TL;DR: ISC2 Congress 2025 showed security teams moving from manual policy writing to policy as code, continuous assurance, and encoded governance for AI and machine identities, with Cerbos reporting that the winning pattern is versionable, testable, and auditable enforcement across the stack. The real shift is not documentation style but control design, because static review cycles cannot govern dynamic access, agent behavior, or rapidly changing compliance demands.
Editorial analysis by NHI Mgmt Group, based on content published by Cerbos: “What ISC2 congress 2025 made clear about modern compliance”.
Key questions
Q: How should security teams implement policy as code in compliance programmes?
A: Start by encoding the highest-risk access and governance rules as versioned policy, then connect those policies to deployment, testing, and audit evidence.
Q: Why does policy as code matter for AI governance and machine identities?
A: Because AI-driven systems and machine identities act at runtime, governance has to define their allowed behaviour before they operate.
Q: What breaks when compliance still depends on manual attestations?
A: Evidence becomes stale, control ownership becomes ambiguous, and access decisions drift away from the policy that was supposed to govern them.
Practitioner guidance
- Encode access rules as deployable policy Replace static approval documents with policy definitions that can be versioned, tested, and deployed alongside application changes.
- Shift evidence collection to runtime controls Automate evidence capture from policy decisions, access logs, and enforcement points so compliance no longer depends on manual attestations.
- Govern AI and machine identities with explicit rules Define the allowed actions for machine identities, agents, and model-driven workflows in code before those systems are allowed to operate.
Bottom line: Policy as code turns governance into an enforceable system rather than a paper exercise, which is why it is gaining ground in compliance programmes.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Policy as code is becoming the operational form of compliance. The article reflects a broader shift away from manual attestations toward controls that can be tested, deployed, and observed like software. That matters because assurance only scales when the control itself produces evidence. Practitioners should treat policy execution as part of the security architecture, not as a separate governance layer.
A question worth separating out:
Q: How do policy-based access control and just-in-time access fit together?
A: They work together when policy determines whether access can be granted and JIT limits how long that access exists. The useful distinction is that policy decides eligibility, while JIT reduces standing exposure. Used together, they narrow privilege without relying on permanent entitlements.
👉 Read our full editorial: Policy as code is becoming the new compliance playbook