skip to content

Compliance as Code

You will learn to turn an audit control into a check that runs: benchmark profiles, run records mapped to SOC 2 clauses, waivers that expire. Interviewers probe whether compliance is engineered here.

on this pageshow

explore

questions

page 1 of 2

Why map one TLS-minimum check to clauses in three compliance frameworks instead of writing three checks?

level: juniorimportance: must knowfreq 62%

answer

  1. one fact, three reports
  2. assertion versus compliance claim
  3. the mapping is data, not code
  4. duplicate rules drift apart
  5. one failure fans out to three findings

basics

~10 s

The check is the same engineering fact; only the reporting differs. One check with three mapping edges means one rule to maintain and three audit reports that can never disagree about the same listener.

solid answer

~50 s

A crosswalk separates the technical assertion from the compliance claim. The assertion — every externally reachable listener negotiates TLS 1.2 or higher — is one rule producing one result set. The crosswalk is a mapping that says this result answers a NIST SP 800-53 transmission-protection control, a SOC 2 common criterion in the CC6 logical-access series, and PCI DSS Requirement 4 on protecting cardholder data in transit over open, public networks. Three separate copies of the rule drift: someone tightens the cipher list in the PCI copy and not the others, and two reports quietly disagree about the same host. The mapping also works in the failing direction — one failed listener fans out into three findings, in three reports, with three different remediation deadlines. And because the mapping is data rather than code, adding a fourth framework is a new edge, not a new scanner.

go deeper

for a junior

Be ready to state the difference between the technical assertion a check evaluates and the framework clause it is claimed to answer, and to say that a crosswalk is the mapping between them.

for a middle

Explain the mechanics of the duplication failure: how copied rules drift after the first fix, and how a single failed resource fans out into several findings with different remediation clocks.

for a senior

Show you have operated this. Talk about edges carrying conditions — one framework's clause applying only to a subset of listeners — and about the crosswalk changing reporting rather than enforcement.

for a principal

Own the argument that the mapping is data with an owner, so a new customer framework is a set of rows rather than a new scanning programme. Be able to say what that decision costs when a mapping is wrong.

## Two different objects A compliance framework clause and a policy check are not the same kind of thing, and a crosswalk exists because of that gap. - **The assertion** is engineering: *every externally reachable listener negotiates TLS 1.2 or higher*. It is evaluable. It runs on a schedule, it looks at a concrete set of resources, and it returns pass or fail per resource with a timestamp. - **The claim** is compliance: *we protect data in transit*. It is a sentence written by a standards body for thousands of organisations, and it deliberately does not name your load balancers. A crosswalk is the mapping between the two: a table of edges, each saying "this check's result is part of the answer to that clause of that framework at that revision". ## The worked case One TLS-minimum check plausibly touches three frameworks at once: | Framework | What the edge says | |---|---| | NIST SP 800-53 | Answers the transmission confidentiality and integrity control for the components in the mapping's scope | | SOC 2 | Supports a common criterion in the CC6 logical-access series, as tested against your own stated policy | | PCI DSS | Answers Requirement 4, protecting cardholder data with strong cryptography in transit over open, public networks | Note what is already visible here: the three edges are not identical. The PCI edge carries a condition — it only speaks to listeners inside the cardholder-data environment reachable from a public network. The SOC 2 edge is tested against what your own policy document says you do. So even the "one check answers three clauses" case is really "one result, three edges, each with its own qualifier". Recording those qualifiers is the whole craft. ## Why not three checks The obvious alternative is to let each compliance workstream own its own rule. It fails in four predictable ways. 1. **Drift.** The copies start identical and diverge on the first fix. A cipher suite gets banned in one copy after an incident; the others still pass. Now two reports about the same host disagree, and nobody can say which is right without reading three rule bodies. 2. **Cost of the estate.** Three rules is three sets of false positives, three exception lists, three sets of people to argue with, and three things to update when TLS 1.2 stops being an acceptable floor. 3. **Incoherent evidence.** An auditor who sees two results for one listener does not conclude that one report is stale; they conclude the control is not operating reliably. The point of a control is that it works the same way every time. 4. **Frameworks multiply.** A customer contract adds a fourth framework. With a crosswalk that is a handful of new rows written by the control owner. With copied rules it is another scanner configuration to build, run and keep green. ## What a crosswalk changes and what it does not It changes **reporting**, not enforcement. The mapping never blocks a deployment, never mutates a resource, never gates a pipeline. It decides which report a failure appears in and under which heading. If you removed the crosswalk entirely, exactly the same listeners would pass and fail; you would simply be unable to say which audit cares. It also does not, on its own, prove the control. A passing check proves the assertion held on the resources it looked at, at the times it ran. Most clauses want more than that: a documented standard saying TLS 1.2 is the floor, a record that the check ran continuously, and a story about what happened when it failed. The crosswalk edge is the pointer that connects those pieces to the clause; it is not the evidence. ## What good looks like in an interview Say the assertion out loud, separately from the clause. Then describe the mapping as data with an owner, kept next to the rule and reviewed when it changes. Then mention the failure direction — that one failed resource means three findings, and that the frameworks may impose different remediation clocks on the same fix, which is a real operational consequence of the mapping and the first thing a control owner notices in practice.

  • What breaks first when each compliance workstream keeps its own copy of the same check?
    The copies diverge on the first fix. Someone tightens the cipher list in one copy after an incident and leaves the others alone, so two reports now disagree about the same listener. An auditor reading both does not assume one is stale — they conclude the control does not operate consistently, which is a worse finding than the original gap.
  • Does a passing check ever fully satisfy a framework clause by itself?
    Rarely. The check proves the assertion held on the resources it examined, at the times it ran. Clauses usually also want a documented standard that fixes the threshold, and confidence the check ran continuously rather than once before the audit. The crosswalk edge points at those pieces; it does not replace them.

One thermometer, three forms. The temperature is measured once; the school, the airline and the clinic each have their own box to copy it into, with their own rules about what counts as too high.

saying these in an interview costs you the question

  • Treats the three frameworks' clauses as identical requirements
  • Copies the rule per framework and calls that coverage
  • Says a passing check proves the control rather than the assertion
  • Thinks the crosswalk enforces or blocks something
  • Forgets that one failure now opens three findings

context

open as a page

What does it mean to decompose a compliance control into automated checks?

level: juniorimportance: must knowfreq 66%

basics

~20 s

Decomposition turns one control sentence into the separate facts a machine can test. "Audit logging enabled and retained 365 days" becomes distinct checks: a log destination exists, retention is at least 365, tamper-evidence is on, delivery still succeeds.

open as a page

A control report says 98% of database instances are encrypted at rest — what does that number hide?

level: juniorimportance: must knowfreq 63%

basics

~20 s

A pass rate hides its denominator. The 98% counts only instances the check actually enumerated; anything in an account, region or project the tooling never reached sits outside both numbers, so unseen systems are invisible rather than failing.

open as a page

Your 90-day password rotation check passes on every account — what risk does it not cover?

level: juniorimportance: must knowfreq 62%

basics

~20 s

It proves only that passwords change on schedule. It says nothing about phishing, stolen session tokens, or accounts that were never removed. A green control measures the activity someone wrote down, not the attack it was meant to stop.

open as a page

What must an automated backup-retention check record so its result works as audit evidence later?

level: juniorimportance: must knowfreq 63%

basics

~20 s

Each record needs the verdict plus everything that makes it re-checkable: which control it proves, which resource was evaluated, the exact rule version and input it saw, when it ran, and which identity ran it.

open as a page

What must a policy-as-code waiver record carry besides the rule id and a reason?

level: juniorimportance: must knowfreq 64%

basics

~20 s

A usable waiver names five things: who owns it, exactly what it covers, why the rule cannot be met, who approved it, and when it expires. A rule id plus free text is a note, not a waiver.

open as a page

A compliance check passed on March 3rd - what does that result claim about the system on March 20th?

level: juniorimportance: must knowfreq 62%

basics

~20 s

Only that the resource satisfied the rule at the moment it was evaluated. A pass is a timestamped observation, not a standing property, so every verdict has to be published together with the time it was taken.

open as a page

Why can a host that passed a security baseline check last quarter fail the same check today?

level: juniorimportance: must knowfreq 64%

basics

~20 s

The host moved, not the rule. Three ordinary causes: an operator hand-edited configuration during an incident, a package upgrade shipped new vendor defaults over the compliant settings, or an agent converged the host back to its own state.

open as a page

In an InSpec profile run, what is the difference between a failed control and a skipped one?

level: juniorimportance: must knowfreq 72%

basics

~20 s

A failed control ran and the host did not satisfy it. A skipped control never ran at all - wrong platform, a guard, or a waiver - so it yields no evidence about that requirement, and it is not a pass.

open as a page

How do you make a waiver's expiry date enforced by the engine rather than documentation?

level: middleimportance: must knowfreq 52%

basics

~20 s

Store expiry as a timestamp in the exception record and have the rule compare it to the time it is deciding. Past the date the record stops matching, so the original rule denies again with no human action required.

open as a page

Three of five assertions for an audit-logging control are automated — do you mark it green?

level: seniorimportance: must knowfreq 54%

basics

~20 s

No. Report status per assertion, not per control, and mark the control partially covered. Green on a control whose automation touches three of five assertions tells every reader that all five were tested, which is a claim your evidence does not support.

open as a page

What belongs in a machine-readable crosswalk mapping one check to clauses in several frameworks?

level: middleimportance: should knowfreq 47%

basics

~10 s

Per framework: the catalog revision being mapped against, the clause identifier, the check that answers it, how strongly it answers it, and an owner. OSCAL expresses this as one control-implementation block per framework.

open as a page

A control requires annual security-awareness training — how do you handle a control with no machine check?

level: middleimportance: should knowfreq 45%

basics

~20 s

Say so explicitly. Training and background checks decompose to evidence collection, not a pass-or-fail rule: automate gathering dated records, then have a named owner attest the control. Never invent a proxy rule to make the dashboard green.

open as a page

How do you build the applicability set for an encryption-at-rest control across cloud accounts?

level: middleimportance: should knowfreq 54%

basics

~20 s

Enumerate from an authoritative source that owns the whole estate — the organisation's account directory, then each account's own resource listing — never from the checking tool's own findings. Reconcile against the asset inventory and treat every discrepancy as a finding.

open as a page

How do you make a stored compliance evidence record tamper-evident to an auditor?

level: middleimportance: should knowfreq 42%

basics

~20 s

Hash each record, chain each hash to the previous record's, and sign the chain head with a key the producing job cannot reuse. Store the records in append-only storage locked for the retention period the framework requires.

open as a page

How do quarterly, nightly and change-triggered compliance evaluations differ in what they detect?

level: middleimportance: should knowfreq 57%

basics

~20 s

They differ in detection lag and in coverage. A per-audit-period sweep bounds lag at a quarter, a nightly run at a day, and change-triggered evaluation at seconds - but change-triggered only sees resources that emit an event, so it never fires for controls that expire on the calendar.

open as a page

A host that passed a baseline control now fails it: how do you tell whether the host moved or the baseline moved?

level: middleimportance: should knowfreq 48%

basics

~10 s

Compare both sides. Pin the revision of the check content that produced each result; if it is identical across both runs, the host moved. Then diff the recorded compliant state against the measured state.

open as a page

In InSpec, how do you override an upstream benchmark profile's sshd rule without forking it?

level: middleimportance: should knowfreq 56%

basics

~20 s

Write a wrapper profile: declare the upstream profile under depends in inspec.yml, pull its controls in with include_controls, skip_control the rule you are replacing, and add your own stricter control or feed the upstream one a different input value.

open as a page

How do you record a key-rotation check that fully satisfies one framework's clause but only partly another?

level: seniorimportance: should knowfreq 41%

basics

~20 s

Give every mapping edge an explicit strength, and on anything less than full, name the remainder: what else must be true and which artifact carries it. Partial edges must render as partial, never as a green tick.

open as a page

How do you detect production systems that no asset inventory or account list knows about?

level: seniorimportance: should knowfreq 43%

basics

~20 s

Not by scanning the inventory: a system missing from it is invisible to it. Enumerate instead from sources every workload touches anyway — billing, identity, DNS, egress — and treat anything present there but absent from your registered estate as a finding.

open as a page

How do you use incident data to show a green compliance control is not reducing risk?

level: seniorimportance: should knowfreq 52%

basics

~20 s

Map each of the last dozen incidents to the controls that were green throughout it. That table turns opinion into measurement, and the argument it supports is a change to the control's wording, brought with a replacement check.

open as a page

An auditor wants last quarter's policy evaluation re-run to reproduce the same verdict — what makes that possible?

level: seniorimportance: should knowfreq 51%

basics

~20 s

Reproduction needs the archived input, the exact rule version, the engine version and any external data the rule used, all pinned by digest. It becomes impossible when the rule evaluated live state instead of a captured input.

open as a page

When every expiring policy waiver is renewed unchanged each quarter, what makes a renewal real?

level: seniorimportance: should knowfreq 46%

basics

~10 s

A real renewal re-answers the original question with fresh evidence and a fresh approval, and usually shortens the expiry. A date bump applied to an unchanged record is silent extension wearing a process.

open as a page

How do you evaluate the control "a restore from backup was tested this quarter" on a continuous schedule?

level: seniorimportance: should knowfreq 38%

basics

~20 s

You cannot make the activity continuous, so you evaluate the record of it instead. Turn the control into a recency predicate over an authoritative test record - most recent successful restore test is under 90 days old - which any schedule can then check.

open as a page

On-call widened a host's egress firewall rule at 03:00 to end an incident and the baseline now fails: what did that cost the control?

level: seniorimportance: should knowfreq 55%

basics

~20 s

The host is easy to fix; the period is not. The control can no longer be claimed continuously effective, and the gap is bounded only by the two measurements unless something independently timestamped the change.

open as a page

Why does kube-bench have to run on the node with host PID and host file access?

level: seniorimportance: should knowfreq 44%

basics

~20 s

Most Kubernetes benchmark checks read the flags a component was actually started with and the ownership and mode of files on disk. Neither is exposed by the Kubernetes API, so the runner needs the node's process table and filesystem.

open as a page

Your security backlog is all audit checkboxes while incidents come from elsewhere — how do you rebalance?

level: principalimportance: should knowfreq 38%

basics

~20 s

Split the work into two funded portfolios: obligations, satisfied and evidenced as cheaply as possible, and risk reduction, funded by measured exposure. Then change what gets reported, because one pass-rate number always pulls the backlog toward checkboxes.

open as a page

Your services all use mTLS but no compliance control covers it — why does that matter?

level: middleimportance: nice to knowfreq 30%

basics

~20 s

A defence nobody checks is invisible to the report leadership funds from. It gets no owner, no budget and no alarm when it regresses, it earns no audit credit, and a redundant product gets bought to solve it again.

open as a page

How does a control crosswalk survive a framework revision that splits or withdraws control ids?

level: seniorimportance: nice to knowfreq 30%

basics

~20 s

Treat a revision as a migration, not a find-and-replace. Load the new catalog alongside the old, diff the identifier sets, re-decide every affected edge by hand, and keep the old mapping intact for audits still running against the old revision.

open as a page

With hundreds of framework controls and one engineer-quarter, how do you choose which get automated checks?

level: principalimportance: nice to knowfreq 31%

basics

~20 s

Prioritise by how silently a control's state drifts and how much evidence toil it costs each cycle, not by how easy the check is. Controls the provider satisfies need a citation, and process controls need an attestation; neither deserves engineering time.

open as a page

showing 1–30 of 36