-
Notifications
You must be signed in to change notification settings - Fork 23
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Ability to reproduce any observation #301
Labels
enhancement
New feature or request
Comments
Is there other metadata that we need to include in the observation other information that is pertinent for reproducible result. |
Should we consider the use of a separate file for storing the data collected? |
brandtkeller
modified the milestones:
OSCAL Reporting data,
v0.2.0 Release,
OSCAL Artifact Generation
Apr 2, 2024
6 tasks
6 tasks
6 tasks
This issue has been decomposed into the aforementioned issues. Closing this issue as complete. |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Intent
For the Lula validation process - we have access to the validations (proofs) of what is measured and the policy it must adhere to - this can be linked and/or transient across OSCAL as the project defines.
The missing piece for historical assessment data is to have the collected data present in the
Assessment-Results
such that anyone performing an audit of what was assessed would have the ability to "replay" a given point-in-time observation.I believe this creates a layer of trust where auditing can be a function of reviewing both the validation inputs, data applied against the inputs, and the policy decision that was made to influence the finding state.
Potential Considerations
assessment-result
in some way.Sub-issues
Since this is a decent chunk of work, the following issues have been created to close out this issue:
The text was updated successfully, but these errors were encountered: