00:00:00:00 - 00:00:01:18 Hi. My name is Pirooz Javan. 00:00:01:18 - 00:00:05:03 I have given, at least other the talks on one of these workshops. 00:00:05:10 - 00:00:06:23 I’m the CTO of Easy Dynamics. 00:00:06:23 - 00:00:10:04 As Michaela mentioned, we've been working with OSCAL for several years, 00:00:10:14 - 00:00:13:08 and we also help drive a number of community 00:00:13:08 - 00:00:16:08 initiatives, one of them being the OSCAL.io website. 00:00:16:12 - 00:00:19:11 I don't know if any of you have had a chance to take a look at it, 00:00:19:11 - 00:00:20:13 and what's available there. 00:00:20:13 - 00:00:24:03 But we are rapidly building capabilities and releasing them there. 00:00:24:03 - 00:00:27:10 And I want to get an opportunity to kind of, inform some of the group here today. 00:00:27:10 - 00:00:29:21 What's available there to take a look at. 00:00:29:21 - 00:00:31:01 there's one capability 00:00:31:01 - 00:00:35:12 there it’s an OSCAL Viewer, OSCAL Viewer supports not any OSCAL Json. 00:00:35:12 - 00:00:37:04 It does not support the mapping model. 00:00:37:04 - 00:00:40:03 We are looking at adding support for the mapping model, 00:00:40:03 - 00:00:43:14 but a couple of capabilities with the viewer is, it's 00:00:43:14 - 00:00:47:13 got the ability to represent some tailoring in profiles. 00:00:47:13 - 00:00:50:11 It also has and supports some of the import chain, which we'll go 00:00:50:11 - 00:00:54:01 over and evidence attaching and showing how that may work. 00:00:54:01 - 00:00:56:17 Today, I'm also going to kind of showcase an example. 00:00:56:17 - 00:00:59:23 You'll see the FSEA, I don't know exactly what it stands for. 00:00:59:23 - 00:01:05:00 It's a fictitious government organization, federal something administration. 00:01:05:02 - 00:01:06:19 But, I've created a few examples. 00:01:06:19 - 00:01:10:19 The examples kind of break and expand on the pattern library 00:01:10:19 - 00:01:12:23 that we started in the OSCAL Foundation. 00:01:12:23 - 00:01:14:17 So I'm planning on taking these examples 00:01:14:17 - 00:01:17:17 and posting them back there for everybody to have access to. 00:01:18:01 - 00:01:22:03 The viewer also in OSCAL.io, in addition to the viewer, 00:01:22:03 - 00:01:24:00 we also have a registry. 00:01:24:00 - 00:01:26:17 And the registry supports the seven models. 00:01:26:17 - 00:01:30:24 It's where you can upload information, and then get an API access. 00:01:31:03 - 00:01:34:16 The registry is just, a storage repository for OSCAL files. 00:01:34:17 - 00:01:35:23 Nothing fancy over there. 00:01:35:23 - 00:01:38:09 And I'll give you some overview of what's available there. 00:01:38:09 - 00:01:42:17 But that's one of the areas we're using to create content resources 00:01:42:17 - 00:01:46:16 and save content resources that we need for dependencies for other files. 00:01:47:17 - 00:01:50:12 As we start to look, I'm going to jump into 00:01:50:12 - 00:01:53:20 a demo: Federal Space Exploration Administration. 00:01:53:20 - 00:01:57:12 And, when we're thinking about a demo, it's good for us to kind of set up 00:01:57:14 - 00:01:59:07 what the contracts are. 00:01:59:07 - 00:02:03:17 So the main information system here is our Orion mission platform, 00:02:03:17 - 00:02:08:24 that has an ATO boundary with a mission portal and a partner API. 00:02:09:04 - 00:02:10:20 And that system 00:02:10:20 - 00:02:14:24 takes advantage of other systems from a leveraged authorization standpoint. 00:02:15:01 - 00:02:18:08 So we're going to show some of that and what that may mean and you see here 00:02:18:08 - 00:02:22:03 that it’s got 4 leverages, 4 leverage authorizations at the bottom. 00:02:22:05 - 00:02:25:17 And, when we think about, a typical deployment in a federal agency, 00:02:25:17 - 00:02:31:16 and I ask as you're looking at this, try not to criticize the actual data 00:02:31:16 - 00:02:34:23 and kind of like what we've decided to put into some of this content. 00:02:35:02 - 00:02:38:15 This is more around the connectivity and the tissue of how to build 00:02:38:15 - 00:02:42:18 initial data architecture patterns and how that would look like in OSCAL. 00:02:42:18 - 00:02:46:19 I know many of us have seen a lot of examples of catalogs and profiles, 00:02:46:19 - 00:02:49:19 but it gets very limited quickly as we start to go down the models. 00:02:49:21 - 00:02:53:12 SSPs, AP, so we're going to, go over some of that today. 00:02:53:15 - 00:02:58:04 So, there's four environments an AWS, FedRAMP high environment. 00:02:58:04 - 00:03:02:15 We also have two identity systems, one for workforce identity, 00:03:02:15 - 00:03:05:24 such as privilege access management, control plane to the system. 00:03:05:24 - 00:03:08:00 It has some governance services. 00:03:08:00 - 00:03:11:06 And then we also have an external citizen because it's a mission portal, 00:03:11:06 - 00:03:14:23 and you have folks that can authenticate in, we have an Auth0, 00:03:14:23 - 00:03:17:24 service there, and it’s provided through a capability as well. 00:03:17:24 - 00:03:20:16 And then lastly, every information system 00:03:20:16 - 00:03:23:21 we manage has some kind of SoC integration that it requires. 00:03:23:21 - 00:03:28:08 So there's also a SoC, leverage system that we're taking advantage of as well. 00:03:28:08 - 00:03:30:17 And I'm going to say I've put a lot of these files together 00:03:30:17 - 00:03:33:22 last night, made some changes to the viewer to support these. 00:03:33:22 - 00:03:35:24 And, we may have some hiccups along the way. 00:03:35:24 - 00:03:38:03 I'll do my best to kind of get through those. 00:03:38:03 - 00:03:41:00 But the point of the viewer and the registry, 00:03:41:00 - 00:03:43:05 at least a viewer, the viewer is open source. 00:03:43:05 - 00:03:46:10 And while I'm going through, some of these capabilities, 00:03:46:10 - 00:03:49:16 we made a decision, a while ago to, like, 00:03:49:16 - 00:03:52:22 when we run open source projects, we treat them as highly governed. 00:03:52:22 - 00:03:55:07 It's not to say that the viewer is not highly governed. 00:03:55:07 - 00:03:57:18 It is an AI first project. 00:03:57:18 - 00:03:58:20 So we are going to be, 00:03:58:20 - 00:04:03:05 a little liberal at the onset of allowing contributions from folks. 00:04:03:05 - 00:04:06:22 I got somebody contact me today and say that they're working and about 00:04:06:22 - 00:04:11:03 to put in a pull request to introduce a lot of test components into the viewer. 00:04:11:03 - 00:04:11:23 Which is great. 00:04:11:23 - 00:04:15:04 You know, I ask anybody that wants to contribute, take a look at it. 00:04:15:04 - 00:04:19:01 If you see shortcomings, our goal with the viewer is to provide 00:04:19:01 - 00:04:22:20 viewing capabilities but provide a lot of capabilities around first tier constructs. 00:04:23:03 - 00:04:26:04 In the viewer. Not custom made-customized views around prompts. 00:04:26:11 - 00:04:30:02 So, coming back to the Orion mission, within the mission again, 00:04:30:02 - 00:04:32:09 there's a mission portal and a constellation, 00:04:32:09 - 00:04:35:23 and there are four leveraged ATOs available. 00:04:35:23 - 00:04:38:23 So I'm going to drop out of this Okay. 00:04:39:05 - 00:04:41:08 This is called the OSCAL.io website. 00:04:41:08 - 00:04:43:21 As you see here, there's a content registry. 00:04:43:21 - 00:04:45:10 And we do have a link to tools. 00:04:45:10 - 00:04:48:14 We've kind of expanded some of the tools that are available over here. 00:04:48:20 - 00:04:52:00 So take a look and see what's available. 00:04:52:00 - 00:04:55:19 And if you have a tool and like for us to add it, just email us 00:04:55:19 - 00:04:57:08 and we will take a look at it. 00:04:57:08 - 00:05:00:13 For addition, if we look at the content registry, 00:05:00:13 - 00:05:03:15 the content registry supports the seven models. 00:05:03:15 - 00:05:05:01 It's got a sign in button. 00:05:05:01 - 00:05:07:13 You can browse all files and see how many docs are here, 00:05:07:13 - 00:05:12:02 and you kind of see 33, 26, as I said, you we start to go down the path. 00:05:12:04 - 00:05:13:05 There's less examples. 00:05:13:05 - 00:05:16:09 And we're working on creating some of the examples, to upload in here. 00:05:16:09 - 00:05:17:21 And we're going to see some of those. 00:05:17:21 - 00:05:19:02 Choose to sign in. 00:05:19:02 - 00:05:21:08 You can sign in with your Google account. 00:05:23:19 - 00:05:26:23 And when you sign in, you will not see this admin tab, 00:05:26:23 - 00:05:30:14 but you will see your profile and my documents. 00:05:30:19 - 00:05:34:07 The my documents gives you ability to kind of add and manage, 00:05:34:07 - 00:05:36:16 and we'll see something here called public. 00:05:36:16 - 00:05:41:06 We've added a capability, our goal with the registry was really to promote, 00:05:41:06 - 00:05:45:17 good high quality examples, use cases of how folks are tackling OSCAL. 00:05:45:21 - 00:05:47:17 We wanted to make everything free to provide 00:05:47:17 - 00:05:52:05 transparency to folks around use cases and how folks are using OSCAL. 00:05:52:05 - 00:05:55:12 But we recognize that sometimes you just may not want to have something public. 00:05:55:12 - 00:05:58:19 So when you upload something, there's about ten document limitation. 00:05:58:19 - 00:06:02:03 But if you click on this it switches it to private. 00:06:02:03 - 00:06:02:18 And as you're 00:06:02:18 - 00:06:06:24 looking at the visibility of private, it won't be listed on public registry. 00:06:07:02 - 00:06:09:21 And I'll go over why somebody may want to do that. 00:06:09:21 - 00:06:13:23 You can download the Json, view the Json directly here. 00:06:14:05 - 00:06:15:24 And then we have API reference. 00:06:15:24 - 00:06:19:00 And there's a nice API that you can hit against it. 00:06:19:00 - 00:06:23:13 Now that there is an ability to kind of authenticate and, log in 00:06:23:13 - 00:06:27:08 if you, secure a document, under your settings, you have the ability 00:06:27:08 - 00:06:31:12 to change your display name and handle, but there's also an API token. 00:06:31:12 - 00:06:35:01 I'm not going to click Get token, but that's where you get the token. 00:06:35:01 - 00:06:38:18 And you can replay that in your API calls. 00:06:38:20 - 00:06:39:13 Should you wish. 00:06:40:20 - 00:06:43:00 So coming back into, again, 00:06:43:00 - 00:06:46:09 just a repository of OSCAL files we see here. 00:06:46:09 - 00:06:50:10 Just if I'm browsing 83 total documents and what files are across, 00:06:50:10 - 00:06:53:14 each of the models, when we look at a file, 00:06:54:14 - 00:06:59:24 and we have this open in viewer, it will open the file in the OSCAL viewer. 00:06:59:24 - 00:07:04:14 And, what it does is it passes a query string 00:07:04:14 - 00:07:08:00 and we have cores and able to trust that URL. 00:07:08:02 - 00:07:11:04 when it loads, it also has the ability to kind of 00:07:11:05 - 00:07:14:15 take a look at some of the dependencies and load those as well. 00:07:14:15 - 00:07:19:13 So as long as those dependencies are publicly available, they load no problem. 00:07:19:13 - 00:07:25:17 So a great example of that is something called this this CISA SCuBA assessment results. 00:07:25:17 - 00:07:27:12 So this is an assessment result, 00:07:27:12 - 00:07:30:23 of an automated assessment against a Microsoft 365 tenant. 00:07:30:23 - 00:07:34:02 And have the result, but we don't really know anything else about, 00:07:34:07 - 00:07:38:02 information system that was scanned, what profile was used? 00:07:38:02 - 00:07:42:15 And if I open this in the viewer, I'll notice that we have a resolver 00:07:42:15 - 00:07:46:09 and that resolver goes out and resolves that document. 00:07:46:09 - 00:07:47:13 So long as they're linked 00:07:47:13 - 00:07:51:06 correctly, and pulls those documents into the viewer as well. 00:07:51:08 - 00:07:55:05 So in this situation and pulled three documents from the registry 00:07:55:07 - 00:08:00:01 and the actual 800-53 from its source in GitHub. 00:08:00:01 - 00:08:04:09 I will see here in the assessment results, I get to, view the, 00:08:04:22 - 00:08:09:06 first tenant assemblies, the viewer right now is just a starting point. 00:08:09:14 - 00:08:13:12 And what excites me about OSCAL is I see more and more, data examples. 00:08:13:12 - 00:08:15:24 It just creates a lot of opportunity for us to continue 00:08:15:24 - 00:08:19:02 to bring some of that richness of that data into the viewer. 00:08:19:02 - 00:08:21:23 As you look up here, you'll see that the assessment results is 00:08:21:23 - 00:08:25:01 loaded, assessment plan is loaded, SSP is loaded. 00:08:25:01 - 00:08:28:01 No component definitions, profile and catalog. 00:08:28:01 - 00:08:32:02 If I click to the assessment plan, I see that there's one task. 00:08:32:02 - 00:08:36:07 And that task is broken down into various assessments. 00:08:36:10 - 00:08:41:05 Assess Microsoft, enter ID and this is an implementation 00:08:41:05 - 00:08:46:01 of a hardening guide that was published by CISA for Bod 2501 00:08:46:04 - 00:08:50:19 and we, used OSCAL to demonstrate the flexibility and conversion 00:08:50:19 - 00:08:56:02 of hardening guides into assessment plans, which is a pattern that we're adopting. 00:08:56:02 - 00:09:00:13 And as you look at each of the steps that are taken, you see standard 00:09:00:13 - 00:09:04:23 and strict preset, we have MITRE attacks and whatever the links are available 00:09:05:02 - 00:09:09:05 and the controls that are offered by, this task and the steps 00:09:09:05 - 00:09:12:19 that are underneath. So all of these are pulled directly from CISA. 00:09:12:19 - 00:09:14:10 And demonstrated here. 00:09:14:10 - 00:09:18:11 And you can see that there's a system security plan and it may have, 00:09:18:11 - 00:09:21:15 entry ID here, as a system. 00:09:22:00 - 00:09:23:16 And you can see the components 00:09:23:16 - 00:09:26:09 and the control implementations This is a representative. 00:09:26:09 - 00:09:27:06 It's not full. 00:09:27:06 - 00:09:30:23 And the profile that it produced which was a NIST 800-53 00:09:30:23 - 00:09:32:05 moderate in the catalog. 00:09:32:05 - 00:09:33:22 So I'm going to close out of that. 00:09:34:05 - 00:09:37:01 And the purpose of that was to really show you 00:09:37:01 - 00:09:41:20 an example of the dependency and the links that can be pulled in to the viewer. 00:09:41:20 - 00:09:46:05 And what I'd like to do now is show you a couple other examples. 00:09:46:13 - 00:09:50:05 So for the Orion profile, what I'm going to do is I'm going 00:09:50:05 - 00:09:53:02 to actually link the profile first 00:09:53:02 - 00:09:56:14 for the system, since this is a federal agency example 00:09:56:18 - 00:09:59:24 and the profile that we've added, these are all going to be added 00:09:59:24 - 00:10:01:20 to the registry as well. 00:10:01:20 - 00:10:03:18 So feel free to take a look at them there. 00:10:03:18 - 00:10:07:10 We'll see that there's 561 controls, 19 control families, 00:10:07:12 - 00:10:10:03 parameter constraints and altered controls. 00:10:10:03 - 00:10:14:03 then we see how many operations were added and how many operations were removed 00:10:14:03 - 00:10:15:09 from the profile. 00:10:15:09 - 00:10:20:00 as we navigate the profile, if there are tailoring, you'll see an M 00:10:20:05 - 00:10:24:06 that displays and, you know, you just like you can look at any controls 00:10:24:06 - 00:10:25:15 and see what's, what's there. 00:10:25:15 - 00:10:29:08 If I look at a, modified profile, we get to see, 00:10:29:11 - 00:10:36:00 what's been added, what's been removed, and this example that we took actually 00:10:36:00 - 00:10:40:22 takes advantage of information that US Department of Education provides online. 00:10:40:22 - 00:10:42:13 We use this as an example. 00:10:42:13 - 00:10:45:21 And as you kind of look into their access control policy, you see that 00:10:45:21 - 00:10:48:21 this document has a lot more information in it. 00:10:48:22 - 00:10:52:14 Then typically, you would find and that's kind of what was represented 00:10:52:14 - 00:10:55:04 here as one of the, examples that we used to see. 00:10:55:04 - 00:10:59:15 But nice little way to view your profile tailoring, within the tool. 00:10:59:19 - 00:11:05:02 So now that we have the profile, I'm going to go ahead and drop in my Orion SSP. 00:11:05:02 - 00:11:07:06 I had some capabilities working earlier 00:11:07:06 - 00:11:10:11 that I'll refresh on the viewer after this, if you guys have worked 00:11:10:11 - 00:11:13:19 enough with AI, you know that it can get a little bit, squishy. 00:11:13:19 - 00:11:15:23 We're working on areas to protect that. 00:11:15:23 - 00:11:19:07 What I wanted to show here is that, under system 00:11:19:07 - 00:11:22:11 characteristics, we have the Orion mission platform. 00:11:22:13 - 00:11:26:24 within that platform, what we also have is, 00:11:27:03 - 00:11:32:22 authorization boundary diagrams, network diagrams and data flow diagrams. 00:11:32:22 - 00:11:38:09 So we've added capabilities to the viewer such that when you add back matter 00:11:38:09 - 00:11:43:15 resources that include base64 for draw.io 00:11:43:15 - 00:11:47:17 and mermaid diagrams, the tool does support initial. 00:11:47:17 - 00:11:49:20 The MVP was put in yesterday on that. 00:11:49:20 - 00:11:52:07 So it allows you to kind of take a look at a diagram 00:11:52:07 - 00:11:55:02 see some of the constructs of the Orion mission platform. 00:11:55:02 - 00:11:58:11 We see the Apollo mission portal, some of the constellation, 00:11:58:11 - 00:12:01:18 some of the ways it integrates with some of the leverage systems. 00:12:01:20 - 00:12:04:20 And you can see here hosted on leveraged ATO, 00:12:04:20 - 00:12:07:19 AWS, FedRAMP, and we see a SoC over here. 00:12:07:19 - 00:12:12:04 So some of the diagrams that are there, I did have a authorization 00:12:12:04 - 00:12:15:07 boundary diagram, which does not look like it's loading. 00:12:15:07 - 00:12:16:22 I have to take a look at that. 00:12:16:22 - 00:12:20:24 could see some of the network diagrams that may be of use, 00:12:21:03 - 00:12:24:17 but this is how you basically add the diagrams and the data flow diagram. 00:12:24:19 - 00:12:28:03 So let's look at components that make up the system. 00:12:28:12 - 00:12:31:01 I see a number of components. We have the Orion. 00:12:31:01 - 00:12:34:04 This system I can take a look at each component 00:12:34:04 - 00:12:37:12 and see what controls are being offered by that component. 00:12:37:16 - 00:12:39:01 Take a look at the users. 00:12:39:01 - 00:12:42:00 In this situation, inventory items I didn't focus much on that 00:12:42:00 - 00:12:45:00 in terms of the data sample, but it does support inventory items. 00:12:45:04 - 00:12:47:04 And we see here that we have one system. 00:12:47:04 - 00:12:50:02 And, we have some leverage authorizations. 00:12:50:02 - 00:12:53:09 And what we can do now is load in 00:12:53:09 - 00:12:57:17 SSP or drag in SSP in here for leverage authorization. 00:12:57:17 - 00:13:02:01 Now, if you think about this, our goal will be to drop, an Orion. 00:13:02:01 - 00:13:06:12 And if Orion leverages an authorization that is resolvable through the, 00:13:06:12 - 00:13:10:11 content registry or through GitHub, it would automatically load. 00:13:10:13 - 00:13:12:22 In this case, I have not made them resolvable. 00:13:12:22 - 00:13:14:17 So I'll just go ahead and drop in, 00:13:14:17 - 00:13:18:17 which create some funky logic in terms of what controls are offered. 00:13:18:20 - 00:13:20:18 Now. Brian saw this yesterday. 00:13:20:18 - 00:13:22:07 I was demoing him. Destiny. 00:13:22:07 - 00:13:25:07 do have the capability where all these controls will expand 00:13:25:10 - 00:13:28:10 and show you the controls overlaid between the leverage. 00:13:28:10 - 00:13:31:12 I had to remove that capability because it was causing some issues. 00:13:31:14 - 00:13:34:14 But if I, go to the Amazon Web Service 00:13:34:20 - 00:13:38:19 see here that there's controls offered and what's provided 00:13:38:23 - 00:13:41:24 out of the service and what the responsibilities are. 00:13:41:24 - 00:13:44:24 So when we think about a customer responsibility matrix, 00:13:45:02 - 00:13:49:21 we use in terms of the models and the system security plan. 00:13:50:08 - 00:13:53:04 If you take a look at, control implementation. 00:13:53:04 - 00:13:57:11 So imagine you're on the AWS, system and the SSP, 00:13:57:14 - 00:14:00:18 and if you take a look at export, you have the ability to export 00:14:00:18 - 00:14:04:05 provided services and responsibilities. 00:14:04:05 - 00:14:08:09 And this is how we are engineering and designing the customer responsibilities. 00:14:08:13 - 00:14:10:23 And it's working very well for us. 00:14:10:23 - 00:14:15:00 As you take a look at some of the controls you'll see that the icons change. 00:14:15:00 - 00:14:16:17 And it's basically saying, hey, 00:14:16:17 - 00:14:21:10 I have control level implementations, but I'm also inheriting some, implementations 00:14:21:10 - 00:14:25:13 and we get to see the provided exports for AC2 in this situation. 00:14:25:13 - 00:14:28:12 I'm getting some things, from Amazon Web Service 00:14:28:12 - 00:14:32:17 and I'm seeing all the provided services Amazon's providing. 00:14:32:17 - 00:14:34:13 According to this control. 00:14:34:13 - 00:14:37:07 And we'll see that pattern continuously. 00:14:37:07 - 00:14:40:12 So let's say I go into enterprise ICAM program. 00:14:40:12 - 00:14:43:14 And then I drag in the enterprise ICAM program, 00:14:43:14 - 00:14:46:18 and I see that there's AC and IA controls. 00:14:46:18 - 00:14:51:24 So now when I go to, AC you'll see that there's FedRAMP, Amazon, controls provided 00:14:51:24 - 00:14:56:14 or I can see what is provided directly from the ICAM program, 00:14:56:14 - 00:15:00:18 which I'm getting my privilege access users, as I go to leverage authorizations. 00:15:00:18 - 00:15:03:13 And it looks like the Orion system. 00:15:03:13 - 00:15:05:14 I must have dragged the wrong file here. 00:15:05:14 - 00:15:06:14 I need to see that. 00:15:06:14 - 00:15:09:02 So, Orion system, is here. 00:15:09:02 - 00:15:11:10 This should not be here, but the Amazon Web 00:15:11:10 - 00:15:14:12 service is a leveraged service, and so is a Gemini. 00:15:14:12 - 00:15:16:03 Enterprise ICAM program. 00:15:16:03 - 00:15:18:02 Let’s see if I can remove that. 00:15:18:02 - 00:15:21:04 Gemini does not seem to be loaded. 00:15:21:04 - 00:15:22:07 I'll have to take a look at that. 00:15:22:07 - 00:15:25:02 As I said, I was putting in some of these capabilities last night. 00:15:25:02 - 00:15:28:10 We're excited for them because it gives you a real ability 00:15:28:10 - 00:15:30:23 to start kind of testing some of your data examples. 00:15:30:23 - 00:15:34:24 I don't think I mentioned this at the OSCAL our viewer is 100% client side. 00:15:34:24 - 00:15:38:00 So, while I can go out and grab documents to resolve, 00:15:38:00 - 00:15:42:00 it does not make any data calls back to any system to save anything. 00:15:42:02 - 00:15:44:10 It's all client side, rendering. 00:15:44:10 - 00:15:48:13 That said, that gives you an idea of the leverage services. 00:15:48:13 - 00:15:50:09 We also added this attachment. 00:15:50:09 - 00:15:54:19 So if a, specific control level implementation 00:15:54:19 - 00:15:58:09 has a attachment in the back matter such as, let's say, 00:15:58:14 - 00:16:03:09 platform continuous monitoring plan, and we include that as a base 64. 00:16:03:11 - 00:16:05:11 In this case it's a markdown. 00:16:05:11 - 00:16:09:14 It shows the information and allows you to see the files that are attached. 00:16:09:14 - 00:16:10:14 This allows you to put 00:16:10:14 - 00:16:14:09 contingency plans or whatever you want directly into your artifacts, 00:16:14:09 - 00:16:17:11 and attach them as base64 in the resources, 00:16:17:11 - 00:16:19:21 and then link them to the control implementations. 00:16:19:21 - 00:16:22:21 And the viewer will show that there's attachments, available 00:16:22:22 - 00:16:24:06 for particular controls in there. 00:16:24:06 - 00:16:28:11 I'm going to reset this, and start fresh and show 00:16:28:11 - 00:16:31:20 you just another, set of capabilities that we're also working on. 00:16:31:23 - 00:16:33:11 As I mentioned earlier. 00:16:33:11 - 00:16:35:19 We looked at the CISA SCuBA assessment results. 00:16:35:19 - 00:16:38:23 When I go back to assessment plans, on the registry, 00:16:38:23 - 00:16:40:14 you'll see a few examples here. 00:16:40:14 - 00:16:45:08 And we are, socializing this and working at least with one vendor right now. 00:16:45:08 - 00:16:48:16 On hardening guides, conversion to, 00:16:48:16 - 00:16:51:18 assessment plans for automated assessment against those hardening guides. 00:16:51:18 - 00:16:55:12 We have examples for CISA SCuBA which we've also showing examples 00:16:55:12 - 00:16:57:03 for CIS benchmarks. 00:16:57:03 - 00:17:00:03 Here's one for PostgreSQL and here's one for ubuntu. 00:17:00:06 - 00:17:03:14 And we see there's not really many files here for Stig's 00:17:03:17 - 00:17:05:18 we are creating that and I'll add those in. 00:17:05:18 - 00:17:09:18 I wanted to show you, what a stig assessment plan would look like. 00:17:09:21 - 00:17:13:18 let's say, a rel is what happens when the resolver, 00:17:13:18 - 00:17:17:18 there's a placeholder there for the SSP, because these are more templates. 00:17:17:20 - 00:17:21:07 Not really like traditional APs because we don't have a target system. 00:17:21:09 - 00:17:25:06 This is how we are designing the ability to kind of execute category 00:17:25:06 - 00:17:26:18 one, high severity. 00:17:26:18 - 00:17:32:16 And, today we break each of those into a audit check and then a remediation. 00:17:32:16 - 00:17:34:16 We are working to the OSCAL foundation 00:17:34:16 - 00:17:40:01 and looking to make this remediation a more first assembly, within the AP. 00:17:40:01 - 00:17:44:14 But you can see, it checks and how to remediate, in certain cases. 00:17:44:14 - 00:17:49:11 So, and all of this is pulling directly from the stig’s XCCDF, formats, 00:17:49:11 - 00:17:54:19 and we pull them in directly into APs, which gives us opportunity to use, OSCAL 00:17:54:19 - 00:17:57:04 assessment plans to conduct automated assessments 00:17:57:04 - 00:18:00:21 and therefore capture the results as OSCAL assessment results. 00:18:00:21 - 00:18:02:05 So we have a number of these. 00:18:02:05 - 00:18:04:23 I can show you another one for Windows. 00:18:04:23 - 00:18:08:11 We'll be publishing these, today on OSCAL registry. 00:18:08:13 - 00:18:12:18 And this goes to our intent behind the OSCAL.io website, 00:18:12:18 - 00:18:16:12 which is really about, advocating for interoperability, less 00:18:16:12 - 00:18:21:22 focus on props for unique, organizational use cases and more focused on 00:18:22:01 - 00:18:26:19 when we start to see rich, rich data inOSCAL, how may a tool represent that? 00:18:26:19 - 00:18:30:16 If my goal is to really achieve a high degree of interoperability across 00:18:30:16 - 00:18:34:16 tools, that gives you a overview of OSCAL.io website. 00:18:34:18 - 00:18:36:15 I hope, you, liked what you saw. 00:18:36:15 - 00:18:38:04 If you have any questions, Mikayla, 00:18:38:04 - 00:18:40:22 I guess we can stop the recording and go into conversation. 00:18:40:22 - 00:18:44:19 I do want to put something on the record as an explanation, 00:18:44:21 - 00:18:46:12 because we're referring here 00:18:46:12 - 00:18:50:07 to registries, and those are OSCAL content registries. 00:18:50:07 - 00:18:51:15 There is a need. 00:18:51:15 - 00:18:56:02 And we discussed that in the past and with OSCAL Foundation for a registry 00:18:56:02 - 00:18:59:05 that supports the extensions, the OSCAL extensions 00:18:59:07 - 00:19:04:07 is there, plan this registry that you presented to expand 00:19:04:07 - 00:19:08:05 to support also the OSCAL extensions or not. 00:19:08:05 - 00:19:12:04 And if you want to elaborate on the difference between the two, please, 00:19:12:24 - 00:19:16:02 or the audience to have it when it comes to extensions, 00:19:16:02 - 00:19:20:11 I think any time we're looking at implementing something, having good 00:19:20:19 - 00:19:24:04 examples of how folks want to use some of the extensions, 00:19:24:04 - 00:19:26:18 I know we got quite a bit, coming out of IBM. 00:19:26:18 - 00:19:29:18 We've talked internally around what an extensions, 00:19:29:21 - 00:19:31:05 registry would look like. 00:19:31:05 - 00:19:34:15 I know OSCAL Foundation has a high degree of interest of implementing it. 00:19:34:22 - 00:19:38:14 suppose as we start to see more use cases or props being used. 00:19:38:17 - 00:19:40:06 And that would get prioritized. 00:19:40:06 - 00:19:44:00 But right now, our focus at least, from a OSCAL.io perspective, 00:19:44:04 - 00:19:48:14 is really focusing on the nonprops and, improving interoperability. 00:19:48:17 - 00:19:50:03 we're not doing it on accident. 00:19:50:03 - 00:19:53:08 We're seeing a lot of examples of files that we drop them in tools 00:19:53:08 - 00:19:56:23 and, the usage of the first class assemblies has variants, and we're trying 00:19:56:23 - 00:19:59:23 to promote some level of uniformity through the site. 00:20:00:14 - 00:20:01:03 Thank you. 00:20:01:03 - 00:20:05:00 So I wanted to clarify that there is a distinction between the 00:20:05:05 - 00:20:09:06 content registry, the one that you presented and the registry 00:20:09:06 - 00:20:14:00 that we've been discussing in this circle with the community that would support, 00:20:14:04 - 00:20:17:04 OSCAL extensions under different namespaces. 00:20:17:23 - 00:20:20:22 With that, I'm going to stop the recording so we can open the 00:20:20:22 - 00:20:22:07 floor for conversation.