The fastest path from documentation to execution is evidence automation. The goal is to make the normal delivery pipeline produce the proof that the SSP and POA&M need.
Evidence Pipeline
| Stage | Producer | Evidence | Control Families | Storage |
|---|
| Source control | GitHub | Pull request, CODEOWNERS review, branch protection export. | AC, CM, SA | GitHub and evidence repository |
| Build | GitHub Actions | Workflow log, tests, build metadata. | CM, SA, SI | GitHub artifacts |
| Static analysis | CodeQL, Semgrep | SARIF findings. | RA, SA, SI | GitHub security and evidence repository |
| Secret scanning | gitleaks or TruffleHog | Secret scan report. | IA, SC, SI | CI artifact and security dashboard |
| Dependency scanning | Trivy, Grype, OSV-Scanner | Vulnerability report. | RA, SI, SR | CI artifact and POA&M |
| SBOM | Syft | CycloneDX or SPDX SBOM. | CM, SR | Artifact registry |
| Signing | cosign | Signature and verification output. | CM, SI, SR | Registry and evidence repository |
| Provenance | SLSA generator | in-toto attestation. | SA, SR | Registry and evidence repository |
| Deployment | Argo CD | Sync result, app health, target revision. | CM, AU | Argo CD and evidence export |
| Admission policy | Kyverno | PolicyReport and blocked admission records. | AC, CM, SC, SI | Cluster and evidence repository |
| Runtime detection | Falco | Runtime alert and triage result. | SI, IR | Alerting system |
| Observability | OpenTelemetry, Prometheus, Grafana, Loki | Metrics, traces, logs, dashboard snapshots. | AU, CA, SI | Observability stack |
| Backup | Velero, pgBackRest, provider backup | Backup and restore evidence. | CP, SC | Backup system and evidence repository |
OSCAL Automation Targets
| OSCAL Artifact | Source | Generator Candidate | Review Owner |
|---|
| Component definition | Kubernetes policies, scanners, CI/CD controls. | Compliance Trestle or hand-authored OSCAL YAML | Platform Engineering |
| SSP model | Approved SSP implementation statements. | Compliance Trestle | Security |
| Assessment plan input | Control matrix and evidence inventory. | Compliance Trestle | Security and 3PAO |
| Assessment results | Lula validation, scanner reports, 3PAO results. | Lula and 3PAO tooling | Security |
| POA&M data | Risk register and findings workflow. | GitHub Issues export or compliance system | Security |
Minimum Evidence Bundle Per Release
| Artifact | Required | Reason |
|---|
| Pull request link | Yes | Shows reviewed change and separation of duties. |
| CI workflow run | Yes | Shows test and scan execution. |
| Test report | Yes | Shows expected behavior was verified. |
| SAST report | Yes | Shows secure-development scanning. |
| Secret scan report | Yes | Shows secrets were checked before release. |
| Dependency or image scan | Yes | Shows vulnerability posture at release time. |
| SBOM | Yes | Shows software inventory for the released artifact. |
| Signature | Yes | Shows artifact integrity and origin. |
| Provenance | Yes | Shows build source and workflow. |
| Deployment record | Yes | Shows what reached production. |
Monthly Evidence Bundle
| Artifact | Required | Reason |
|---|
| Current inventory | Yes | Supports CM-8 and scan completeness. |
| Full vulnerability scan set | Yes | Supports RA-5 and SI-2. |
| POA&M update | Yes | Supports CA-5 and risk governance. |
| Access review status | Yes | Supports AC and IA controls. |
| Backup status | Yes | Supports CP controls. |
| Incident summary | Yes | Supports IR and SI controls. |
| Audit log review | Yes | Supports AU controls. |
| Significant change summary | Yes | Supports CA and CM controls. |
Automation Backlog
| Priority | Automation | Expected Gain |
|---|
| 1 | CI emits SBOM, scan reports, signatures, and provenance for every release. | Large evidence gain for SA, SI, SR, RA, and CM. |
| 2 | Monthly ConMon issue auto-populates links to scans, inventory, POA&M, and release records. | Reduces manual package assembly. |
| 3 | Kubernetes policy reports export to durable evidence storage. | Makes SC, CM, and SI control posture reviewable. |
| 4 | Access review exports are generated on schedule. | Makes AC and IA evidence repeatable. |
| 5 | OSCAL component-definition links to live validation results. | Moves toward FedRAMP 20x-ready documentation. |
Automation Definition of Done