Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Suitability for OSCAL as part of CFI Policy #333

Open
jstclair2019 opened this issue Mar 15, 2023 · 1 comment
Open

Suitability for OSCAL as part of CFI Policy #333

jstclair2019 opened this issue Mar 15, 2023 · 1 comment

Comments

@jstclair2019
Copy link

NIST is developing the Open Security Controls Assessment Language (OSCAL), a set of hierarchical, XML-, JSON-, and YAML-based formats that provide a standardized representations of information pertaining to the publication, implementation, and assessment of security controls. OSCAL is being developed through a collaborative approach with the public. Public contributions to this project are welcome.

With this effort, we are stressing the agile development of a set of minimal formats that are both generic enough to capture the breadth of data in scope (controls specifications), while also capable of ad-hoc tuning and extension to support peculiarities of both (industry or sector) standard and new control types.

The OSCAL website provides an overview of the OSCAL project, including an XML and JSON schema reference, examples, and other resources.
The GitHub repo https://github.com/usnistgov/OSCAL

FOR FINOS/CFI: the NIST’s Cybersecurity Insights blog: “The Foundation for Interoperable and Portable Security Automation is Revealed in NIST’s OSCAL Project” lays out the concepts of security and compliance automation. Should they be considered for FINOS?

@jstclair2019
Copy link
Author

As discussed in the CFI Policy meeting OSCAL would support automation of FFIEC/NIST CSF controls supported by PCI DSS, CIS, and CSA.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant