OSCAL Compass: Compliance as Code with OSCAL
Shriira Press
Turning security compliance from a paperwork ritual into living, machine-readable code that travels with your systems.
Welcome to OSCAL Compass: Compliance as Code with OSCAL.
OSCAL Compass is a CNCF sandbox project that brings the discipline of "as code" to security compliance. Built on NIST's Open Security Controls Assessment Language (OSCAL), it offers a small family of tools — compliance-trestle for creating, splitting, validating, and assembling OSCAL documents; Compliance-to-Policy (C2P) for translating those documents into rules that engines like Kyverno or Open Cluster Management can enforce, and translating their results back; and agile authoring, a GitOps pipeline for collaborative, versioned authoring of compliance artifacts. This book begins with the messy reality of traditional compliance and why a machine-readable standard changes everything. It then walks through OSCAL's layered models, the trestle workspace and its command line, the authoring workflow, the C2P bridge between compliance and policy engines, the GitOps pipeline behind continuous compliance, and finally how all of it comes together in practice. By the end you will understand not just the tools but the idea: that an audit can be a build, not a binder.
This title is part of the ShriIra library and is free to read in full, right here — our small contribution to making world-class knowledge easy to reach.
A note on reading it: open the Contents menu at the top of the reader to jump between chapters, use the Aa menu to set a comfortable text size, theme (light, sepia, or night), and single- or two-page layout. Your place is saved automatically, so you can always pick up where you left off.
We hope it serves you well.
— Shriira Press