Skip to content

Should component output be in OSCAL format? #1705

Discussion options

You must be logged in to vote

The OSCAL Assessment Results model is composed of (among other things): observations, risks, and findings. Observations can contain human or machine-generated evidence of compliance or non-compliance.

OSCAL is on the "higher level of abstraction" side, allowing for implementors to collect evidence from a wide variety of tools and processes without prescribing a specific tool output.

For a really simple example of an automated workflow generating Assessment Results documents based off of tool output (in this case, a Python test), check out this case study that our team recently presented on.

Replies: 2 comments 2 replies

Comment options

You must be logged in to vote
1 reply
@ErnestoOrtiz3
Comment options

Comment options

You must be logged in to vote
1 reply
@ErnestoOrtiz3
Comment options

Answer selected by aj-stein-nist
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
faq Frequently asked questions and answers from OSCAL users.
3 participants