Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

YouTube

Compliance is Broken - The DevOps Revolution for Audit and Controls

InfoQ via YouTube

Overview

Coursera Flash Sale
40% Off Coursera Plus for 3 Months!
Grab it
Watch this 49-minute InfoQ conference talk that exposes the fundamental flaws in traditional IT compliance and audit approaches while introducing a revolutionary DevOps-based solution. Discover why manual spreadsheets, periodic audits, and static Confluence pages are obsolete for modern engineering teams and learn about the Continuous Compliance Framework (CCF), an open-source architectural shift that applies DevOps and observability principles to compliance management. Explore the four critical problems plaguing current audit processes: their manual nature, periodic timing, process-focused approach, and bespoke implementations, while understanding the "compliance tax" that creates resistance to innovation in regulated industries. Examine the regulatory shift toward machine-readable regulations like DORA and witness a live demonstration of CCF in action, including real-time dashboards that display findings by type, subject, and catalog across hybrid cloud environments spanning AWS, Azure, and on-premises infrastructure. Learn how CCF maps findings to NIST SP 800-53 controls for auditors and understand the OSCAL standard's role in achieving compliance interoperability. Gain insights into the accidental development of CCF, key architectural decisions, and practical lessons learned from implementing continuous, real-time evidence gathering. Participate in comprehensive Q&A sessions covering subjective requirements handling, automation scope, auto-remediation capabilities, data sovereignty considerations, and determining whether technical teams or audit teams should champion this transformation.

Syllabus

0:00 Intro: Compliance is Broken & The Revolution
1:55 Why Regulated Industries are Adopting Cloud-Native
3:20 Part 1: What is Wrong with Compliance & Audit Today?
5:45 The 4 Problems with Audits: Manual, Periodic, Process-Focused, Bespoke
9:15 Why is it like this? The "Compliance Tax" & Resistance to Innovation
12:00 The Regulatory Shift: DORA & Machine-Readable Regulations
14:00 DEMO: The Continuous Compliance Framework CCF Live
16:50 CCF Dashboards: Viewing Findings by Type, Subject, and Catalog
19:30 Mapping Findings to NIST SP 800-53 Controls for Auditors
21:05 How We Accidentally Built CCF & Architectural Decisions
23:25 OSCAL Standard: The Key to Interoperability in Compliance
26:10 Lessons Learned & The "Help Me Sleep at Night" Use Case
28:05 Q&A: Handling Subjective Requirements & Automation Scope
30:20 Q&A: Auto-Remediation and Taking Action from Findings
31:40 Q&A: Data Sovereignty and Why CCF is NOT SaaS
32:55 Q&A: Who Should Be Excited—Tech Team or Audit Team?

Taught by

InfoQ

Reviews

Start your review of Compliance is Broken - The DevOps Revolution for Audit and Controls

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.