Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Consider using OSCAL or OpenCRE to advertise control/requirements mapping #114

Open
SecurityCRob opened this issue Dec 17, 2024 · 7 comments
Assignees
Labels
enhancement New feature or request question Further information is requested

Comments

@SecurityCRob
Copy link
Contributor

There are a few groups seeking to express security requirements/controls/criteria in a machine-readable format. At some point we should talk about possibly using:
OSCAL

@SecurityCRob SecurityCRob added enhancement New feature or request question Further information is requested labels Dec 17, 2024
@xee5ch
Copy link

xee5ch commented Dec 18, 2024

Hello, founding member of the OSCAL Club, a.k.a Self-Appointed Treehouse Manager. 👋 I am happy to advise or pitch in on the OSCAL front. Let me know how I can be of service.

@JonZeolla
Copy link

Also happy to contribute here - I'm focused on automating compliance/assurance and have been working on similar things in the CNCF for the past few years

@eddie-knight
Copy link
Contributor

What would be a good next step to producing the OSCAL catalog? Is there any way we could automate the conversion from baseline.yaml?

@xee5ch
Copy link

xee5ch commented Dec 21, 2024

Do you want the YAML to be canonical? Ironically OSCAL supports a data format for encoding. So you could have both or even just one.

I think what's important to hammer out first is how a catalog gets used (in the OSCAL sense): will people use controls and write against them in a description of "a system" in a system security plan (what that is can be many things; I'll leave that own for now)? To assess a project teams and code to report how they did? Both? I only ask because reviewing the controls and repo it isn't 100% clear yet.

@SecurityCRob
Copy link
Contributor Author

the group discussed today and agreed to explore OSCAL and OpenCRE after we finish merging this recent batch of PRs to firm up missing criteria.

@brandtkeller
Copy link

Also interested in getting involved here. Given the current golang utilization I can assist in proposing what some of this work with OSCAL could look like from a functional perspective.

@eddie-knight
Copy link
Contributor

eddie-knight commented Jan 8, 2025

Thanks @brandtkeller! I'd be happy to review or help with that proposal.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request question Further information is requested
Projects
None yet
Development

No branches or pull requests

5 participants