From Legacy Documentation to OSCAL: An MCP-Based Agent Pipeline for Threat-Informed Continuous Compliance in Critical Infrastructure
AI-agent pipeline converts legacy OT security documentation into machine-readable OSCAL compliance artifacts without active scanning—directly relevant for NIS2 continuous-compliance mandates in critical infrastructure.
Summary written by editorial AI · Source link below
arXiv:2607.08288v1 Announce Type: new Abstract: In critical infrastructure, operational technology environments often cannot be actively scanned, and yet active system feedback is needed for risk assessment and compliance. This paper presents a non-invasive, MCP-grounded multi-agent pipeline that converts natural-language system descriptions into source-verified knowledge graph and audit-ready artifacts in the NIST OSCAL format for continuous automated compliance management. The architecture de
Editorial Analysis
NIS2 demands continuous, auditable compliance evidence from critical infrastructure operators, many of whom still rely on static documents; automated conversion to OSCAL closes that gap.
Pilot an MCP-based agent pipeline on a representative sample of legacy OT security documentation to assess feasibility of OSCAL-format compliance evidence generation.
Automated conversion of legacy security documents to machine-readable compliance format can accelerate NIS2 readiness for critical-infrastructure operators.
Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.
External link — opens at arXiv Crypto & Security in a new tab.
More from the Compliance Desk
- X-rated Compliance Theater: An Empirical Evaluation of European Age Verification Systems in Adult Websites17 Jul
- 23andMe to pay $18 million in new genetics data breach settlement16 Jul
- Designing a GDPR-Compliant Security Architecture for Remote Elderly Care Systems: A Privacy-by-Design Approach16 Jul
- Manage Vendor Risk in a Few Practical Steps14 Jul
- Reverse Engineering Compliance: A Dual-Graph Verification Framework for Auditing Legacy IT Security Concepts10 Jul