Compliance Check

Use when the user asks to assess compliance of a product or deployed cloud environment against PCI DSS, NIST 800-53, FedRAMP High/Moderate, SOC 2 (TSC), or the GDPR technical slice — e.g. "run a compliance check", "assess X against FedRAMP moderate", "SOC 2 posture for this service", "are we meeting 800-53 on this cluster", "compliance across all frameworks". Runs the deterministic assessment runner (code-computed verdicts, evidence bundles, citation gate) and judges only evidence_review controls; emits compliance-assessment.{json,md} + optional OSCAL. "interview" mode is the self-service intake: it walks a service owner through boundary declaration and evidence-review context, writing a validated scope-registry entry and an attestation bundle — attestations are evidence, never verdicts.

openshift 3711e61 6 files · 82.7 KB Updated

File contents

openshift/traust/tree/main/harnessing/3-audit/compliance-check commit 3711e610ba

Frequently asked questions

npx skillmds@latest add openshift/compliance-check