Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Provide a way to tailor a framework (profile) #676

Open
eric-intuitem opened this issue Jul 21, 2024 · 0 comments
Open

Provide a way to tailor a framework (profile) #676

eric-intuitem opened this issue Jul 21, 2024 · 0 comments

Comments

@eric-intuitem
Copy link
Collaborator

Problem statement

A framework needs often to be tailored, to determine a profile applicable to the entity.
This can be done by customising a library "offline", but it would make sense to use the differential approach of OSCAL to generate a profile based on an existing framework directly in the tool.

Expected behavior

  • In the governance section, there is a Profile section to create profiles based on existing frameworks and custom reference controls.
  • It is possible to retain existing controls from the source framework(s) without modification.
  • It is possible to retain an existing control with a modification of the description (substitutions of strings).
  • it is possible to add custom reference controls.

Additional context

This will facilitate the support for OSCAL, which is a mid-term goal for CISO Assistant.

@eric-intuitem eric-intuitem added question Further information is requested new feature and removed question Further information is requested labels Jul 21, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

1 participant