Compliance assessment and simulation system
Systems and methods include reception of a first request to check code associated with a first service for compliance with one or more criteria, determination of a plurality of code components associated with the first service, execution of a code check of each of the plurality of code components, generation of a first service compliance statement associated with the first service based on results of the executed code checks, determination of a definition of the first product from a product repository, the definition listing a plurality of services on which the product depends, the plurality of services including the first service, identification of a compliance statement associated with each of the plurality services, and determination of a product compliance statement based on each of the identified compliance statements.
1. A system comprising:
a code check system comprising:
a first memory storing first processor-executable program code; and
a first at least one processing unit to execute the first processor-executable program code to cause the system to:
receive a first request to check code associated with a first service for compliance with one or more criteria; and
in response to the first request:
determine a plurality of code components associated with the first service;
execute a code check of each of the plurality of code components;
generate a first service compliance statement associated with the first service based on results of the executed code checks; and
transmit a second request to check compliance of a first product associated with the first service; and
a policy engine system comprising:
a second memory storing second processor-executable program code; and
a second at least one processing unit to execute the second processor-executable program code to cause the system to:
receive the second request; and
in response to the second request, read a definition of the first product, the definition listing a plurality of services on which the product depends, the plurality of services including the first service;
execute compliance rules to assess compliance of the first product;
identify a plurality of compliance statements, each of the plurality of compliance statements associated with a respective one of each of the plurality services; and
determine a product compliance statement based on the assessed compliance of the first product, the first service compliance statement and the plurality of identified compliance statements,
wherein in response to a determination that deployment of first product instances and a plurality of services instances according to a deployment configuration would not violate compliance demands of each customer associated with the of the first product instances, the first product instances and the plurality of services instances are deployed according to the deployment configuration.
2. A system according to claim 1 , wherein the code check comprises a check for Federal Information Processing Standards (FIPS) compliance and for General Data Protection Regulation (GDPR) compliance.
3. A system according to claim 1 , the second at least one processing unit to execute the second processor-executable program code to cause the system to:
receive a third request to check compliance of deployment of the first product; and
in response to the third request:
determine the deployment configuration for the first product instances and the plurality of services instances;
determine the compliance demands of each customer associated with the first product instances; and
determine, based on the compliance statements associated with each of the plurality services and the product compliance statement, whether deployment of the first product instances and the plurality of services instances according to the deployment configuration would violate the compliance demands.
4. A system according to claim 3 , further comprising:
a deployment system comprising:
a third memory storing third processor-executable program code; and
a third at least one processing unit to execute the third processor-executable program code to cause the system to:
transmit the third request;
wherein the deployment system deploys the first product instances and the plurality of services instances according to the deployment configuration.
5. A system according to claim 4 , the second at least one processing unit to execute the second processor-executable program code to cause the system to:
receive a fourth request to check compliance of onboarding a first customer to a deployed first product instance; and
in response to the fourth request:
determine the deployment configuration of the first product instance;
determine a second product compliance statement associated with the first product and the deployment configuration of the first product instance;
determine compliance demands of the first customer; and
determine, based on the second product compliance statement, whether onboarding of the first customer would violate the compliance demands of the first customer.
6. A system according to claim 1 , the second at least one processing unit to execute the second processor-executable program code to cause the system to:
receive a third request to check compliance of onboarding a first customer to a deployed first product instance; and
in response to the fourth request:
determine a deployment configuration of the first product instance;
determine a second product compliance statement associated with the first product and the deployment configuration of the first product instance;
determine compliance demands of the first customer; and
determine, based on the second product compliance statement, whether onboarding of the first customer would violate the compliance demands of the first customer.
7. A method comprising:
receiving a first request to check code associated with a first service for compliance with one or more criteria;
determining a plurality of code components associated with the first service;
executing a code check of each of the plurality of code components;
generating a first service compliance statement associated with the first service based on results of the executed code checks;
identifying, from a product repository, a first product which depends on the first service and a plurality of services on which the first product depends, the plurality of services including the first service;
executing compliance rules to assess compliance of the first product;
identifying a plurality of compliance statements, each of the plurality of compliance statements associated with a respective one of each of the plurality services;
determining a product compliance statement based on the assessed compliance of the first product, the first service compliance statement and the plurality of identified compliance statements;
determining that deployment of first product instances and a plurality of services instances according to a deployment configuration would not violate compliance demands of each customer associated with the first product instances; and
in response to determining that deployment of the first product instances and the plurality of services instances according to the deployment configuration would not violate compliance demands of each customer associated with the first product instances, deploying the first product instances and the plurality of services instances according to the deployment configuration.
8. A method according to claim 7 , wherein the code check comprises a check for Federal Information Processing Standards (FIPS) compliance and for General Data Protection Regulation (GDPR) compliance.
9. A method according to claim 7 , further comprising:
determining the deployment configuration for the first product instances and the plurality of services instances;
determining the compliance demands of each customer associated with the first product instances; and
determining, based on the compliance statements associated with each of the plurality services and the product compliance statement, whether deployment of the first product instances and the plurality of services instances according to the deployment configuration would violate the compliance demands.
10. A method according to claim 8 , further comprising:
receiving a second request to check compliance of onboarding a first customer to a deployed first product instance; and
in response to the second request:
determining the deployment configuration of the first product instance;
determining a second product compliance statement associated with the first product and the deployment configuration of the first product instance;
determining compliance demands of the first customer; and
determining, based on the second product compliance statement, whether onboarding of the first customer would violate the compliance demands of the first customer.
11. A method according to claim 7 , further comprising:
receiving a second request to check compliance of onboarding a first customer to a deployed first product instance; and
in response to the second request:
determining the deployment configuration of the instance of the first product;
determining a second product compliance statement associated with the first product and the deployment configuration of the instance of the first product;
determining compliance demands of the first customer; and
determining, based on the second product compliance statement, whether onboarding of the first customer would violate the compliance demands of the first customer.
12. A non-transitory computer-readable medium storing processor-executable program code, the program code executable by a computing system to:
receive a first request to check code associated with a first service for compliance with one or more criteria;
determine a plurality of code components associated with the first service;
execute a code check of each of the plurality of code components;
generate a first service compliance statement associated with the first service based on results of the executed code checks;
identify, from a product repository, a first product which depends on the first service and a plurality of services on which the first product depends, the plurality of services including the first service;
execute compliance rules to assess compliance of the first product;
identify a plurality of compliance statements, each of the plurality of compliance statements associated with a respective one of each of the plurality services;
determine a product compliance statement based the assessed compliance of the first product, the first service compliance statement and of the plurality of identified compliance statements;
determine that deployment of first product instances and a plurality of services instances according to a deployment configuration would not violate compliance demands of each customer associated with the first product instances; and
in response to the determination that deployment of first product instances and a plurality of services instances according to a deployment configuration would not violate compliance demands of each customer associated with the first product instances, deploy the first product instances and the plurality of services instances according to the deployment configuration.
13. A non-transitory medium according to claim 12 , wherein the code check comprises a check for Federal Information Processing Standards (FIPS) compliance and for General Data Protection Regulation (GDPR) compliance.
14. A non-transitory medium according to claim 12 , the program code executable by a computing system to:
determine the deployment configuration for the first product instances and the plurality of services instances;
determine the compliance demands of each customer associated with the first product instances; and
determine, based on the compliance statements associated with each of the plurality services and the product compliance statement, whether deployment of the first product instances and the plurality of services instances according to the deployment configuration would violate the compliance demands.
15. A non-transitory medium according to claim 14 , the program code executable by a computing system to:
receive a second request to check compliance of onboarding a first customer to a deployed first product instance; and
in response to the second request:
determine the deployment configuration of the first product instance;
determine a second product compliance statement associated with the first product and the deployment configuration of the first product instance;
determine compliance demands of the first customer; and
determine, based on the second product compliance statement, whether onboarding of the first customer would violate the compliance demands of the first customer.
16. A non-transitory medium according to claim 12 , the program code executable by a computing system to:
receive a second request to check compliance of onboarding a first customer to a deployed first product instance; and
in response to the second request:
determine the deployment configuration of the first product instance;
determine a second product compliance statement associated with the first product and the deployment configuration of the first product instance;
determine compliance demands of the first customer; and
determine, based on the second product compliance statement, whether onboarding of the first customer would violate the compliance demands of the first customer.