信息格式标准-OSCAL

OSCAL

The Open Security Controls Assessment Language (OSCAL)arrow-up-right is a project led by the National Institute of Standards and Technology (NIST)arrow-up-right that allows security professionals to express control-related information in machine-readable formats. Expressing compliance information in this way allows security practitioners to use automated tools to support data analysis, while making it easier to address downstream requirements such as translation and accessibility. In the United States, Amazon Web Services (AWS)arrow-up-right has collaborated closely with NIST and the FedRAMParrow-up-right program to advance the adoption of OSCAL, and was the first cloud service provider to submit a FedRAMP system security plan (SSP) in OSCAL formatarrow-up-right in 2022.

最后更新于