Compliance isn't about creativity. It's about auditability. 📝
"We write the SAF rules to follow the STIG profile 'as written'... You are being held accountable to the profile." @AaronLippold.
Read how @MITREcorp SAF handles automation: https://anchore.com/blog/stig-in-action-4-lessons-on-automating-compliance-with-mitre-saf/