NIST OSCAL
OSCAL (Open Security Controls Assessment Language) is a set of formats published by NIST that represent security controls and related information in machine-readable form. The goal is to automate security and privacy risk management across the supply chain.
OSCAL defines a layered model: - Control layer - Catalog and Profile documents - Implementation layer - System Security Plan (SSP) and Component Definition - Assessment layer - Assessment Plan, Assessment Results, and POA&M - Mapping layer - Cross-framework control mappings
Version modeled in this repository: 1.2.1
Key references:
- Specification: https://pages.nist.gov/OSCAL/
- GitHub: https://github.com/usnistgov/OSCAL
- JSON Schema source files: http://csrc.nist.gov/ns/oscal/1.2.1/