OSCAL Compass: Compliance as Code with OSCAL cover

Technology · Ebook

OSCAL Compass: Compliance as Code with OSCAL

by Shriira Press

4.7(193)126 pagesPublished 2026

OSCAL Compass is a CNCF sandbox project that brings the discipline of 'as code' to security compliance, built on NIST's Open Security Controls Assessment Language. It pairs compliance-trestle, for creating, splitting, validating, and assembling OSCAL documents, with Compliance-to-Policy (C2P), which translates those documents into rules for engines like Kyverno and Open Cluster Management and translates their results back, and agile authoring, a GitOps pipeline for versioned, collaborative authoring. This book starts with why traditional compliance stays manual, walks through OSCAL's layered models, the trestle workspace and CLI, the authoring workflow, the C2P bridge, the continuous-compliance pipeline, and how it all fits in practice. The idea: an audit can be a build, not a binder.

Contents

  1. 1Preface
  2. 2Chapter 1 — The Compliance Problem
  3. 3Chapter 2 — OSCAL: A Common Language for Controls
  4. 4Chapter 3 — Trestle: The Workspace and the CLI
  5. 5Chapter 4 — Authoring Compliance Documents
  6. 6Chapter 5 — Compliance to Policy
  7. 7Chapter 6 — Agile Authoring and Continuous Compliance
  8. 8Chapter 7 — OSCAL Compass in Practice