Skip to content

NIST OSCAL

OSCAL (Open Security Controls Assessment Language) is a set of formats published by NIST that represent security controls and related information in machine-readable form. The goal is to automate security and privacy risk management across the supply chain.

OSCAL defines a layered model: - Control layer - Catalog and Profile documents - Implementation layer - System Security Plan (SSP) and Component Definition - Assessment layer - Assessment Plan, Assessment Results, and POA&M - Mapping layer - Cross-framework control mappings

Version modeled in this repository: 1.2.1

Key references: - Specification: https://pages.nist.gov/OSCAL/ - GitHub: https://github.com/usnistgov/OSCAL - JSON Schema source files: http://csrc.nist.gov/ns/oscal/1.2.1/