You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
A framework needs often to be tailored, to determine a profile applicable to the entity.
This can be done by customising a library "offline", but it would make sense to use the differential approach of OSCAL to generate a profile based on an existing framework directly in the tool.
Expected behavior
In the governance section, there is a Profile section to create profiles based on existing frameworks and custom reference controls.
It is possible to retain existing controls from the source framework(s) without modification.
It is possible to retain an existing control with a modification of the description (substitutions of strings).
it is possible to add custom reference controls.
Additional context
This will facilitate the support for OSCAL, which is a mid-term goal for CISO Assistant.
The text was updated successfully, but these errors were encountered:
Problem statement
A framework needs often to be tailored, to determine a profile applicable to the entity.
This can be done by customising a library "offline", but it would make sense to use the differential approach of OSCAL to generate a profile based on an existing framework directly in the tool.
Expected behavior
Additional context
This will facilitate the support for OSCAL, which is a mid-term goal for CISO Assistant.
The text was updated successfully, but these errors were encountered: