Machine-Readable Compliance Evidence: NIST SSDF and Patch Controls as Code for Federal Cloud Authorization
Due to the emergence of strict regulatory standards such as the NIST Secure Software Development Framework (SSDF), the demand for compliance is higher. Traditional methods of implementing compliance measures are based on manual auditing and document management. This may lead to inefficiency, delayed processes, and security threats. For the above problems, this research presents a framework that automates compliance validation through rules-as-code approach in order to implement continuous assurance. This paper introduces the Rules-as-Code Cloud Assurance Framework (RC-CAF) which implements automated extraction and execution of rules in order to improve compliance processes in cloud-based environments. Experimental results have shown that the presented model has significantly improved compliance verification compared to FS-PKSE and CIA-Scheme models. It has achieved compliance accuracy of 96%, reduced computational costs to 180 ms and increased efficiency of compliance monitoring in real-time to 95%. The violation detection rate of 97% has been achieved with reduced processing time.