This Chef InSpec course goes beyond syntax. You’ll learn how compliance-as-code fits into real DevSecOps workflows: writing reusable profiles, auditing AWS, Azure, and GCP resources, managing waivers for accepted risk, and generating audit-ready reports. We also cover the shift toward CINC Auditor, the free, license-free distribution of InSpec, so you know exactly which tool to use in commercial environments without running into Chef’s licensing terms – a detail most training providers still skip.
Prerequisites
There is no strict prerequisite for this course, but you’ll get more out of it if you already have:
- Basic familiarity with Linux or Windows server administration
- Comfort working from the command line
- Some exposure to configuration management (Chef, Ansible, Puppet, or similar) – helpful but not required
- A basic understanding of YAML or Ruby syntax is a plus, though InSpec’s DSL is designed to be readable without deep programming experience
Course Objectives
- Understand compliance-as-code principles and where InSpec fits inside a DevSecOps pipeline
- Install and configure Chef InSpec and CINC Auditor across Linux and Windows environments
- Write, structure, and version-control InSpec profiles and controls
- Audit on-prem and cloud infrastructure (AWS, Azure, GCP) against recognized security baselines
- Map technical controls to CIS Benchmarks, DISA STIGs, and NIST frameworks
- Integrate InSpec scans into Jenkins, GitLab CI, and GitHub Actions pipelines
- Manage waivers and exceptions without weakening the underlying controls
- Generate and interpret compliance reports using Chef Automate and MITRE Heimdall
- Build a complete compliance profile for a multi-tier application as a capstone project
What You Will Learn
- The InSpec DSL: resources, describe blocks, matchers, and control metadata
- How to structure profiles with inputs, dependencies, and overlays for reuse across teams
- Auditing OS-level configuration – users, services, packages, file permissions – on Linux and Windows
- Validating cloud resources using the AWS, Azure, and GCP InSpec resource packs
- The practical difference between Chef InSpec (license required for some commercial use) and CINC Auditor (free, license-free fork)
- Writing custom resources when built-in resources don’t cover a specific check
- Using Test Kitchen and Kitchen-InSpec to test profiles locally before deployment
- Automating compliance scans inside CI/CD pipelines and failing builds on non-compliance
- Handling waivers for accepted-risk findings in a defensible, auditable way
- Exporting results to JSON, JUnit, and Heimdall-compatible formats for dashboards and audits
Who Should Take This Course?
This course is built for professionals responsible for keeping infrastructure secure, audit-ready, and compliant at scale:
- DevOps and Site Reliability Engineers automating infrastructure validation
- Security and compliance analysts moving from manual audits to compliance-as-code
- System administrators managing Linux/Windows fleets who need repeatable audit evidence
- Cloud engineers responsible for AWS, Azure, or GCP security posture
- QA and release engineers adding compliance gates to CI/CD pipelines
- IT governance, risk, and compliance (GRC) professionals working toward ATO or cATO processes
- Professionals preparing for Chef’s official Auditing with InSpec certification exam
Skills You Will Gain
- Writing and debugging InSpec controls and profiles
- Reading and adapting open-source CIS Benchmark and DISA STIG profiles
- Cloud resource auditing across AWS, Azure, and GCP
- CI/CD pipeline integration for automated compliance gates
- Mapping technical controls to compliance frameworks (CIS, NIST, DISA)
- Managing waivers and audit exceptions responsibly
- Producing audit-ready evidence and reports
- Communicating compliance gaps to non-technical stakeholders
Tools Covered
- Chef InSpec / CINC Auditor
- Chef Workstation
- Test Kitchen and Kitchen-InSpec
- InSpec resource packs for AWS, Azure, and GCP
- Chef Automate (compliance dashboard and reporting)
- MITRE Heimdall (results visualization)
- MITRE SAF (Security Automation Framework) CLI
- Jenkins, GitLab CI, and GitHub Actions
- Git for profile version control
- Open-source DISA STIG and CIS Benchmark profiles
Career Outcomes
Compliance-as-code skills are in growing demand as organizations shift from point-in-time audits to continuous compliance. Learners from this course typically target roles such as:
- DevSecOps Engineer
- Compliance Automation Engineer
- Cloud Security Engineer
- Site Reliability Engineer (SRE)
- Infrastructure Security Analyst
- IT Compliance / GRC Specialist
- Configuration Management Engineer
Why Choose kodestree?
Here’s what sets this training apart:
- Live, instructor-led online sessions
- Hands-on labs on real Linux, Windows, and cloud environments
- Curriculum updated for the current CINC Auditor and licensing landscape
- Capstone project built around a real compliance profile
- Recorded sessions with lifetime access
- Course completion certificate
- Flexible weekday and weekend batches
- Post-training doubt-clearing support
- Resume and interview preparation support