AspisAI enables automated and traceable multi-standard compliance monitoring

AspisAI: A Canonical, Machine-Interpretable Governance Framework for Automated Multi-Standard Compliance Monitoring

Cryptography and SecurityComputers and SocietySoftware Engineering

Summary

Companies must follow many different security and privacy rules at the same time, which is usually hard and done by hand. The authors created AspisAI, a system that turns these various rules into one common model a computer can understand. It checks submitted evidence automatically and explains whether rules are met, making compliance easier to track and audit. They tested AspisAI on real and simulated data, showing it works well and matches other trusted mappings.

What this means in practice

  • For security compliance teams: Automatically evaluate compliance evidence across multiple cybersecurity and privacy standards to improve audit consistency and traceability.
  • For open source project maintainers: Identify and address governance gaps by applying a machine-readable compliance model to third-party security score data.

Authors

Tsafac Nkombong Regine Cyrille, Hasan Dag, Reiner Creutzburg, Knut Haufe

Abstract

Organisations operating in regulated and critical-infrastructure sectors must satisfy multiple, heterogeneous cybersecurity and privacy instruments simultaneously, including but not limited to ISO/IEC~27001, the NIST Cybersecurity Framework~2.0, Cyber Essentials, and the GDPR. In practice, these obligations are managed through manual mappings, spreadsheet-based tracking, and periodic audits that are costly to maintain, inconsistent across standards, and weak in traceability. This paper presents \emph{AspisAI}, a bounded, standard-agnostic governance framework that translates selected requirements from several frameworks into a canonical, machine-interpretable control model, and evaluates submitted evidence against condition-based decision rules to produce explainable, traceable compliance determinations. Within a bounded scope of 26 representative requirements, the framework is evaluated in a controlled simulation against five governance-oriented criteria and, critically, against two external reference points that mitigate the circularity of single-author evaluation: its cross-standard mappings are validated against NIST's own published informative references, with 57\,\% exact agreement and divergences confined to same-family controls, and the framework is applied to real third-party evidence from the OpenSSF Scorecard, surfacing genuine governance gaps in a live open-source project. The controlled results, comprising full requirement encoding, 88.5\,\% mapping coverage, complete traceability, and correct detection of all introduced gaps, establish functional correctness, while the external validation provides evidence of applicability beyond the simulation. The contribution is therefore a demonstration that a canonical, provenance-preserving governance model can render multi-standard compliance both automatable and auditable.