Chainguard
Asana's Implementation of Chainguard for Compliance
Pages
1
Time to read
4 mins
Publication
Language
English
Pages
1
Time to read
4 mins
Publication
Language
English
This case study details Asana's experience in implementing Chainguard Containers to enhance their vulnerability management process and achieve compliance with federal standards. Asana faced significant challenges due to the noisy results from AWS Inspector scans, which complicated their vulnerability management efforts and created operational overhead. The need for FedRAMP authorization prompted Asana to seek a more efficient solution, as their existing approach required substantial manual tracking and reporting. By integrating Chainguard into their CI/CD pipelines, Asana significantly improved their base image coverage and streamlined vulnerability scanning processes. The implementation led to a dramatic reduction in vulnerabilities, transforming their compliance tracking from over 100,000 entries to approximately 200. This shift not only eased audit preparations but also improved engineer morale, allowing the team to focus on building secure systems. Ultimately, Chainguard enabled Asana to achieve FedRAMP accreditation, facilitating access to federal markets and enhancing their security posture.