You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
This issue outline the proposal to add support for OSCAL Assessment Plan and track implementation.
Related to #5
Proposed Implementation
Below outlines the creation of an Assessment Task and associated Activities from OSCAL Components and RuleSet property information.
Components can be added through the imported OSCAL SSP or in the local definitions. The Assessment Task would provide an aggregated view of all Rule related Assessment Activities.
Each activity corresponds to a RuleSet defined in properties in the OSCAL System Component. It also include the related controls defined in the Control Implementation properties.
Assessment Results are created by C2P and policy artifact generation is created from Component Definitions. The below issue proposes that artifact generation is guided by an ingested Assessment Plan. oscal-compass/compliance-to-policy-go#43
The text was updated successfully, but these errors were encountered:
jpower432
changed the title
Add OSCAL Assessment Plan Support
Document OSCAL Assessment Plan Support
Mar 10, 2025
Summary
This issue outline the proposal to add support for OSCAL Assessment Plan and track implementation.
Related to #5
Proposed Implementation
Below outlines the creation of an Assessment Task and associated Activities from OSCAL Components and RuleSet property information.
Components can be added through the imported OSCAL SSP or in the local definitions. The Assessment Task would provide an aggregated view of all Rule related Assessment Activities.
Each activity corresponds to a RuleSet defined in properties in the OSCAL System Component. It also include the related controls defined in the Control Implementation properties.
The use of Associated Activities can provide linkage the Task and Assessment Subject (the component in this case).
Example output
Relevant Issues
oscal-compass/oscal-sdk-go#32
oscal-compass/oscal-sdk-go#34
oscal-compass/oscal-sdk-go#33
Relevant Work
oscal-compass/oscal-sdk-go#36 - Merged
oscal-compass/oscal-sdk-go#45
oscal-compass/oscal-sdk-go#48
Use Cases
Assessment Results are created by C2P and policy artifact generation is created from Component Definitions. The below issue proposes that artifact generation is guided by an ingested Assessment Plan.
oscal-compass/compliance-to-policy-go#43
The text was updated successfully, but these errors were encountered: