Git Product home page Git Product logo

ism-oscal's Introduction

ISM OSCAL

A mirror of ISM OSCAL documents. The authoritative source can be found at https://www.cyber.gov.au/ism/oscal. The Australian Signals Directorate (ASD) provides the Information Security Manual (ISM) in the Open Security Controls Assessment Language (OSCAL), a standardised machine-readable format developed by the United States’ National Institute of Standards and Technology (NIST). ISM OSCAL enables enhanced machine-supported consumption possibilities that can be incorporated into organisations’ governance, risk and compliance (GRC) processes and tooling. For example, improved tooling could include programmatic ingestion of ISM releases into internal systems for tracking in line with organisations’ GRC processes. NIST publishes several OSCAL learning resources to help organisations understand the concepts behind OSCAL and its use.

The ISM is provided as an OSCAL catalog with the use of OSCAL props for unique ISM attributes. ASD also provides illustrative OSCAL profiles and OSCAL resolved profile catalogs for each ISM control’s applicability (ALL, OFFICIAL: Sensitive, PROTECTED, SECRET, TOP SECRET), as well as for Essential Eight Maturity Level One (ML1), Maturity Level Two (ML2) and Maturity Level Three (ML3). Importantly, to enable greater flexibility for consumers, and to align with the ISM’s non-machine-readable documents, the information used to inform these profiles are also included in the source ISM catalog.

ASD welcomes feedback regarding ISM OSCAL. If you would like to provide any feedback or insights about your usage, or have enquiries regarding ISM OSCAL, please complete the ISM Feedback Form. Feedback pertaining to the broader use of OSCAL (including the OSCAL specification) should be directed to the OSCAL community or NIST’s OSCAL team.

ism-oscal's People

Contributors

acscuser4 avatar

Stargazers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

Watchers

 avatar  avatar  avatar  avatar  avatar  avatar

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.