Compliance-as-Code Validation Architectures for Multi-Cloud GxP Platforms
Keywords:
compliance-as-code, GxP validation, multi-cloud governance, policy-as-code, Infrastructure-as-Code, Zero Trust architectureAbstract
Regulated life-sciences organizations are caught between two systems that were never designed to coexist. Good Practice (GxP) quality frameworks demand a validated state that stays fixed; modern cloud platform engineering is built to change that state continuously, sometimes several times a day. This article argues that the common industry pattern of bolting a compliance-reporting layer onto an already-built Infrastructure-as-Code (IaC) and policy-as-code pipeline cannot validate multi-cloud GxP platforms, because it treats validation evidence as something to be recovered after the fact rather than a property the architecture is designed to produce from the outset. Drawing on operational experience with Cloud Adoption Framework (CAF) landing zones, Terraform-based IaC, Kubernetes cluster engineering, and Azure Policy guardrails, we propose a layered reference architecture in which an enforcement layer, a cross-cloud evidence normalization layer, a validation-artifact generation layer, and an audit and traceability layer are designed concurrently, not sequentially. Evaluation criteria are derived from core GxP validation requirements traceability, attributability, reproducibility, and auditability and the proposed architecture is assessed against them using a practitioner-architecture-evaluation method rather than a controlled experiment. Concurrent design closes gaps that retrofitted reporting layers cannot close by construction, particularly around cross-cloud evidence consistency and installation/operational/performance-qualification (IQ/OQ/PQ) equivalence. GxP cloud governance practice should treat validation-evidence generation as a first-class architectural concern, on par with policy enforcement and infrastructure provisioning; we outline the practical and residual-manual-effort implications of that shift for platform teams operating across multiple cloud providers.
Downloads
References
A. Rahman, R. Mahdavi-Hezaveh, and L. Williams, "A systematic mapping study of infrastructure as code research," Information and Software Technology, vol. 108, pp. 65-77, 2019. https://www.sciencedirect.com/science/article/abs/pii/S0950584918302507
A. Rahman, C. Parnin, and L. Williams, "The Seven Sins: Security Smells in Infrastructure as Code Scripts," in Proc. 41st Int. Conf. Software Engineering (ICSE 2019), pp. 164-175, 2019. https://ieeexplore.ieee.org/document/8812041
S. Rose, O. Borchert, S. Mitchell, and S. Connelly, "Zero Trust Architecture," NIST Special Publication 800-207, National Institute of Standards and Technology, 2020. https://www.paloaltonetworks.com/cyberpedia/what-is-a-zero-trust-architecture
M. M. Mushtaq et al., "A Systematic Literature Review on the Implementation and Challenges of Zero Trust Architecture Across Domains," Sensors, vol. 25, no. 19, art. 6118, 2025. https://www.mdpi.com/1424-8220/25/19/6118
A. Rahman, S. I. Shamim, D. B. Bose, and R. Pandita, "Security Misconfigurations in Open Source Kubernetes Manifests: An Empirical Study," ACM Transactions on Software Engineering and Methodology, vol. 32, no. 4, art. 100, 2023. https://dl.acm.org/doi/10.1145/3579639
I. Koishybayev et al., "Characterizing the Security of GitHub CI Workflows," in Proc. 31st USENIX Security Symposium, pp. 2747-2763, 2022. https://www.usenix.org/conference/usenixsecurity22/presentation/koishybayev
A. Rahman, D. B. Bose, Y. Zhang, and R. Pandita, "An empirical study of task infections in Ansible scripts," Empirical Software Engineering, vol. 29, no. 1, art. 34, 2024. https://akondrahman.github.io/files/papers/emse2024-tidal.pdf
R. Opdebeeck, A. Zerouali, and C. De Roover, "Smelly Variables in Ansible Infrastructure Code: Detection, Prevalence, and Lifetime," in Proc. 19th Int. Conf. Mining Software Repositories (MSR '22), pp. 61-72, 2022. https://ieeexplore.ieee.org/document/9796178
H. Hu, Y. Bu, K. Wong, G. Sood, K. Smiley, and A. Rahman, "Characterizing Static Analysis Alerts for Terraform Manifests: An Experience Report," in 2023 IEEE Secure Development Conf. (SecDev), pp. 7-13, 2023. https://ieeexplore.ieee.org/document/10305615
S. K. Mondal, R. Pan, M. H. D. Kabir, T. Tian, and H.-N. Dai, "Kubernetes in IT administration and serverless computing: An empirical study and research challenges," The Journal of Supercomputing, vol. 78, no. 2, pp. 2937-2987, 2022. https://dl.acm.org/doi/abs/10.1007/s11227-021-03982-3
T. Hirano et al., "Data Validation and Verification Using Blockchain in a Clinical Trial for Breast Cancer: Regulatory Sandbox," Journal of Medical Internet Research, vol. 22, no. 6, e18938, 2020. https://pubmed.ncbi.nlm.nih.gov/32340974/
J. Oakley et al., "Scrybe: A Secure Audit Trail for Clinical Trial Data Fusion," ACM Digital Threats: Research and Practice, vol. 4, no. 2, art. 20, 2023. https://pubmed.ncbi.nlm.nih.gov/37937206/
T. Suhonen and C. Martinez, "Continuous Auditing and Continuous Certification of Cloud Services in MEDINA - Security Auditor's View," Open Research Europe, vol. 3, art. 208, 2023/2024. https://pmc.ncbi.nlm.nih.gov/articles/PMC11196927/
A. Rahman, M. R. Rahman, C. Parnin, and L. Williams, "Security Smells in Ansible and Chef Scripts: A Replication Study," ACM Transactions on Software Engineering and Methodology, vol. 30, no. 1, art. 3, 2021. https://dl.acm.org/doi/10.1145/3408897
A. Rahman and C. Parnin, "Detecting and Characterizing Propagation of Security Weaknesses in Puppet-based Infrastructure Management," IEEE Transactions on Software Engineering, vol. 49, no. 6, pp. 3536-3553, 2023. https://ieeexplore.ieee.org/document/10102545
A. Verdet, M. Hamdaqa, L. Da Silva, and F. Khomh, "Assessing the adoption of security policies by developers in Terraform across different cloud providers," Empirical Software Engineering, vol. 30, no. 3, art. 74, 2025. https://pubmed.ncbi.nlm.nih.gov/40027081/
A. War, A. Diallo, A. Habib, J. Klein, and T. F. Bissyande, "Vulnerabilities in infrastructure as code: what, how many, and who?," Empirical Software Engineering, vol. 30, no. 5, art. 120, 2025. https://link.springer.com/article/10.1007/s10664-025-10672-8
Downloads
Published
How to Cite
Issue
Section
License

This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License.
All papers should be submitted electronically. All submitted manuscripts must be original work that is not under submission at another journal or under consideration for publication in another form, such as a monograph or chapter of a book. Authors of submitted papers are obligated not to submit their paper for publication elsewhere until an editorial decision is rendered on their submission. Further, authors of accepted papers are prohibited from publishing the results in other publications that appear before the paper is published in the Journal unless they receive approval for doing so from the Editor-In-Chief.
IJISAE open access articles are licensed under a Creative Commons Attribution-ShareAlike 4.0 International License. This license lets the audience to give appropriate credit, provide a link to the license, and indicate if changes were made and if they remix, transform, or build upon the material, they must distribute contributions under the same license as the original.


