Git Ops for CISOs
Detection-as-code, AI BOM, prompt governance, agent permissions.
Agent permissions and prompt governance — the incidents that don’t have playbooks yet.
Detection Rules as Code
A detection rule that only lives in the SIEM console has no version history, no review, and no rollback.
AI Incident Response Playbook as Code
When the incident involves an AI system, the playbook that applies has to already account for that — improvising one mid-incident is too slow.
Prompt Engineering Governance
A production prompt is a security-relevant artifact — it deserves the same review discipline as production code.
System Prompt Governance
The system prompt is the constitution — everything else the AI does operates within the boundaries it sets.
Secrets Rotation as Code
A rotation schedule that exists only in a spreadsheet is a rotation schedule that gets missed.
Purple Team Exercises as Code
A purple team finding that never becomes a tracked, version-controlled test case gets rediscovered from scratch next year.
Infrastructure Drift Detection as Code
The infrastructure-as-code file describes intent — drift is the gap between that intent and what’s actually running.
Compliance-as-Code
A control that’s only checked once a year during audit season is a control that can drift out of compliance for eleven months undetected.
Vulnerability SLA Enforcement in CI/CD
A vulnerability with a missed SLA and one within its SLA window look identical in a raw scan report — until this pipeline tells them apart.
Security Champion Program Tracking
A champion program without measurable activity is just a list of job titles with an extra word added.
Threat Model as Code
A threat model in a slide deck goes stale the day after the review meeting — one in the repo can’t.
AI Agent Permission Manifests in Git
An agent’s permissions should be reviewable by a human before the agent ever gets to exercise them.
Runbook Versioning and Testing
A runbook nobody has actually executed since it was written is a runbook you’re hoping works, not one you know works.
Security Metrics Dashboard as Code
A metric definition that lives only in one person’s head produces a dashboard nobody else can actually trust.
Dependency Update Security Review Automation
Most dependency updates are routine — the automation exists to find the handful that genuinely aren’t.
Board Reporting Pipeline as Code
A board deck assembled by hand the night before is a board deck built on whatever the preparer remembered to check.