usnistgov / oscal-xproc3

OSCAL (Open Security Controls Assessment Language) on an XProc3 platform
Other
4 stars 2 forks source link

Examples of SSPs with constraints #6

Open wendellpiez opened 2 weeks ago

wendellpiez commented 2 weeks ago

Committer Notes

The PR contains test files useful for tracing effectiveness of constraints validation.

See https://github.com/usnistgov/OSCAL/pull/2024 for related PR in OSCAL.

But these files are not intended to test or validate this issue specifically, but rather to augment the test set with real examples.

More work on such augmentation is probably called for.

All Submissions:

Changes to Core Features:

wendellpiez commented 2 weeks ago

@iMichaela can we discuss this PR? It is intended to capture work for future (re)use, but its files could probably be masked or obfuscated (etc.) and be just as useful.

That is, there are a couple of data governance policy questions to be discussed, with possible changes made, before merging.

Since this repository is devoted to OSCAL, it doesn't seem amiss to use it for the purpose of assembling use cases for validation.

(And follow-on work could deploy an OSCAL Inspector XSLT to test the same constraints.)