Skip to content

Support for Gemara (GRC Engineering Model for Automated Risk Assessment) Framework #127

@jpower432

Description

@jpower432

Summary

This feature proposes adding support for the Simplified Compliance Infrastructure (rename pending) framework as a supported compliance framework.

Rationale

Integrating SCI would enable users who utilize this framework to seamlessly leverage C2P for policy generation and result consumption within their ecosystem.

Use Cases

  • The oscal-compass organization is being evaluated against the OSPS baseline which is expressed in SCI. Adding this framework give us an opportunity to use C2P to aid in the evaluation.

Completion Criteria

  • A prototype or POC is likely required to complete this issue to get community feedback
  • Upon acceptance, create new commands results2sci and sci2policy (pending rename)
  • Add or adopt functionality to convert SCI Layer 4 to OSCAL Assessment Layer to use with oscal2posture

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or requestnew-frameworkAdd a new compliance frameworkv2Relates to Go module v2

    Projects

    Status

    Needs Triage

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions