One answer might be to avoid complex or new environments such as Azure, Google Cloud, or Amazon Web Services (AWS). For most businesses, that’s no longer an option. It is nearly impossible to find a thriving company that’s not dependent upon some level of IAAS (infrastructure as a service), PAAS (platform as a service) or SAAS (software as a service), and it’s not practical to limit data centers from a liberal or complete use of virtualization technology.
Also, pretty much all of our networks are transitioning to SDN (Software Defined Networking), so that’s the whole stack, in the cloud. (Gone are the days of having your hands in everything unless your arms happen to be long enough to stretch into the clouds.)
It's getting a lot harder to keep track of your data

Today’s MBA has to understand business as a service, and one of those critical services not yet mentioned is security. SecAAS, or security as a service, offers another way to extend security operations via compliance fabric or platform. Security too, must become a platform and foundation layer beneath SecOps, and must act as a force multiplier in the speed of DevOps.
you're a company deploying AWS workloads two to three times a day and you get a matter of seconds to assess security at release.
An example of the solutions available to assist in determining security over cloud-enabled systems is to leverage Open Vulnerability Assessment Language (OVAL) and The Security Content Automation Protocol (SCAP) from NIST. This too can be time-consuming. With over 75 CIS benchmarks, and 300+ DISA Security Technical Implementation Guides or STIGS, maintaining continuous visibility over configurations across On-Premise, Hybrid and Public Clouds is just not possible. Security operations require a compliance platform and integrated reporting. It's just one more point of inevitable security tooling that's become a mandate of the day.
So, what do we need to automate?

CIS AMAZON LINUX BENCHMARK V2.0.0 provides prescriptive guidance for establishing a secure configuration posture for Amazon Linux systems running on AWS. At 282 pages in length, the task of interpreting and setting rules to meet the needs of your business environment is not resource or time effective.
To meet the challenges of DevOps, guidance like CIS prescriptive benchmarks, security operations require a compliance platform that can quickly answer questions like:
"What are the top ten ways our configured enterprise is most likely to fail an audit?"
From the perspective of things that are BOTH most exploited and most audited, using a compliance platform allows for an integration of best practice at the speed necessary for DevOps. There's no other way to meet the challenge. Business compliance has to find and report alignment with security best practices in real-time. The issue is that engineering can't wait for security's blessing. They simply have to deploy. Additionally, sending a long list of security issues where the impact is only noted as a "potential" problem is ineffective. If the act of detection lacks the logic to also send a notification with the exact steps to remediation, detection is a liability and waste of time. These are reasons that security has to work with tools like Cavirin, ServiceNow, Allgress, CIS, and many others.
Top ten ways to get exploited and fail audit
A full review of the required security policy is larger than most people realize. In the case of Amazon Linux, for example, there are 215 recommended system automated policy checks, organized by over 50 control subjects, and associated to specific NIST 800-54 r4 control policies more than 1500 times. Security needs tools that can reliably and repeatedly do this work.

With system information, it becomes relatively easy to see where configuration recommendations have the greatest potential to disrupt the most regulated areas of security and IT governance, not to mention bringing focus to the areas most often exploited by cyberattacks.

How do we prioritize and respond?

Whether you're preparing for Cybersecurity certification, working with government standards, or simply starting your career in compliance, these are the NIST Federal Information Processing Standards (FIPS), Special Publication (SP), and Interagency Report (IR) topics