Discovery: Controls and Mapping #14
Replies: 6 comments 3 replies
-
|
Beta Was this translation helpful? Give feedback.
-
The general outline of the qualifier tag can be viewed in this issue. The general outline of the provenance tag can be viewed in this issue. For both of these, I produced the rough outline, and we are looking for input/feedback around the terms used, as well as the allowed values. Feedback can be added in the discussion by commenting below. Also, thoughts around what is required and the cardinalities are welcome. This has not been considered yet. Places to find the code:Draft Mapping ModelExisting draft (previously in the develop branch) Staging for all proposed changes (no merges yet, but coming soon) Specific Tags (Work in Progress) |
Beta Was this translation helpful? Give feedback.
-
We've started publishing the draft documentation for prototype models. The documentation for mapping can be found here: https://pages.nist.gov/OSCAL-Reference/models/prototype-mapping-model/ Specific locations:
Please note that element names and allowed values, and constraints are very conceptual and still need definition. Cardinalities and constraints are also not defined at the moment. Input is welcome. |
Beta Was this translation helpful? Give feedback.
-
|
Beta Was this translation helpful? Give feedback.
-
Here is a sample mapping for XYZ set of controls to NIST 800-53 rev4, using the previous develop version of OSCAL. Notice that we've used properties to capture mapping percentages and relationships (controls, procedures, rules). Perhaps there's a better way of doing that? |
Beta Was this translation helpful? Give feedback.
-
Beta Was this translation helpful? Give feedback.
-
This effort is currently under review for initiation here: #18
Spiral 1 has been started.
Beta Was this translation helpful? Give feedback.
All reactions