Skip to content
Conference

Machine-Readable Compliance Evidence: NIST SSDF and Patch Controls as Code for Federal Cloud Authorization

Jul 2026 · 2026 4th International Conference on Sustainable Computing and Smart Systems (ICSCSS) · pp. 1063-1070 · 0 citations · 19 references

Abstract

Due to the emergence of strict regulatory standards such as the NIST Secure Software Development Framework (SSDF), the demand for compliance is higher. Traditional methods of implementing compliance measures are based on manual auditing and document management. This may lead to inefficiency, delayed processes, and security threats. For the above problems, this research presents a framework that automates compliance validation through rules-as-code approach in order to implement continuous assurance. This paper introduces the Rules-as-Code Cloud Assurance Framework (RC-CAF) which implements automated extraction and execution of rules in order to improve compliance processes in cloud-based environments. Experimental results have shown that the presented model has significantly improved compliance verification compared to FS-PKSE and CIA-Scheme models. It has achieved compliance accuracy of 96%, reduced computational costs to 180 ms and increased efficiency of compliance monitoring in real-time to 95%. The violation detection rate of 97% has been achieved with reduced processing time.

View source

Similar papers

2026

A cryptographically verified approach to secure Docker container updates in CI/CD pipelines

A secure CI/CD update workflow that combines keyless Cosign signing (OIDC/Fulcio), immutable SHA-256 digest–based image addressing, mandatory pre-deployment signature verification, and freshness controls against rollback attacks is presented, while permitting controlled rollback only to previously verified versions.

Vitaliy Tymoshchuk, Dmytro Tymoshchuk, Mykola Mytnyk et al. · 0 citations
Conference Jul 2026

SMT: SBOM and Merkle Tree Based Integrity Verification for Serverless Environments

Serverless computing environments are vulnerable to software supply chain attacks due to their heavy reliance on external libraries. However, existing integrity verification methods are centered on runtime execution logs, which limits their ability to directly detect tampering with function code and dependencies. In this paper, we propose an integrity verification framework that combines a Software Bill of Materials (SBOM) with a Merkle Tree, hereafter referred to as an SMT scheme. By utilizing SBOMs within the CI/CD (Continuous Integration/Continuous Delivery) pipeline, the SMT scheme establishes a trusted baseline at deployment time. Furthermore, it verifies both code and runtime integrity by correlating runtime execution logs with corresponding SBOM hash values. Experimental results demonstrate that the SMT scheme effectively detects code and dependency tampering attacks while incurring only a modest overhead of approximately 5–10% relative to existing method.

Jieon Lee, Won-Bin Kim, Daehee Seo · 0 citations
Open access Aug 2026

Analyzing Wazuh-Based File Integrity Monitoring for Layered Academic Server Security

The proposed system demonstrates the potential to serve as an effective and practical host-level security layer for strengthening cybersecurity resilience in academic server environments, although the evaluation was limited to three monitored servers and did not include advanced adversarial attack scenarios.

Engie Ramadhani, Agussalim Agussalim, Nur Cahyo Hendro Wibowo · 0 citations
Preprint Aug 2026

Improving the Security of Containerized Workloads using Transparency and Traceability Services

This paper presents an architecture for verifiable container image distribution that addresses key-management challenges and enables policy-enforced admission-time verification, and implements a proof-of-concept integrated with GitHub Actions and GitLab Runners that mitigates common supply-chain attacks under a realistic threat model.

N. Fotiou, Lefteris Georgiadis, Ignacio Lacalle et al. · 0 citations
Review Open access Aug 2026

Securing CI/CD Pipelines: A DevSecOps Framework for Preventing Credential Leaks and Misconfigurations

This study investigates security risks in Dock-er-based GitHub Actions workflows and proposes a tailored, DevSecOps-aligned security checklist to mitigate these threats, offering practical protection against supply-chain threats while preserving delivery speed and scalability.

A. Amirova · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.