<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>OSCAL on Sinetris's viewpoints</title><link>https://sinetris.info/tags/oscal/</link><description>Recent content in OSCAL on Sinetris's viewpoints</description><generator>Sine Die theme for Hugo</generator><language>en</language><webMaster>duilio@sinetris.info (Duilio Ruggiero)</webMaster><lastBuildDate>Mon, 17 Mar 2025 10:45:42 GMT</lastBuildDate><atom:link href="https://sinetris.info/tags/oscal/index.rss.xml" rel="self" type="application/rss+xml"/><item><title>Compliance as Code</title><link>https://sinetris.info/topics/iam/grc/compliance-as-code/</link><pubDate>Mon, 17 Mar 2025 10:45:42 GMT</pubDate><guid>https://sinetris.info/topics/iam/grc/compliance-as-code/</guid><description>&lt;h2 id="standards"&gt;Standards&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;a href="https://scap.nist.gov/" rel="external"&gt;SCAP&lt;/a&gt;: Security Content Automation Protocol&lt;/li&gt;
&lt;li&gt;
&lt;a href="https://pages.nist.gov/OSCAL/" rel="external"&gt;OSCAL&lt;/a&gt;: Open Security Controls Assessment Language&lt;/li&gt;
&lt;li&gt;
&lt;a href="https://www.omg.org/spec/BPMN" rel="external"&gt;BPMN&lt;/a&gt;: Business Process Model and Notation&lt;/li&gt;
&lt;li&gt;
&lt;a href="https://www.omg.org/spec/DMN" rel="external"&gt;DMN&lt;/a&gt;: Decision Model and Notation&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="guidelines"&gt;Guidelines&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;a href="https://complianceascode.readthedocs.io/" rel="external"&gt;ComplianceAsCode&lt;/a&gt;: The ComplianceAsCode project
&lt;blockquote&gt;
&lt;p&gt;Previously known as SCAP Security Guide (SSG)&lt;/p&gt;
&lt;/blockquote&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="tools"&gt;Tools&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;a href="https://www.open-scap.org/" rel="external"&gt;OpenSCAP&lt;/a&gt;: open source security compliance toolkit
&lt;blockquote&gt;
&lt;p&gt;NIST certified for SCAP 1.2&lt;/p&gt;
&lt;/blockquote&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;a href="https://github.com/IBM/compliance-trestle" rel="external"&gt;Trestle&lt;/a&gt;: Manage compliance as code using NIST&amp;rsquo;s OSCAL standard&lt;/li&gt;
&lt;li&gt;
&lt;a href="https://www.openpolicyagent.org/" rel="external"&gt;Open Policy Agent (OPA)&lt;/a&gt;: Declarative Policies
&lt;blockquote&gt;
&lt;p&gt;Context-aware, Expressive, Fast, Portable&lt;/p&gt;
&lt;/blockquote&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;a href="https://github.com/permitio/opal" rel="external"&gt;OPAL&lt;/a&gt;: Open Policy Administration Layer&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="good-reads-and-presentations"&gt;Good reads and presentations&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;a href="https://pages.nist.gov/OSCAL/learn/presentations/mini-workshop/" rel="external"&gt;OSCAL Mini Workshop Series&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</description></item></channel></rss>