What is Open Security Controls Assessment Language (OSCAL)?
mainOSCAL is a set of hierarchical, XML-, JSON-, and YAML-based formats developed by NIST to provide standardized representations of information regarding the publication, implementation, and assessment of security controls.
The formats are designed to be minimal and generic enough to capture broad control specifications while allowing for ad-hoc tuning and extensions to support specific industry standards or new control types.
Key resources for developers:
- Schema Reference: XML and JSON schemas can be found at the OSCAL schema reference.
- Examples: Practical usage examples are available at OSCAL resources.