Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Assessment Models: Timing and Expiration #700

Open
3 tasks
brian-ruf opened this issue Jun 19, 2020 · 2 comments
Open
3 tasks

Assessment Models: Timing and Expiration #700

brian-ruf opened this issue Jun 19, 2020 · 2 comments
Labels
Aged A label for issues older than 2023-01-01 enhancement Research Scope: Modeling Issues targeted at development of OSCAL formats User Story

Comments

@brian-ruf
Copy link
Contributor

User Story:

In an effort to more fully support activities such as continuous assessment, the assessment plan and assessment results models must have the ability to support timing of collection and expiration of results.

The assessment plan model must enable a security practitioner to define a frequency of collection on a per-test basis. It may be necessary to modify the catalog and profile models to support testing frequency as an expansion of the assessment objective/methods modeling.

The assessment plan and assessment results models must also support the ability to assign an expiration date to the results. OSCAL should enable both an implicitly derived expiration date based on the frequency of collection above, and an explicitly defined expiry period. Regardless, individual results must have the ability to reflect the period of time within which the results are valid or trusted.

It is worth noting that the assessment results model already supports time-date stamps on each individual finding. This equates to a date of information collection, and may be used by tools to make decisions as to the "freshness" of the results information in a particular context.

Goals:

  • Define clear OSCAL data requirements for frequency of testing at the individual test level.
  • Define clear OSCAL data requirements for results expiration and/or freshness.
  • Identify the models to update and plan the changes.
  • Implement the changes.

Dependencies:

None.

Acceptance Criteria

  • All OSCAL website and readme documentation affected by the changes in this issue have been updated. Changes to the OSCAL website can be made in the docs/content directory of your branch.
  • A Pull Request (PR) is submitted that fully addresses the goals of this User Story. This issue is referenced in the PR.
  • The CI-CD build process runs without any reported errors on the PR. This can be confirmed by reviewing that all checks have passed in the PR.
@david-waltermire david-waltermire added this to the OSCAL 1.1.0 milestone Oct 30, 2020
@david-waltermire david-waltermire added the Scope: Modeling Issues targeted at development of OSCAL formats label Oct 30, 2020
@david-waltermire
Copy link
Contributor

This issue has received no feedback since its creation. As a result I am pushing this to OSCAL 1.2.

@aj-stein-nist
Copy link
Contributor

Given the questions around core requirements for this issue and existing comments and labels, I will align the status with "DEFINE Research Needed."

(Also I unassigned you off the issue @brian-ruf only because we are trying to make it a habit not to assign issues unless a team member is actively working on it, meaning the status is "In Progress," during the sprint. Thanks for opening and any work that has occurred since)

@aj-stein-nist aj-stein-nist moved this from Todo to DEFINE Research Needed in NIST OSCAL Work Board Sep 26, 2023
@Compton-US Compton-US added the Aged A label for issues older than 2023-01-01 label Nov 2, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Aged A label for issues older than 2023-01-01 enhancement Research Scope: Modeling Issues targeted at development of OSCAL formats User Story
Projects
Status: DEFINE Research Needed
Development

No branches or pull requests

4 participants