Jul 2026· De Computis· Vol 15, pp. 453· 0 citations· 17 references
Computer Science
TL;DR
Empirically evaluates a reusable multi-stage Policy-as-Code enforcement model based on a shared policy-definition layer implemented using the Open Policy Agent framework and its Rego policy language and demonstrates that a shared policy-definition layer can support consistent policy enforcement across complementary enforcement stages while enabling policy reuse without requiring duplicate policy implementations within the evaluated environment.
Abstract
Cloud-native software-delivery pipelines increasingly rely on Policy-as-Code (PaC) to automate security, compliance, and governance enforcement. Although Policy-as-Code is widely adopted within Continuous Integration (CI) pipelines and Kubernetes admission-control frameworks, governance requirements are often implemented independently, potentially increasing maintenance effort and creating opportunities for policy drift. Despite the growing adoption of Policy-as-Code, comparatively little empirical evidence exists regarding the reuse of a shared policy-definition layer across complementary enforcement stages within the software-delivery lifecycle. This paper presents and empirically evaluates a reusable multi-stage Policy-as-Code enforcement model based on a shared policy-definition layer implemented using the Open Policy Agent (OPA) framework and its Rego policy language. Rather than proposing a new Policy-as-Code technology, the study investigates whether a shared policy-definition layer can support consistent policy enforcement across Continuous Integration validation and Kubernetes admission control. The model was evaluated using Conftest and OPA Gatekeeper through a structured experimental study comprising 29 Kubernetes manifests, 37 experimental scenarios, eight Kubernetes resource types, and 261 policy assertions covering representative cloud-native workload-governance requirements. Within the evaluated dataset, all intentionally introduced insecure configurations were correctly identified without observed false positives or false negatives. The shared policy-definition layer was successfully reused across both validation stages, while Kubernetes admission control mitigated all evaluated CI bypass scenarios by providing an independent deployment-time enforcement boundary. The results demonstrate that a shared policy-definition layer can support consistent policy enforcement across complementary enforcement stages while enabling policy reuse without requiring duplicate policy implementations within the evaluated environment. More broadly, the study contributes empirical evidence supporting policy reuse as a governance strategy for cloud-native software delivery and provides a reproducible foundation for future investigations involving larger datasets, broader governance-policy portfolios, alternative Policy-as-Code ecosystems, and production-scale deployments.
ReATest is introduced, an automated approach to enhancing PaC workflows through systematic test case generation from Rego specifications, which achieves an average 35.43% reduction in test suite size and retains 64.57% of the generated test cases.
Thanh-Binh Trinh, N. Le, H. Nguyen· Software quality journal· 0 citations
Abstract—Federal and regulated organizations continue to rely on document-centric Authorization to Operate (ATO) processes even as the NIST Risk Management Framework (RMF), continuous monitoring guidance, Zero Trust Architecture (ZTA), and continuous authorization initiatives require more continuous, evidence-driven ri...
Anand Janjal· Journal of Cybersecurity Edu...· 0 citations
Infrastructure as Code (IaC) has become an important approach for automating the provisioning, configuration, validation, and management of cloud and software infrastructure. This review covers five aspects of IaC: DevOps integration, security, automation, compliance, validation, and risk management. By version control...
Swapnil Joshi· International Research Journ...· 0 citations
The article represents a Proof of Concept (PoC) for policy-as-code methodology designed to detect “Privilege Sprawl” in GitLab CI/CD environments and showed how teams can reduce their organisational exposure by 73% and get back into compliance with Least Privilege.
The rapid expansion of global enterprise applications and multi-cloud infrastructures has significantly increased the need for strict data governance and regulatory compliance. With the rise of region-specific data protection laws, organizations are now required to ensure that sensitive data remains within defined geog...
Environmental, Social, and Governance (ESG) compliance has shifted from voluntary best practice to enforceable legal obligation across major global jurisdictions. Frameworks such as the European Union's Corporate Sustainability Reporting Directive (CSRD), the Sustainable Finance Disclosure Regulation (SFDR), the United...
Isaiah Oluwsegun Owolabi· CogNexus· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.