Open kscarfone opened 7 years ago
Having reviewed this, the original project requirement can possibly be reframed as: "how do build a presentation layer of OSCAL machine-readable data for a framework (such as CSF, SP 800-53, PCI-DSS) for human use. I do feel that is a worthwhile avenue of research, albeit large, to consider how the catalog of security controls, system descriptions, and assessments are presented, perhaps not in a linear format like paper document. Given this interpretation, and follow-on from the team, I would consider it good for discovery work.
Given the questions around core requirements for this issue and existing comments and labels, I will align the status with "DEFINE Research Needed."
As a compliance auditor, I can see a framework in a human-readable format.
Required Resources:
Goals:
Acceptance Criteria: