usnistgov / OSCAL

Open Security Controls Assessment Language (OSCAL)
https://pages.nist.gov/OSCAL/
Other
674 stars 183 forks source link

Render a framework in a human-readable format #51

Open kscarfone opened 7 years ago

kscarfone commented 7 years ago

As a compliance auditor, I can see a framework in a human-readable format.

Required Resources:

Goals:

  1. Create the necessary files (CSS, XSLT, etc.) to convert a machine-readable OSCAL framework into a human-readable format.
  2. Test the conversion process using the selected framework.

Acceptance Criteria:

  1. Validate that the necessary conversion files have been created as defined in Goal 1.
  2. Validate that the conversion successfully generates the framework in a clear, human-readable format without conversion errors, omissions, etc.
aj-stein-nist commented 1 year ago

Having reviewed this, the original project requirement can possibly be reframed as: "how do build a presentation layer of OSCAL machine-readable data for a framework (such as CSF, SP 800-53, PCI-DSS) for human use. I do feel that is a worthwhile avenue of research, albeit large, to consider how the catalog of security controls, system descriptions, and assessments are presented, perhaps not in a linear format like paper document. Given this interpretation, and follow-on from the team, I would consider it good for discovery work.

aj-stein-nist commented 1 year ago

Given the questions around core requirements for this issue and existing comments and labels, I will align the status with "DEFINE Research Needed."