Security authorization and compliance are assessed primarily at the system level through periodic control assessments, while the supporting evidence is generated continuously and may change at the component level between assessments, causing drift. This mismatch limits the ability to determine which prior conclusions remain valid when component evidence, configurations, vulnerabilities, or dependencies change.
This research develops and evaluates a component-centric methodology for continuous compliance assurance, in which atomic security assertions derived from machine-verifiable evidence are composed bottom-up through explicit component relationships to produce continuously updated system-level assurance. The methodology will use clear definitions, component dependency mapping, and prototype-based evaluation to define and test this approach.
Deliverables include the methodology as the primary research contribution, a prototype implementation, and a comparative evaluation of feasibility, traceability, and effectiveness relative to traditional system-level assessment.
Assessments are periodic. The evidence underneath them changes continuously. The gap between the two is drift, and drift quietly invalidates conclusions that no one goes back to re-check.
A system is authorized on a point-in-time picture: this configuration, these vulnerabilities, these dependencies, on this date. But the components underneath, the containers, services, libraries, and controls, keep moving between assessments. When one of them changes, there is no principled way to know which of the earlier system-level conclusions still hold. This research asks whether assurance can be rebuilt from the bottom up so the answer stays current.
A component-centric methodology for continuous compliance assurance: how atomic, evidence-backed assertions about individual components compose upward, through explicit relationships, into a system-level conclusion that stays current as the components change.
Coming soon- DefinitionsThe core terms the methodology rests onComing soon
- Component dependency mappingHow component relationships are representedComing soon
A working prototype that ingests machine-verifiable evidence, maps component dependencies, and produces continuously updated system-level assurance, so the methodology can be tested against real evidence rather than argued on paper.
Coming soonA structured comparison of the component-centric approach against traditional system-level assessment, measured on feasibility, traceability, and effectiveness, to show where and how much it actually helps.
Coming soonWorking on continuous compliance, RMF, or component-level assurance, or just curious where this lands? Let's talk.