/blossom-case-study

A case study for ACSAC 2022 utilizing OSCAL with a custom GitHub action to automate assessments.

Primary LanguageHTMLOtherNOASSERTION

Case Study: Shifting Left the Right Way with OSCAL

This repository was created to demonstrate an automated assessment workflow using GitHub Actions. It utilizes a minimal application to trace a single control through the OSCAL models.

Detailed information about the use and structure of this repository can be found in the docs/ folder.

Through this project, we intend to help take the first steps with OSCAL and integrate these concepts into a development project. This will facilitate security, privacy and compliance activities as a part of an application development project from the start.

Contacts:

oscal@nist.gov

National Institute of Standards and Technology

Information Technology Lab, Computer Security Division

More Information