Overview
Coursera Spring Sale
40% Off Coursera Plus Annual!
Grab it
Learn how to automate policy and compliance in cloud-native environments through this conference talk that demonstrates practical applications of the Open Security Controls Assessment Language (OSCAL). Discover how to bridge the gap between abstract cybersecurity regulations and concrete, enforceable policies using real-world examples and proven methodologies. Explore the integration of CNCF projects including the newly released OSCAL Compass Compliance-to-Policy (C2P) v2 and Open Policy Agent (OPA) to transform regulatory requirements into actionable policy-as-code artifacts. Understand the challenges of gathering compliance evidence in rapidly evolving cloud-native environments where systems are continuously deployed, secured, and governed. Master an end-to-end approach that generates verifiable, audit-ready evidence while addressing the complexities of modern infrastructure management. Gain practical insights into tools and practices that enable organizations to maintain compliance without sacrificing the agility and speed required in contemporary software development and deployment cycles.
Syllabus
OSCAL in Action: Real World Examples of Automating Policy & Compliance - J. Power & H. Braswell
Taught by
OpenSSF