Join our Newsletter — 33% off our NHI Course

Policy as code and AI governance: what security teams need now

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 21730
Topic starter  

TL;DR: ISC2 Congress 2025 showed security teams moving from manual policy writing to policy as code, continuous assurance, and encoded governance for AI and machine identities, with Cerbos reporting that the winning pattern is versionable, testable, and auditable enforcement across the stack. The real shift is not documentation style but control design, because static review cycles cannot govern dynamic access, agent behavior, or rapidly changing compliance demands.

Editorial analysis by NHI Mgmt Group, based on content published by Cerbos: “What ISC2 congress 2025 made clear about modern compliance”.

Key questions

Q: How should security teams implement policy as code in compliance programmes?

A: Start by encoding the highest-risk access and governance rules as versioned policy, then connect those policies to deployment, testing, and audit evidence.

Q: Why does policy as code matter for AI governance and machine identities?

A: Because AI-driven systems and machine identities act at runtime, governance has to define their allowed behaviour before they operate.

Q: What breaks when compliance still depends on manual attestations?

A: Evidence becomes stale, control ownership becomes ambiguous, and access decisions drift away from the policy that was supposed to govern them.

Practitioner guidance

  • Encode access rules as deployable policy Replace static approval documents with policy definitions that can be versioned, tested, and deployed alongside application changes.
  • Shift evidence collection to runtime controls Automate evidence capture from policy decisions, access logs, and enforcement points so compliance no longer depends on manual attestations.
  • Govern AI and machine identities with explicit rules Define the allowed actions for machine identities, agents, and model-driven workflows in code before those systems are allowed to operate.

Bottom line: Policy as code turns governance into an enforceable system rather than a paper exercise, which is why it is gaining ground in compliance programmes.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 5 days ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21566
 

Policy as code is becoming the operational form of compliance. The article reflects a broader shift away from manual attestations toward controls that can be tested, deployed, and observed like software. That matters because assurance only scales when the control itself produces evidence. Practitioners should treat policy execution as part of the security architecture, not as a separate governance layer.

A question worth separating out:

Q: How do policy-based access control and just-in-time access fit together?

A: They work together when policy determines whether access can be granted and JIT limits how long that access exists. The useful distinction is that policy decides eligibility, while JIT reduces standing exposure. Used together, they narrow privilege without relying on permanent entitlements.

👉 Read our full editorial: Policy as code is becoming the new compliance playbook


This post was modified 5 days ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.