 10
different compliance uh regulatory
certificates. They are the one who are
seen to be you know breached by all
these attacks. Uh and the next question
are why aren't they isn't Oracle
certified with this? Isn't uh you know
cloud crowd strike certified with that?
But why are they getting attacked? That
that's because they people are just
following documentations. you know they
they are they're racing ahead times to
get a certificate but they are not
really translating it into their
infrastructure uh or the configurations.
So that will be my the essence of my
talk. It's beyond infrastructure as
code, beyond pipelines as code, it's
security as code, policy as code. How do
you codify them? What does it mean?