Sovereign Compliance, ISO Standards, SOC 2 & Data Governance
Okustera is architected from the bare-metal layer up to guarantee National and European Data Sovereignty, full compliance with the EU NIS2 Directive (2022/2555), GDPR Chapter V (Regulation EU 2016/679), AICPA SOC 2 Type II (Trust Services Criteria), and international Cloud ISO Standards (ISO/IEC 17788/17789, 27001, 27017, 27018, 19941, and 22301).
ποΈ The Sovereign Compliance Frameworkβ
1. Cloud ISO Standards Mapping & Technical Controlsβ
Okustera's technical controls directly implement the specifications of international cloud standards:
| ISO Standard | Scope | Okustera Technical Architecture & Enforcement |
|---|---|---|
| ISO/IEC 17788 & 17789 | Cloud Computing Reference Architecture | Clean three-tier architectural separation of Resource Layer (KVM, Ceph, physical network), Control Layer (Nova, Neutron, Cinder, K8s CAPI), and Tenant Workload Layer. Standard IaaS, DBaaS, and AI PaaS. |
| ISO/IEC 27001:2022 | Information Security Management System (ISMS) | β’ Access Control (A.8.2): Keystone RBAC, domain-scoped access, mandatory TOTP 2FA, scoped application credentials, and Kubernetes Pod Workload Identity. β’ Cryptography (A.8.24): Hardware-accelerated LUKS AES-256 envelope encryption-at-rest via OpenStack Barbican KMS with tenant crypto-shredding; Cilium WireGuard pod-to-pod transparent mesh encryption; Ceph Messenger v2 in-transit wire encryption; Virtual TPM 2.0 ( swtpm) measured boot; mandatory TLS 1.3 on external ingress.β’ Logging & Monitoring (A.8.15): Centralized Prometheus metrics, Grafana Loki immutable log streams, and Keystone API audit middleware. |
| ISO/IEC 27017:2015 | Cloud Security Controls (CSPs & Customers) | β’ Virtual Segregation (CLD.9.2): Hardware KVM isolation, Linux network namespaces, and OVN Geneve L3 virtual routing preventing cross-tenant leakage. β’ Secure Deletion (CLD.8.1.5): Immediate cryptographic erasure and block unmapping ( discard: unmap) upon Cinder/Ceph volume deletion.β’ Runtime Sandboxing (CLD.9.5.2): Google gVisor ( runsc) user-space virtualization for untrusted AI agent execution and serverless functions. |
| ISO/IEC 27018:2019 | Protection of PII in Public Cloud | β’ Data Localization: 100% in-country data residency; zero data transfer outside the physical hosting boundary; zero US CLOUD Act exposure. β’ Zero Data Exploitation: Tenant model prompts, vector embeddings, and database tables are never shared or used for AI model training. β’ Jurisdictional Transparency: Physical server serial numbers, node IDs, and storage rack layouts are transparently verifiable. |
| ISO/IEC 19941:2017 | Cloud Interoperability & Portability | β’ Pure Open APIs: Standard OpenStack REST APIs, CNCF Kubernetes APIs, AWS S3-compatible Ceph RGW, OpenAI /v1 inference specification, and official Terraform providers (openstack + okustera). Zero proprietary API lock-in.β’ Workload Portability: Unmodified QCOW2/RAW VM images, OCI container images, Helm charts, and standard database dumps. |
| ISO/IEC 22301:2019 | Business Continuity & Disaster Recovery | β’ Storage Redundancy: Ceph CRUSH rules with 3x replication across physical failure domains with automatic rebalancing. β’ Control Plane HA: Clustered MariaDB Galera (multi-master), RabbitMQ quorum queues, and HAProxy virtual IPs. β’ DBaaS Resiliency: Sub-10s automated failover quorum (CloudNativePG, Valkey Sentinel) and continuous WAL archiving to immutable S3 buckets with WORM object locking. |
| AICPA SOC 2 Type II | Trust Services Criteria (Security, Availability, Confidentiality, Processing Integrity) | β’ Perimeter Protection (CC6.6): WAN perimeter firewalls and strict ingress packet filtering. β’ Access Control (CC6.1): Scoped least-privilege credentials and RBAC. β’ Continuous Monitoring (CC7.2): Predictive anomaly detection via Cluster Sentinel daemon. β’ System Resiliency (A1.2): Automated disaster recovery and self-healing reboot runbooks. β’ Change Management (CC8.1): GitOps commit traceability and tamper-resistant software verification. β’ In-Transit Confidentiality (C1.1 & C1.2): End-to-end TLS 1.3 cryptographic cipher suites, Cilium WireGuard pod-to-pod transparent mesh encryption, and Ceph Messenger v2 encrypted wire protocols. |
The Cloud Security Shared Responsibility Model (ISO 27017 & Cloud Standards)β
As defined across international cloud security standards (ISO/IEC 27017, NIST SP 800-144, and industry frameworks synthesized in Wiz Cloud Security Standards), cloud security is an explicit shared partnership between the Cloud Service Provider (CSP) and the tenant customer:
- Okustera CSP Responsibilities:
- Physical datacenter facilities, power feeds, and sovereign bare-metal hardware.
- Hypervisor layer isolation (KVM security context, CPU pinning, memory virtualization).
- Storage pool encryption-at-rest (Ceph NVMe pools with per-tenant Barbican KMS key escrow).
- Software-Defined Networking core (OVN Geneve virtual routers, inter-tenant isolation, WAN border firewalls).
- Continuous platform health monitoring, predictive Sentinel anomaly telemetry, and automated BCDR failover.
- Customer Tenant Responsibilities:
- Identity governance: configuring Keystone user roles, enforcing TOTP two-factor authentication, and rotating API access tokens.
- Network access rules: defining Neutron security group ingress filters and VPC route tables.
- Guest operating system maintenance: installing security updates, managing application containers, and configuring workload firewalls.
- Workload data management: managing application-level encryption keys and executing GDPR Right to Erasure workflows for customer end-users.
- Continuous Cloud Security Posture Assessment:
- Moving beyond point-in-time annual audits, Okustera provides the automated Compliance Inspector (
okustera-auditCLI tool and Backoffice Hub) to continuously evaluate infrastructure baselines and flag security drift in real time.
- Moving beyond point-in-time annual audits, Okustera provides the automated Compliance Inspector (
2. EU NIS2 Directive (2022/2555) Complianceβ
As a digital infrastructure provider, Okustera implements the technical, operational, and organizational measures mandated under Article 21 and Article 23 of the NIS2 Directive:
Article 21: Cybersecurity Risk-Management Measuresβ
- Supply Chain Security & SBOM (Art. 21.2.d):
- All container images hosted in Artifact Keeper (
artifacts.okustera.com) are cataloged with Software Bill of Materials (SBOM) and continuously scanned against National Vulnerability Databases (NVD) via DependencyTrack. - The AI Model Foundry strictly enforces SafeTensors binaries, preventing arbitrary code execution vulnerabilities common in unverified PyTorch pickle weights (CVE-2024-34359).
- All container images hosted in Artifact Keeper (
- Cryptography & Encryption (Art. 21.2.h):
- Mandatory encryption-at-rest across Ceph block storage and database backups using Barbican KMS.
- Enforced TLS 1.3 with modern cipher suites on all external ingress endpoints (APISIX API Gateway).
- Multi-Factor Authentication (Art. 21.2.j):
- Mandatory Time-based One-Time Password (TOTP) two-factor authentication on all Web Console logins, credential resets, and sensitive administrative actions.
- Business Continuity & Backup Management (Art. 21.2.c):
- Fully automated Point-In-Time Recovery (PITR) with continuous WAL streaming, offsite immutable backup vaults, and scheduled restoration drills.
Article 23: Incident Reporting Obligationsβ
- 24-Hour Early Warning: Keystone audit middleware and Grafana Loki log streaming detect anomalous access patterns or unauthorized authentication attempts, automatically triggering operational alerts.
- 72-Hour Full Assessment: Detailed immutable request traces capture caller identity, source IP, timestamp, and mutated resource IDs for rapid forensic audit and authority notification.
3. GDPR Compliance Checklist & National Data Sovereignty (Regulation EU 2016/679)β
Okustera guarantees strict jurisdictional integrity for European and regulated public sector workloads, implementing the complete GDPR Compliance Framework across technical, operational, and architectural layers:
Pillar 1: Lawful Basis and Transparency (Articles 6, 12, 13, 14, 30)β
- Information Audit & Records of Processing Activities (RoPA, Art. 30):
- Okustera maintains an automated inventory of all data processing activities, storage pools (Ceph RBD/RGW), database clusters, and tenant metadata.
- Pre-configured Data Protection Impact Assessment (DPIA) templates assist tenants in documenting high-risk workloads before production deployment.
- Lawful Justification for Processing (Art. 6):
- Infrastructure operates strictly under contractual necessity and tenant consent. Customer data, database tables, prompts, and vector embeddings are never utilized for secondary purposes, telemetry training, or advertising.
- Transparent Privacy Documentation & Privacy Notices (Articles 12, 13, 14):
- Guided by the official GDPR.eu Privacy Notice Framework, Okustera provides transparent, intelligible, and easily accessible documentation of all platform processing activities.
- Notices explicitly outline: Controller and DPO contact details, lawful basis (contractual execution under Art. 6), specific retention schedules, categories of infrastructure sub-processors, zero cross-border transfer guarantees (100% in-country pinning), data subject rights, right to lodge complaints with supervisory authorities, and absence of automated profiling on customer workloads.
- Drafted in plain, active language avoiding ambiguous qualifiers (e.g. "may" or "might").
Pillar 2: Data Security & Privacy by Design (Articles 25, 32, 33, 34, 35)β
- Data Protection by Design & Default (Art. 25):
- Multi-tenant micro-segmentation via OVN Geneve L3 VPCs, strict default-deny firewall policies, and ephemeral workload identity tokens eliminate cross-tenant data exposure at the hardware level.
- Encryption, Pseudonymization & Anonymization (Art. 32):
- At Rest: Enforced hardware AES-256 LUKS volume encryption with keys held in tenant-dedicated Barbican KMS vaults.
- In Transit: Mandatory TLS 1.3 with Perfect Forward Secrecy (PFS) across all public API ingress and inter-node control planes.
- Telemetry: System metrics and access logs pseudonymize customer identifiers to prevent inadvertent PII leakage in monitoring pipelines.
- Internal Security Policies & Operational Controls:
- Mandatory Time-based One-Time Password (TOTP) two-factor authentication, strictly restricted 0600 file permissions for configuration and credential files, and automated secret rotation.
- Data Protection Impact Assessment (DPIA, Art. 35):
- Built-in posture assessments evaluating high-risk processing (e.g. AI inference models, vector search, multi-tenant databases).
- 72-Hour Breach Notification Process (Articles 33 & 34):
- Keystone audit middleware and Grafana Loki log streams continuously monitor anomalous authentication and access patterns.
- Automated alerting notifies security teams and data protection leads immediately upon anomalous incident detection, enabling full forensic reporting to supervisory authorities within 72 hours.
Pillar 3: Accountability and Governance (Articles 25, 27, 28, 37-39)β
- Data Processing Agreements (DPA, Art. 28):
- Standard enterprise DPAs clearly define the division of responsibility between the Cloud Service Provider (Data Processor) and the tenant (Data Controller), guaranteeing zero sub-processor ambiguity.
- EU Representative & Anti-CLOUD-Act Sovereign Pinning (Art. 27 & Chapter V):
- 100% owned, operated, and hosted on sovereign European physical bare-metal hardware.
- Zero Extraterritorial Jurisdiction: The operating entity is purely non-US and immune to foreign surveillance warrants or extraterritorial discovery requests (including the US CLOUD Act and FISA 702).
- All tenant workloads, persistent block volumes, object stores, and database replicas remain physically pinned to national datacenters.
- Data Protection Officer (DPO, Articles 37-39):
- Dedicated compliance governance overseeing regulatory alignment, cooperating with EU national supervisory authorities (e.g. CNIL, BfDI, DPC), and supervising continuous compliance checks.
Pillar 4: Privacy Rights of Data Subjects (Articles 15-22)β
- Right of Access & Data Portability (Articles 15 & 20):
- Tenants retain full ownership of all data. Workloads can be exported instantly in open, non-proprietary formats (QCOW2/RAW VM images, OCI container images, standard S3 objects, and native PostgreSQL/MySQL dumps) with zero vendor lock-in.
- Right to Rectification (Art. 16):
- Self-service API and Backoffice management allow immediate updates to tenant records, billing profiles, and project metadata.
- Right to Erasure Intake & Crypto-Shredding Architecture (Art. 17):
- Following the GDPR.eu Right to Erasure Request Framework, Okustera standardizes the intake, identity validation, and execution of "Right to be Forgotten" requests within the statutory 30-day (1-month) SLA.
- Identity Verification: Requests require cryptographic identity validation (scoped Keystone token or certified tenant authorization) to prevent unauthorized data loss.
- Statutory Grounds & Exception Review: Verification against Article 17(1) conditions (data no longer needed, consent revocation, Art. 21 objection) and Article 17(3) statutory exceptions (financial tax records, ongoing litigation defense).
- The Immutable Cloud Backup Dilemma: In cloud architectures, immutable WORM backups (Ceph S3 Object Lock, PostgreSQL WAL streams) cannot be physically pruned without breaking cryptographic hash chains.
- The Barbican KMS Crypto-Shredding Solution: When an erasure request is executed, the per-tenant Barbican KMS master encryption key is destroyed. This instantaneously and permanently renders all active block volumes, object snapshots, and historical immutable S3 backup archives mathematically unreadable, achieving verifiable compliance with Article 17 while maintaining WORM storage integrity.
- Formal Declaration: A cryptographically signed audit certificate of erasure is generated for tenant compliance records.
- Right to Restriction & Right to Object (Articles 18 & 21):
- Tenant administrators can instantly quarantine workloads, freeze compute instances, or revoke IAM API credentials via one-click controls.
- Safeguards for Automated Decision-Making (Art. 22):
- Human-in-the-loop validation is enforced for destructive operations, quota modifications, and account terminations.
4. Multi-Region Geographic Architectureβ
Okustera supports scaling across multiple autonomous geographic locations (RegionOne, RegionTwo):
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
β Global Identity & Governance β
β Keystone (IAM & SSO) Β· Okustera Web Portal Β· Terraformβ
βββββββββββββββββββββββββββββ¬βββββββββββββββββββββββββββββ
β
βββββββββββββββββββββββββββββββ΄ββββββββββββββββββββββββββββββ
βΌ βΌ
βββββββββββββββββββββββββββββ βββββββββββββββββββββββββββββ
β RegionOne (e.g. Frankfurt)β β RegionTwo (e.g. Zurich) β
βββββββββββββββββββββββββββββ€ βββββββββββββββββββββββββββββ€
β β’ KVM Hypervisors (Nova) β β β’ KVM Hypervisors (Nova) β
β β’ OVN Geneve L3 VPCs β β β’ OVN Geneve L3 VPCs β
β β’ Ceph NVMe Storage Pool β β β’ Ceph NVMe Storage Pool β
β β’ Regional Kubernetes API β β β’ Regional Kubernetes API β
β β’ Local AI PaaS (vLLM) β β β’ Local AI PaaS (vLLM) β
β β’ Local Barbican KMS Vaultβ β β’ Local Barbican KMS Vaultβ
βββββββββββββββββββββββββββββ βββββββββββββββββββββββββββββ
Region vs. Availability Zone (AZ)β
- Availability Zones (AZs): Share a local control plane and are designed for sub-millisecond synchronous application high availability across power feeds or racks.
- Regions (
RegionOne,RegionTwo): Autonomous datacenters in different countries or jurisdictions. Each region operates independent Keystone, Barbican KMS, Ceph, and Kubernetes control planes with zero cross-border WAN dependencies, preventing cross-border telemetry leakage.
5. How Backup & Disaster Recovery (BCDR) Impacts ISO Standardsβ
While having a robust BCDR strategy is an explicit requirement under ISO/IEC 27001 (Control 8.13) and ISO 22301 (Clause 8.5), an improperly designed backup architecture is one of the most common causes of audit failure.
Okustera enforces specific technical guardrails to prevent BCDR operations from breaking ISO standards:
| BCDR Failure Mode | Violated ISO Standard | Failure Mechanism | Okustera Technical Safeguard |
|---|---|---|---|
| Cross-Border Replication | ISO/IEC 27018 (A.10.1) GDPR Chapter V | Backups replicated to an offsite region in a foreign country violate data sovereignty and transfer laws. | Sovereign-Boundary BCDR: Regional backups default strictly to within-border facilities. Cross-border replication requires explicit tenant opt-in via Terraform. |
| Privilege Escalation ("Backdoor to Data") | ISO/IEC 27001 (Controls 5.15, 8.2) ISO/IEC 27017 (CLD.9.2) | Primary DB enforces strict RBAC, but backup storage buckets have loose permissions, allowing admins to restore and dump tenant data. | Append-Only Workload Identity: Backup agents (Barman, Velero) use scoped Kubernetes Pod IAM with write-only access (s3:PutObject). Downloads require two-man rule TOTP authorization. |
| Unencrypted Backups & Key Loss | ISO/IEC 27001 (Control 8.24) ISO 22301 (Clause 8.4) | Backups are stored in cleartext, or encryption keys are lost when the host dies, causing permanent data loss. | Envelope Encryption & Distributed KMS: Backups are encrypted with per-tenant Barbican KMS keys. Master key escrows are securely replicated out-of-band using Shamir's Secret Sharing. |
| Multi-Tenant Commingling | ISO/IEC 27017 (CLD.9.2) | Snapshots of multiple tenants are dumped into a shared, un-partitioned bucket, risking cross-tenant data bleed. | Cryptographic Tenant Segregation: Backups are written to tenant-dedicated Ceph RGW buckets encrypted with unique tenant keys. |
| Untested Backups ("SchrΓΆdinger's Backup") | ISO/IEC 27001 (Control 8.13) ISO 22301 (Clause 8.5) | Backups run on a cron job, but restorations are never tested. ISO auditors classify untested backups as non-existent. | Automated Synthetic Restore Drills: Automated CI/CD pipelines restore CloudNativePG WAL archives and Velero manifests into isolated sandbox namespaces weekly. |
| Retention Overruns vs. Right to Erasure | ISO/IEC 27018 (A.12.1) ISO 27701 (7.4.7) | Immutable backups retain PII indefinitely, violating data minimization and the GDPR Right to be Forgotten. | Crypto-Shredding on Tenant Deletion: Destroying the tenant's unique Barbican encryption key instantaneously renders all past immutable backups mathematically unreadable. |
6. Automated Sovereign Compliance Skill & CLI Auditorβ
To guarantee continuous compliance and accelerate external audits, Okustera includes an autonomous agent skill and CLI verification tool:
- Agent Skill:
omc-sovereign-compliance(specifies mandatory invariants across compute, networking, storage, DBaaS, and AI). - Automated Audit CLI:
Evaluates 19 technical controls across data residency, Barbican KMS health, credential permissions, BCDR immutability, NIS2 observability, GDPR crypto-shredding, and AICPA SOC 2 Type II perimeter firewalls, anomaly telemetry, and resiliency.okustera-audit# or directly:bash .agents/skills/omc-sovereign-compliance/scripts/audit_compliance.sh
7. SOC 2 Type II 8-Step Audit Readiness Lifecycleβ
Okustera adheres to the structured 8-step SOC 2 readiness methodology:
- Establish Objectives: Align security posture with customer data protection requirements, enterprise procurement criteria, and regulatory mandates.
- Auditor Selection: Engage independent accredited CPA assessors early across DevOps, SecOps, and Platform engineering teams.
- Report Scope Selection: Focus on SOC 2 Type 2 attestation (evaluating 6β12 months of operational effectiveness) rather than point-in-time Type 1 assessments.
- Scope Definition: Identify in-scope infrastructure (Nova VMs, Neutron VPCs, Ceph pools, Kubernetes CAPI, DBaaS) across mandatory Security plus Availability, Confidentiality, Processing Integrity, and Privacy.
- Continuous Gap Assessment: Run automated scans (
okustera-audit) to detect missing security policies, unsegmented network routes, or unencrypted assets. - Remediate Gaps & Implement Controls: Enforce WAN firewalls, 0600 secret permissions, Barbican KMS LUKS encryption, and TLS 1.3 ingress.
- Automated Audit Simulation (Mock Audit): Conduct automated pre-audit dry runs via
okustera-auditand the Backoffice Compliance Inspector Hub (POST /api/v1/inspector/compliance/run). - Audit Execution & Continuous Compliance: Undergo formal assessment, receive the CPA auditor report, and maintain continuous posture monitoring through Loki, Prometheus, and Sentinel telemetry.
8. Cloud Compliance Fast-Track Methodology (Assessment, Guardrails & Continuous Remediation)β
Adhering to modern cloud compliance best practices (as articulated in Wiz Cloud Compliance Fast-Track Guide), Okustera structures cloud compliance across a 3-step implementation blueprint and 4 operational disciplines:
3-Step Fast-Track Implementation Blueprintβ
- Step 1: Baseline Posture Assessment & Gap Analysis:
- Rather than guessing security readiness, Okustera runs automated discovery across compute instances (Nova), software-defined networks (Neutron), storage pools (Ceph), and DBaaS clusters via
okustera-audit. - Generates a prioritized gap analysis highlighting regulatory risk (e.g., exposed WAN ports, loose file permissions, unencrypted storage pools).
- Rather than guessing security readiness, Okustera runs automated discovery across compute instances (Nova), software-defined networks (Neutron), storage pools (Ceph), and DBaaS clusters via
- Step 2: Scoped Framework-to-Workload Mapping:
- Compliance is scoped to actual business workloads to prevent over-engineering. Workloads handling cardholder data map strictly to PCI DSS, EU citizen records map to GDPR Chapter V in-country residency, critical infrastructure operators map to EU NIS2, and general enterprise cloud tenants map to SOC 2 Type II and ISO 27001.
- Step 3: Declarative Technical Guardrails (vs. Bureaucratic Gates):
- Traditional compliance creates manual "review gates" that delay software deployments. Okustera instead enforces automated declarative guardrails:
- Pre-configured Terraform validation ensuring every Cinder volume has LUKS encryption enabled (
encrypted = true). - Automated 0600 file permission enforcement on configuration secrets.
- Ephemeral Kubernetes Pod IAM tokens replacing long-lived static API credentials.
- Pre-configured Terraform validation ensuring every Cinder volume has LUKS encryption enabled (
- Traditional compliance creates manual "review gates" that delay software deployments. Okustera instead enforces automated declarative guardrails:
4 Essential Disciplines for Sustained Cloud Complianceβ
- 1. Continuous Compliance Mindset (vs. Pre-Audit Panic):
- Eliminates the traditional 6-month pre-audit scramble. Compliance evidence is continuously streamed to Grafana Loki and Prometheus, allowing audit teams to generate compliance reports on demand.
- 2. Living Identity Hygiene & Least Privilege:
- Because leaked and over-privileged credentials account for ~65% of cloud security incidents, Okustera enforces living IAM hygiene: scoped Keystone application credentials, mandatory TOTP 2FA, short session TTLs, and automated token revocation.
- 3. Automated Remediation for Configuration Drift:
- The gap between detecting a vulnerability and fixing it is minimized through automated self-healing runbooks (
omc_wan_firewall.sh,restore_cluster_after_reboot.sh,omc_doctor.sh).
- The gap between detecting a vulnerability and fixing it is minimized through automated self-healing runbooks (
- 4. Operationalizing Engineering Ownership:
- Compliance alerts and inspector findings route directly to the platform engineers and workload owners who provisioned the resources, preventing security team bottlenecks.
Solving the Modern Compliance Frontiers: AI & Data Sovereigntyβ
- The AI Compliance Blind Spot: Modern AI workloads introduce untrusted data pipelines. Okustera enforces SafeTensors weight validation (blocking pickle-based RCE) and isolates vector embeddings within tenant-dedicated Barbican KMS encryption boundaries, aligning with the EU AI Act.
- Data Sovereignty Pinning: 100% within-border physical bare-metal residency eliminates foreign surveillance warrants (US CLOUD Act/FISA 702).
The compliance scores, automated checks, and pass/fail statuses reported by the Compliance Inspector (okustera-audit CLI and Backoffice Inspector Hub) are internal automated technical checks designed for continuous posture tracking, automated gap assessments, and pre-audit readiness.
Important: These automated checks do not constitute a 100% valid, certified, or legally binding attestation from an external certified audit company (e.g., an accredited CPA firm, ISO registrar, or certified legal counsel). A formal SOC 2 Type II attestation, ISO/IEC certification, or legally verified GDPR audit requires an independent third-party examination by an accredited audit body evaluating operational and organizational controls over a sustained observation period (typically 6β12 months).
9. Compliance Frameworks & Authoritative Sourcesβ
The technical controls, verification heuristics, and audit procedures implemented in Okustera derive from authoritative compliance standards, official guidelines, and industry frameworks:
Machine-Readable Compliance Source Metadataβ
compliance: soc 2
sources:
- https://www.onetrust.com/blog/soc-2-compliance/
- https://www.splunk.com/en_us/blog/learn/soc-2-compliance-checklist.html
compliance: gdpr
sources:
- https://gdpr.eu/checklist/
- https://gdpr.eu/what-is-gdpr/
- https://gdpr.eu/data-processing-agreement/
- https://gdpr.eu/privacy-notice/
- https://gdpr.eu/right-to-erasure-request-form/
compliance: cloud-security-standards
sources:
- https://www.wiz.io/academy/compliance/cloud-security-standards
compliance: cloud-compliance-fast-track
sources:
- https://www.wiz.io/academy/compliance/cloud-compliance-fast-track-guide
Declarative Single-Line Annotationsβ
compliance: soc 2, sources: https://www.onetrust.com/blog/soc-2-compliance/, https://www.splunk.com/en_us/blog/learn/soc-2-compliance-checklist.htmlcompliance: gdpr, sources: https://gdpr.eu/checklist/, https://gdpr.eu/privacy-notice/, https://gdpr.eu/right-to-erasure-request-form/compliance: cloud-security-standards, sources: https://www.wiz.io/academy/compliance/cloud-security-standardscompliance: cloud-compliance-fast-track, sources: https://www.wiz.io/academy/compliance/cloud-compliance-fast-track-guide
Authoritative Standards & Source Mappingβ
| Standard / Framework | Scope & Technical Safeguards | Metadata & Sources | Verification Mechanism |
|---|---|---|---|
| AICPA SOC 2 Type II | Trust Services Criteria (Security CC, Availability A1, Confidentiality C1, Processing Integrity PI1, Privacy P1) | β’ compliance: soc 2 β’ sources: https://www.onetrust.com/blog/soc-2-compliance/ , https://www.splunk.com/en_us/blog/learn/soc-2-compliance-checklist.html | Automated WAN firewall checks, Sentinel anomaly telemetry, recovery runbooks, and TLS 1.3 verification |
| GDPR (Regulation EU 2016/679) | General Data Protection Regulation (Lawful Basis, Data Security, RoPA/DPIA, Breach Notification within 72h, DPA, Data Subject Rights & Crypto-Shredding) | β’ compliance: gdpr β’ sources: https://gdpr.eu/checklist/ , https://gdpr.eu/what-is-gdpr/ , https://gdpr.eu/data-processing-agreement/ , https://gdpr.eu/privacy-notice/ , https://gdpr.eu/right-to-erasure-request-form/ | In-country sovereign boundary verification, Barbican crypto-shredding (Art. 17), 72h Loki audit streams (Art. 33), and non-proprietary API export (Art. 20) |
| Cloud Security Standards & Frameworks | Shared Responsibility Model (ISO 27017), Automated Posture Management (CSPM), CIS Benchmarks, NIST SP 800-144/53 | β’ compliance: cloud-security-standards β’ sources: https://www.wiz.io/academy/compliance/cloud-security-standards | Continuous automated compliance scoring via Compliance Inspector (okustera-audit), KVM hypervisor isolation, and zero-trust IAM |
| Cloud Compliance Fast-Track | Continuous Compliance Lifecycle, Guardrails vs Gates, Living IAM Hygiene, Automated Drift Remediation | β’ compliance: cloud-compliance-fast-track β’ sources: https://www.wiz.io/academy/compliance/cloud-compliance-fast-track-guide | Automated discovery scans, Terraform guardrails, 0600 secret permissions, and self-healing runbooks |
| ISO/IEC 27001 / 27017 / 27018 | Information Security Management System (ISMS), Cloud Security Controls, Cloud PII Protection | β’ compliance: iso-standards β’ sources: https://www.iso.org/standard/27001 , https://www.iso.org/standard/27017 , https://www.iso.org/standard/27018 | Keystone RBAC, OVN network isolation namespaces, Barbican LUKS disk encryption, and gVisor sandboxing |
| ISO/IEC 22301:2019 | Business Continuity Management Systems (BCMS) & Disaster Recovery Drills | β’ compliance: iso-22301 β’ sources: https://www.iso.org/standard/75106.html | MariaDB Galera multi-master clustering, Ceph 3x replication, CloudNativePG sub-10s failover, and automated synthetic restore drills |
| EU NIS2 Directive (2022/2555) | Cybersecurity Risk Management, Supply Chain SBOM, 24h Early Warning & 72h Incident Reporting | β’ compliance: eu-nis2 β’ sources: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32022L2555 | Container image SBOM scanning, SafeTensors model verification, TOTP MFA, and immutable Loki log auditing |