By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: QCon London: Bringing DevOps Principles to Controls and Audit
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > News > QCon London: Bringing DevOps Principles to Controls and Audit
News

QCon London: Bringing DevOps Principles to Controls and Audit

News Room
Last updated: 2025/04/09 at 11:07 AM
News Room Published 9 April 2025
Share
SHARE

Ian Miell, author of many books, including “Docker in Practice,” and Consultant Partner at Container Solutions, delivered a talk at QCon London 2025 on a modernised approach to compliance, announcing an open-source project that aims to solve many of the problems seen in the audit and compliance process.

“The way we manage compliance is wrong, but it is changing,” Miell stated, highlighting that there’s a disconnect between modern DevOps practices of automation and repeatability and traditional audit and compliance procedures which tend to be manual, ad-hoc and inefficient.

Miell’s team has developed the Continuous Compliance Framework (CCF), a project that emerged from real-world frustrations voiced by their customers about their own auditing and compliance processes. Miell went through the current state of compliance management, explaining how it suffers from four critical problems from the point of view of operations teams.

Firstly, Miell has found predominantly manual processes, with audits and compliance largely driven by Wiki pages, spreadsheets and ad-hoc screenshots to track compliance status. Next, the audits happen periodically (perhaps every 6 months), which means that a company may be non-compliant outside audit periods. Next, Miell has found that audits tend to focus on documentation rather than actual working practices, and he analogised this to being the exact opposite of the first element of the Manifesto for Agile Development. Finally, compliance processes tend to be bespoke and non-repeatable depending on who is doing the auditing and for whom, with little possibility of interoperability between them.

Audit and compliance are seen as a side activity and therefore are treated like a tax. It’s something we have to do, but we don’t want to talk to these people really.

Miell explained that this perception problem combined with the manual toil outlined above makes audit and compliance costly and unscalable. He cited research indicating that 10% of overall banking operational costs (not just on technology) is spent on compliance, and that regulatory interest is also increasing, for example with the EU’s Digital Operational Resilience Act (DORA) coming into effect this year.

During his presentation, Miell demonstrated the Continuous Compliance Framework (CCF). He showed how the tool can take data from multiple cloud environments, showing a system monitoring AWS VPCs, Azure subscriptions, and on-premise applications represented by Docker containers. He showed how the system generates real-time compliance data streams that users can filter and analyse into dashboards. According to Miell, CCF’s real-time capabilities, use of open standards, and developer-first approach set it apart from competitors, which tend to be closed-source and expensive. “Competitors come from the compliance side, whereas this comes from the development angle,” he explained.

At the core of the Continuous Compliance Framework is OSCAL (Open Security Controls Assessment Language), a standard written by the US National Institute of Standards and Technology (NIST), which defines machine-readable documents that compatible tools can interpret. “We decided to go all-in on OSCAL,” Miell explained, citing how it is well thought-out and covers the topic thoroughly. He did acknowledge that it can be “quite opaque to understand” however. Miell noted that his team is working with NIST on potential improvements to OSCAL, particularly around adding streaming concepts alongside the existing point-in-time focus.

An OSCAL visualisation tool written by Container Solutions

The architecture behind CCF is agent-based, with small, lightweight agents that can run anywhere. It’s written in Golang and has a MongoDB backend (chosen because OSCAL is JSON-based), with REGO as the policy configuration language.

Looking to the project’s roadmap, Miell hopes that CCF will become a standard for centralised control management. Future plans include more integrations with security tools such as Black Duck, Snyk and meld.io, and perhaps a plugin marketplace. Referring back to his conversations with CISOs, Miell closed his talk by stating a main goal for CCF of helping them to sleep at night, knowing that their systems are being continuously monitored and audited for compliance issues. Miell hopes the system becomes defacto for “gathering evidence from stream data, and being able to slice and dice depending on who is looking at it”.

CCF is available on GitHub now.

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article Nigeria’s telecom sector unaffected by Trump’s 14% export tariff 
Next Article These closed-back planar headphones look as gorgeous as they’ll sound | Stuff
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

How Google’s new Gemini AI update keeps us safe from online scams
News
Legend, Nigeria’s first publicly listed ISP, has bigger internet plans
Computing
Hisense’s 2025 TV range looks great, but it’s the 100in TVs that really set it apart | Stuff
Gadget
Most AI Spending Due to Fear of Falling Behind, According to IBM
News

You Might also Like

News

How Google’s new Gemini AI update keeps us safe from online scams

4 Min Read
News

Most AI Spending Due to Fear of Falling Behind, According to IBM

1 Min Read
News

Unlocking Digital Impact: Inetum Redefines Transformation Through Platform Ecosystems and AI Innovation

12 Min Read
News

Chrome for Android will soon warn you against scam notifications

2 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?