usnistgov / OSCAL

Open Security Controls Assessment Language (OSCAL)
https://pages.nist.gov/OSCAL/
Other
667 stars 181 forks source link

System Inventory Use Cases and Examples #903

Open ohsh6o opened 3 years ago

ohsh6o commented 3 years ago

User Story:

As an OSCAL developer and SSP author, I would like examples and clearer guidance on how to model different kinds of system inventories.

Goals:

As discussed in last week's model meeting, there is a large variety in information systems. NIST OSCAL guidance in the design of system inventories of a system security plan is limited. For conventional and more unconventional ephemeral workloads, it would be helpful if the following existed in documentation.

Dependencies:

Acceptance Criteria

david-waltermire commented 3 years ago

We can work on this for OSCAL 1.1. This has been discussed before in #590.