Skip to content

OSPS-SA-01: Document Security Self Assessment #95

Description

@jpower432

Objectives

Document OSCAL Compass Security Self Assessment and populate the link information in each repo level security-insights.yml

Resources

Guide on Self Assessment from CNCF STAG

There is an existing SELF_ASSESSMENT.md file that can be used for collaboration, but this can also be documented in another platform or location for easier real-time collaboration before moving into the markdown.

Guidance on each section from the original CNCF template is preserved in Markdown comments and are included in each sub task for the relevant section.

Some sections may be relevant to the OSCAL Compass project as a whole and others like Actors and Actions may require breaking down by sub-project to fully capture of the security considerations for the reader.

Core components that should be considered in scope include:
compliance-trestle and associated repos (including Agile Authoring)
compliance-to-policy and associated repos

Completion Criteria

  • Completion of Sub-Issues
  • Document link the security insights file of each in scope repository.

Activity

  1. converted this from a draft issue on Mar 21, 2025
  2. changed the title [-]Document Security Self Assessment[/-] [+]OSPS-SA-01: Document Security Self Assessment[/+] on Mar 24, 2025
  3. added theissue type on Mar 27, 2025
  4. jpower432 commented on Jun 12, 2025

    @jpower432
    MemberAuthor
  5. moved this to In Progress in Slam Backlogon Jun 17, 2025
  6. self-assigned this
    on Jul 7, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

Type

Projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions