[ UNCLASSIFIED // CHANCO.DEV / PRAXIS ]
Doctor of Engineering · Cybersecurity · George Washington University

Component-Centric Assurance Methodology

My doctoral praxis: a way to keep security compliance continuously true at the component level, instead of trusting a system-level snapshot taken months ago. This page follows the research as it develops, from the core definitions to the prototype and the evaluation.

01 The pitch

Security authorization and compliance are assessed primarily at the system level through periodic control assessments, while the supporting evidence is generated continuously and may change at the component level between assessments, causing drift. This mismatch limits the ability to determine which prior conclusions remain valid when component evidence, configurations, vulnerabilities, or dependencies change.

This research develops and evaluates a component-centric methodology for continuous compliance assurance, in which atomic security assertions derived from machine-verifiable evidence are composed bottom-up through explicit component relationships to produce continuously updated system-level assurance. The methodology will use clear definitions, component dependency mapping, and prototype-based evaluation to define and test this approach.

Deliverables include the methodology as the primary research contribution, a prototype implementation, and a comparative evaluation of feasibility, traceability, and effectiveness relative to traditional system-level assessment.

02 The problem

Assessments are periodic. The evidence underneath them changes continuously. The gap between the two is drift, and drift quietly invalidates conclusions that no one goes back to re-check.

A system is authorized on a point-in-time picture: this configuration, these vulnerabilities, these dependencies, on this date. But the components underneath, the containers, services, libraries, and controls, keep moving between assessments. When one of them changes, there is no principled way to know which of the earlier system-level conclusions still hold. This research asks whether assurance can be rebuilt from the bottom up so the answer stays current.

03 Deliverables
01 · PRIMARY CONTRIBUTION In progress
The methodology

A component-centric methodology for continuous compliance assurance: how atomic, evidence-backed assertions about individual components compose upward, through explicit relationships, into a system-level conclusion that stays current as the components change.

Coming soon
  • DefinitionsThe core terms the methodology rests onComing soon
  • Component dependency mappingHow component relationships are representedComing soon
02 · ARTIFACT Planned
Prototype implementation

A working prototype that ingests machine-verifiable evidence, maps component dependencies, and produces continuously updated system-level assurance, so the methodology can be tested against real evidence rather than argued on paper.

Coming soon
03 · EVALUATION Planned
Comparative evaluation

A structured comparison of the component-centric approach against traditional system-level assessment, measured on feasibility, traceability, and effectiveness, to show where and how much it actually helps.

Coming soon
04 Follow along

Working on continuous compliance, RMF, or component-level assurance, or just curious where this lands? Let's talk.