About this talk
In this talk, Chandana Mulapuri discusses graph-powered compliance solutions utilizing AI and Neo4j to address the challenges of regulatory mapping in multi-cloud environments. She highlights the inefficiencies of traditional compliance methods, particularly in dynamic cloud infrastructures where workloads are ephemeral. The speaker elaborates on the advantages of using graph databases to model relationships between regulations, controls, assets, and evidence, which provides a more integrated approach to compliance management. Additionally, she explores the integration of OSCAL for standardized security controls and the incorporation of compliance as code within CI/CD pipelines, allowing for proactive compliance validation. The session concludes with insights into leveraging AI for anomaly detection and risk prioritization, emphasizing the importance of a unified compliance framework across diverse cloud platforms.
Full transcript
Hello everyone. This is Chandana Mulapuri. Um, I'm working with IBM as a senior security specialist um, and I'm very glad to present uh, today here in um, Neo4j. So, we are today talking about a graph-powered uh, compliance and how uh, we can build intelligent um, regulatory mapping with AI and Neo4j. So, let's get uh, started. Nowadays um, uh, the compliance uh, in cloud is kind of uh,
where um, we are using multi-cloud tenants and uh, we are having a lot of uh, crisis uh, which is why traditional approaches are failing because um, of the different requirements in the infrastructure. So, uh, the solution for this uh, we've come up is um, a cloud environments a span um, and destroying resources in minutes. So, uh, yet most enterprises still rely on them. So, what we are
doing in our current uh, environment is we are doing annual audit cycles where uh, we we were we were doing an annual audit cycles where it was too slow for dynamic cloud infrastructure where we we were using um, multi-cloud tenants. And we were also doing uh, manual documentation where uh, the resource intensive uh, we we have to use a lot of and we have to have lot
of team members working on manual documentation whenever it is necessary and um, this also is prone to errors and whenever a team member leaves or whenever we had to do some uh, knowledge transfers it is it was very difficult for us and it was always stale. So, um, coming to the reactive posture, compliance gaps disco- are discovered after the fact when whenever we are going through the
audit or whenever we have some um risk that that is brought to us. So, this is the current gap we were facing. And the core problem in the current um industry is where we're using dynamic where the workloads that live only minutes and not months. So, because whenever the let's just say we have a a market production environment that's going live or we have hit a number
of users in particular off a period. So, the workload is only for a couple of hours or a couple of minutes and then it goes down. And it is not for staying forever. So, the regulatory complexities the next one where multiple overlapping frameworks like SOC 2, NIST, ISO, FedRAMP, and GDPR come into place. And the multi-cloud sprawl. So, where controls scatter across AWS, Azure, Google Cloud, IBM
Cloud, etc. So, uh the because of this we have an alert fatigue. We have set up alerts for a lot of things and a large volume of alerts used to come up and the volume of signals which is overwhelming to the security teams and we don't know which is the critical alert and which is which can be um even though we have sev one, sev two, sev
threes because of the volume of the sev ones or sev sev twos we we don't know which is the most critical one So, in this topic uh in this uh presentation, what we'll cover is why for compliance, uh why the shift from tables to relationships, uh why uh graph schema design works, modeling contracts, regulations, um assets, and evidences work. Um AI on the graph, how uh ML
traversal, uh anomaly detection, and requirement extraction uh are done, and OSCAL integration, uh standardization uh formats, enabling framework interoperability, which helps um OSCAL is one of our um major um development. And uh CICD um with multi-cloud, um compliance as a code in real pipelines more than uh compliance as a service. Uh and what uh uh what we can uh also talk about is the AI governance, uh
data sovereignty, and emerging frameworks. So, let's head right into the topics. So, why uh graph for compliance works, right now graph is um fundamentally a relationship problem. A control doesn't exist uh in isolation in maps look to the regulation. So, where uh the regulations play a important role and applies to assets and is validated by evidences, which also relates to other controls and uh which is why
um the relation data base models, uh this is this access a rows and joins, uh like relation data base models. So, graph database models uh it as actually as it concerns the network of dependencies where uh we can um we can do uh graph databases. So, this is uh the graph schema for regulatory mapping, where we uh in the first circle we have regulation which defines the
requirements that maps the controls. The second circle we have a controls where we implement rules and link link them to the assets. And the third set is assets where we host our resources tied to the controls and evidences. And the third fourth set is evidences where we where we prove the control status for gaps and analysis. Designing the schema this way correctly is foundational. Each node type
carries meta metadata framework version, the risk weight, cloud provider, evidence stamp, timestamp and while relationships carry the most important the compliance logic that makes the traversal meaningful. What Neo4j brings to the table here for us is the native graph storage where relationships are first established and first like the first class citizens. No where the mismatch between data model and queries is not is not not no more
an impedance. Cypher query language where expressive readable traversal across deep regulatory hierarchies comes in picture. And the third one is graph data science library. Where built-in machine learning algorithms for ML pattern detection across compliance networks happens and the this brings a lot onto the table. So let's talk about AI on the compliance graph. There are three AI capabilities that I want to talk about here the requirement
extraction where the machine learning algorithms are traversed regulatory knowledge graphs to extract structured requirements from unstructured documentation mapping to machine-readable controls. And anomaly detection is where the graph pattern graph-based pattern recognition identifies the potential control failures by analyzing the deviation patterns across connected compliance networks. And the third is the risk prioritization where graph centrality algorithms surface the highest impact gaps reducing the alert fatigue focusing the teams
on controls which with the most important priority regulatory dependencies. OSCAL. Let's talk about OSCAL. So, the interoperability bridge here which is OSCAL is nothing but the open source security control assessment language which we call as OSCAL here which provides a standardized machine-readable format for representing security controls and assessments. When OSCAL is integrated with Neo4j, OSCAL catalogs the map directly to graph node schemas. Profile overlays become relationship
attributes. And assessment results feed directly into the evidence layer. Multiple multiple frameworks like NIST, FedRAMP, ISO become interoperable nodes in the same graph which is a great asset to the team. So, compliance as a code in the CI/CD. This is another interesting topic we have. So, Um, than compliance coming at the end of uh the development life cycle, like uh after everything is done and uh we
are ready for production, we've integrated compliance as a code in the CICD pipelines itself where uh whenever the code commit happens, uh it triggers the CICD pipeline and the control validation uh happens next uh in the next stage of the pipeline where uh we run rules from uh Neo4j graph. And the third stage would be the policy query where we detect uh violations via graph queries. And
the fourth uh stage uh stage in the CICD would be enforced remediation where we automate the fix or block the deplo- deployment automatically in this via the CICD pipelines. So, control validation uh here requires uh requirements uh encoded within the graph structures are automatically triggered within the CICD pipelines, which is shifting compliance left and catching gaps even before the resources are provisioned uh and not after. So,
uh coming to uh the multi-cloud compliance coverage, uh where a single graph for every cloud, uh this this helps uh the leadership, the teams as well as uh anyone um understand uh better about the compliance across the whole environment. So, graph architecture provides a unified compliance layer across heterogeneous infra- infrastructure. Uh so, each cloud uh provider's resources become nodes and compliance relationships span them transparently. So, if
you see AWS uh got guard duty, config, uh security hub, and if you consider Azure, let's it's defender, policy, and Sentinel. And if you consider GCP, it's SCC Chronicle and policy controller. So all of them become as a unified compliance layer across the infrastructure and we have a single unified graph for all the multi-cloud environments. managing the alert fatigue with graph built prioritization. This has been a
a help for the team because previously we had we used to have a lot of alerts coming in from different cloud environments where um uh where the team was very uh um very overworking on on these alerts uh where it is not very necessary on some of the alerts where even though we configured minimalistically, we had a lot of alerts popping in because of the multi-cloud environments.
So how we manage the alert fatigue with graph prioritization is we we enable graphs centrally where controls in the most downstream dependencies are ranked highest. Fixing one node resolves many of the findings. the second thing we did was establishing relationship rating uh So we use we risk scores for where the risk scores follow through edges regulatory impact uh which propagates across the graph automatically. And the third
one we have uh done enabled is context-aware triage where alerts carry full graph context with which uh regulation, which asset, which evidence is missing so that we have the maximum number of maximum amount of information uh the team needs to have uh to be able to fix uh and apply the patch. So, considering the road ahead, emerging compliance frontiers, AI governance, let's talk about this. So, EU
AI Act and emerging AI regulations require traceability between model behaviors and regulatory obligations as a natural fit uh for graph modeling. Uh if we talk about data sovereignty, cross-border data flow restrictions, model as graph relationships, enable real-time sovereignty violation detection across cloud regions. Um continuous assurance. Um enabling this gives us continuous assurance because as frameworks multiply, graph-powered compliance scales without rebuilding new Become new models, not new
systems, which helps uh the systems um which helps not creating the duplicate systems. Um so, here we've talked spoken about compliance uh a lot. So, the key takeaways of the session would be like compliance is a graph problem uh where relationships uh between controls, regulations, assets, and evidence are the core compliance uh are the core of the compliance model. Uh compliance model them natively. So, AI amplifies
the graph where um machine learning traversal, anomaly detection, and risk prioritization become powerful when applied to connected uh compliance data. The shift left with compliance as a code, uh which embedded uh, control validation into the CICD uh, pipelines to catch gaps before uh, deployment not after the audits. And OS Cal which enables scale scaling. Standardized uh, formats. I love one graph to span multiple frameworks without rebuilding
from scratch. thank you for joining the session. If you have any questions, uh, I'm here to answer.
More from this event
See all 37 talks →
NODES AI 2026 - Agentic GraphRAG: Autonomous Knowledge Graph Construction and Adaptive Retrieval
11:51
NODES AI 2026 - Semiont: A Graph Based, AI Native Wiki and Annotator
29:48
NODES AI 2026 - MemMachine: Agents That Learn, Memory That Lasts
30:03
NODES AI 2026 - Ghost-busting with Neo4j Graph Analytics in Snowflake
28:47