Show pageOld revisionsBacklinksAdd to bookExport to PDFODT exportBack to top This page is read only. You can view the source, but not change it. Ask your administrator if you think this is wrong. ====== Compliance as Code (CaC) ====== [[dido:99_annexes:annex-b-terms-and-definitions:start|Go up to Terms and Definitions]] ===== Discussion ===== Compliance as Code (CaC) represents compliance criteria, assessment logic, configuration expectations, remediation instructions, and evidence-generation rules through machine-processable artifacts. CaC enables automated tools to apply, evaluate, compare, report, and reproduce compliance-related activities within build, deployment, and operational processes. CaC may include machine-processable benchmarks, profiles, control mappings, policy rules, validation logic, remediation content, evidence templates, and reporting rules. Within Crucible, CaC supports declaration of a [[dido:99_annexes:annex-b-terms-and-definitions:c:compliance_posture|Compliance Posture]], automated scanning during an Image Build, normalization of findings, remediation, and generation of reproducible compliance evidence. ===== Definition ===== //representation of compliance criteria, assessment logic, configuration expectations, remediation instructions, and evidence-generation rules through machine-processable artifacts// ===== Source ===== Generalized from policy as code, security automation, continuous compliance, machine-processable benchmarks, and configuration management and specialized for the Crucible architecture and operational model. ===== Note ===== CaC does not replace governance judgment, legal interpretation, risk acceptance, accreditation, or authorization decisions. Machine-processable content may implement only part of an applicable compliance obligation. Organizational procedures, human review, external evidence, or contextual interpretation may remain necessary. ===== Example ===== A machine-processable [[dido:99_annexes:annex-b-terms-and-definitions:s:stig|Security Technical Implementation Guide (STIG)]] profile defines configuration checks and remediation content for [[dido:99_annexes:annex-b-terms-and-definitions:r:rhel|RHEL 9]]. Crucible applies the content during an Image Build and produces normalized findings and associated evidence. ---- <WRAP centeralign> © 2026 Dido Solutions, Inc. and Jackrabbit Consulting, Inc. </WRAP> dido/99_annexes/annex-b-terms-and-definitions/c/cac.txt Last modified: 2026/07/18 12:33by 127.0.0.1