Skip to main content

OSCAL External Framework Crosswalk

Generated Evaluation Status

This section is generated from the framework manifest and compatibility report. Do not edit it manually.

  • Framework ID: oscal
  • Manifest: docs/external-frameworks/oscal.json
  • Compatibility report: ./reports/oscal.compatibility.json
  • Evidence class: SOURCE_REVIEWED
  • Independently reproducible: False
  • Comparative-testing claim allowed: False
  • Missing reproducibility gates: shared_test_vector, raw_output, timestamp, runtime_configuration, source_version_or_hash, replay_commands, declared_expected_outcome, independent_reproduction
  • Evaluation result: COMPATIBILITY_EVIDENCE_ONLY
  • Cycle status: FIRST_FRAMEWORK_CYCLE_COMPLETE
  • Execution authority claim: False
  • Next bounded action: Add executable observations, raw outputs, pinned versions, replay commands, and independent reproduction before making comparative-testing claims.
  • Posting source: generated compatibility report
  • Generated status is descriptive compatibility evidence only.

Generated Authored Analysis Boundary

This section is generated. Do not edit it manually.

  • Framework ID: oscal
  • Framework name: OSCAL
  • Generated sections above this boundary may be rebuilt from registry, manifest, compatibility-report, and result artifacts.
  • Authored analysis below this boundary may contain interpretation, notes, and framework-specific discussion.
  • Generators must preserve authored analysis unless a future validator explicitly declares a migration path.
  • Boundary rule: generated material is descriptive compatibility evidence only and does not create certification, endorsement, adoption, proof, or operational permission.

Generated Transition Mapping

This section is generated from the framework manifest. Do not edit it manually.

FieldGenerated Value
framework_identityNIST OSCAL 1.2.2
source_referencehttps://pages.nist.gov/OSCAL-Reference/models/v1.2.2/
source_versionOSCAL 1.2.2
allowed_use_boundarymachine-readable control and assessment evidence only
claimscatalog, profile, component-definition, SSP, assessment-plan, assessment-results, POA&M, control-mapping, and structured evidence representation
non_claimsno admissibility proof, certification, endorsement, standing, or execution authority
input_artifact_typeversioned OSCAL control, implementation, assessment, remediation, or mapping document
output_artifact_typestructured control and assessment evidence
actor_or_authority_modelOSCAL party/responsibility records are evidence declarations; current StegVerse authority is independently reconstructed
evidence_modelversioned machine-readable models plus references, hashes, validation state, and assessment freshness
policy_or_rule_modelcatalogs and profiles may supply structured policy/control references
delegation_modelresponsible-party declarations do not independently establish current delegation
decision_or_result_modelassessment findings and results are review evidence only
execution_authority_claimfalse
receipt_or_trace_modelpinned model release, immutable source/sample identity, manifest, compatibility fixture, and validation reports
reconstruction_modelsource package, model version, document version, references, transformations, and assessment records support reconstruction when retained
SPE_overlapstructured control/assessment evidence may inform review but not standing determination
StegVerse_ecosystem_overlapPolicy Reference, Evidence Posture, Review Posture, Reconstructability, Drift, Fail-Closed behavior
fail_closed_conditionsmissing source identity, model/document version confusion, schema/reference failure, stale assessment, missing current authority, semantic scope divergence, or authority overclaim

Generated mapping is compatibility evidence only.

Generated Framework Metadata

This section is generated from the external-framework registry. Do not edit it manually.

  • Framework ID: oscal
  • Name: OSCAL
  • Registry status: SOURCED-CROSSWALK-PROVISIONAL
  • Testbench state: SOURCE_RECORDED_CROSSWALK_PROVISIONAL
  • Manifest path: docs/external-frameworks/oscal.json
  • Source reference: https://pages.nist.gov/OSCAL/
  • Metadata boundary: generated metadata is descriptive only; it does not create certification, endorsement, formalism adoption, admissibility proof, or execution authority.

Status

Relationship type: external framework crosswalk
Canonical StegVerse formalism source: Admissible-Existence
External framework role: machine-readable security control and assessment language
Evaluated OSCAL release: 1.2.2
evidence_class: SOURCE_REVIEWED
page_completeness: COMPLETE_WITH_EXTERNAL_GATES
comparative_testing_claim_allowed: false
execution_authority_claim_allowed: false
Evidence posture: PINNED_PUBLIC_MODEL_RELEASE + PINNED_PUBLIC_SAMPLE + BOUNDED_STEGVERSE_CROSSWALK
Runtime posture: NOT_AN_AUTHORITY_ENGINE
Standing: no standing created
Execution authority: none

Official Source And Version

This evaluation is pinned to NIST OSCAL 1.2.2, the latest released OSCAL model reference identified by the official NIST reference and project release surfaces at the time of this evaluation.

project: https://pages.nist.gov/OSCAL/
release reference: https://pages.nist.gov/OSCAL-Reference/models/v1.2.2/
release tag: https://github.com/usnistgov/OSCAL/releases/tag/v1.2.2
release: OSCAL 1.2.2
release date: 2026-04-30

A second pinned official source demonstrates actual public content using OSCAL 1.2.2:

repository: usnistgov/oscal-content
repository tag: v1.5.0
sample: nist.gov/SP800-53/rev5/json/NIST_SP-800-53_rev5_PRIVACY-baseline_profile.json
Git blob SHA: 85025c21e392ab4d67ad4b4490bbff6871811945
document metadata version: 5.2.0
document oscal-version: 1.2.2

The model-release version, OSCAL content-repository release, and an individual OSCAL document's own version are distinct identities. This evaluation keeps them separate rather than treating any one version string as a substitute for the others.

Evidence Provenance

Evidence ClassCurrent EvidenceStatusMissing Fields
Official Framework SourcesOfficial NIST OSCAL project, OSCAL 1.2.2 release reference/tag, and official model documentation.present_pinned_releaseNo current source-identity gap for the bounded model crosswalk.
Official Implementation SourcesOfficial usnistgov/oscal-content v1.5.0 profile sample pinned by path and Git blob SHA; document metadata records oscal-version: 1.2.2.present_pinned_public_sampleNo claim that this sample represents a deployed system.
Observed BehaviorDirect source inspection confirms a real official OSCAL profile sample with separate document version 5.2.0 and oscal-version 1.2.2. No native authorization runtime behavior is claimed.source_structure_observedNative validator/converter execution is not claimed by this transition.
Reproduced BehaviorNo independent validator/converter reproduction is claimed.not_applicable_for_runtime_resultA separate frozen tool-execution packet would be required for an interoperability-runtime claim.
StegVerse AnalysisOSCAL control and assessment artifacts are mapped to Policy Reference, Evidence Posture, Review Posture, Reconstructability, Drift, and Fail-Closed behavior. Six bounded cases exercise freshness, reference, authority, and scope boundaries.control_assessment_crosswalkCanonical merged-state validation is the remaining local gate.
Interoperability AssessmentOSCAL artifacts can enter a Commitment Candidate as structured control/assessment evidence, but schema validity and machine readability do not create standing or authority.bounded_crosswalk_pending_merged_validationNo independent interoperability certification is claimed.
StandingPublication, schema validity, role declarations, and assessment results create no StegVerse standing.none_createdStanding and delegation must be independently reconstructed at commit time.

Evidence classification:

F1: official NIST OSCAL 1.2.2 project/release/reference sources.
F2: official usnistgov/oscal-content v1.5.0 sample pinned by repository tag, exact path, and Git blob SHA; metadata exposes document version 5.2.0 and oscal-version 1.2.2.
S1: StegVerse interpretation of OSCAL artifacts as structured policy/control/assessment evidence rather than authority.
S2: six-family StegVerse governance mapping for schema/reference validity, evidence freshness, current authority, and semantic scope.
H1: any future claim of native tool interoperability, implementation effectiveness, certification, standing, or execution authority remains prohibited until separately observed and governed.

Framework-Term Definitions

Native OSCAL TermDefinition For This WikiReconciliation ClassAdmissibility Relationship
OSCALNIST Open Security Controls Assessment Language, evaluated here at release 1.2.2.newStructured security-control and assessment evidence language; not an admissibility engine.
CatalogMachine-readable collection of control definitions.adjacentMay provide Policy Reference evidence.
ProfileSelection, tailoring, and organization of controls from one or more catalogs.adjacentMay provide scoped policy evidence; profile validity does not establish transition authority.
Component DefinitionReusable description of how a component may implement controls or capabilities.adjacentImplementation-claim evidence; declaration is not operational proof.
System Security PlanSystem-specific description of control implementation and system context.adjacentEvidence Posture and reconstruction input; not current execution authority.
Assessment PlanStructured plan for evaluating control implementation.adjacentReview Posture input; a plan is not an observed result.
Assessment ResultsStructured findings and observations produced by an assessment.adjacentEvidence Posture and Review Posture; findings do not create delegation.
Plan of Action and MilestonesStructured remediation/planning information for identified findings or risks.adjacentMay inform corrective-action review and continuity; does not authorize consequence.
Control MappingStructured relationship among controls or control concepts.adjacentSupports translation/reconstruction; semantic mapping is not equivalence by itself.
oscal-versionMetadata indicating the OSCAL model version used to represent the document.newRequired for interpretation/replay and must not be conflated with the document's own content version.
Document versionVersion metadata belonging to the represented content/artifact.newEvidence-freshness identity distinct from OSCAL model release identity.

Framework-Native Scope

OSCAL provides machine-readable models for security controls and their lifecycle artifacts, including catalogs, profiles, component definitions, system security plans, assessment plans, assessment results, plans of action and milestones, and control mappings. NIST publishes model references and official content in machine-readable formats.

The pinned public sample demonstrates that a real official profile artifact carries both a content version and an OSCAL model version. This is useful for reconstruction and version discipline. It does not establish that any represented control is implemented, effective, current, applicable, or authorized for a specific transition.

Relationship to Admissibility

OSCAL belongs upstream of commit-time admissibility as structured control and assessment evidence. Its documents can contribute current, provenance-bound evidence, but OSCAL does not itself determine standing, delegation, admissibility, or execution authority.

StegVerse Analysis

The strongest currently supported StegVerse use is a bounded source-versioned crosswalk: preserve model/document identity, validate references and freshness, map control/assessment semantics, and fail closed when authority or action scope cannot be reconstructed.

The six StegVerse case families are bounded mapping tests, not native NIST runtime tests:

FamilyExpected StegVerse Posture
positive alignmentALLOW only when the document is valid, references resolve, evidence is fresh, responsible party/delegation/policy are current, scope matches, and recoverability is satisfied.
framework denial / negative resultDENY when the represented control evidence fails the evaluated validation boundary.
authority / delegation failureDENY even when the OSCAL document is valid if current responsible-party/delegation authority is absent.
stale / missing evidenceFAIL_CLOSED when assessment evidence is stale.
malformed / undefined resultFAIL_CLOSED when the evidence package cannot be validly interpreted or resolved.
semantic divergence guardDENY when the requested action is outside the scope represented by the OSCAL evidence.

Failure Classes

CONTROL_EVIDENCE_VALIDATION_DENIAL
AUTHORITY_DRIFT
STALE_CONTROL_EVIDENCE
FRAMEWORK_RUNTIME_ERROR
ACTION_SCOPE_DIVERGENCE

FRAMEWORK_RUNTIME_ERROR in the StegVerse fixture is a fail-closed test label for malformed/undefined evaluation input; it is not evidence that NIST OSCAL itself experienced a runtime failure.

Commit-Time Interoperability Contract

transition_id
oscal_model_type
oscal_document_reference
oscal_document_hash
oscal_version
document_version
profile_reference
control_references
assessment_result_references
responsible_party_references
validation_tool_reference
transformation_receipt
policy_reference
delegation_reference
evidence_references
source_timestamp
validity_window

Governance-chain placement:

pinned OSCAL artifact + model version + document version + references/hashes
-> Policy Reference / Evidence Posture / Review Posture
-> freshness + reference-resolution + system/action-scope checks
-> independent standing / delegation reconstruction
-> Commitment Candidate evidence set
-> commit-time admissibility decision
-> consequence binding only when separately authorized

Machine readability improves transport, inspection, and reconstruction. It does not convert represented claims into truth or convert named responsible parties into current execution authority.

Machine-Readable Companions

manifest: docs/external-frameworks/oscal.json
benchmark mapping: docs/external-frameworks/benchmark-mappings/oscal.mapping.json
benchmark fixture: docs/external-frameworks/fixtures/oscal-benchmark-fixture.v0.1.json
governance fixture: tests/fixtures/external-frameworks/oscal-governance-compatibility-cases.v1.json
compatibility report: docs/external-frameworks/reports/oscal.compatibility.json
case families: 6
canonical workflow: .github/workflows/validate-chain-continuation.yml

Claims Versus Demonstrated Abilities

QuestionCurrent Evidence
Is an official current OSCAL release pinned?Yes: 1.2.2.
Is a real official OSCAL 1.2.2 content sample pinned?Yes, by repository tag, path, and Git blob SHA.
Are OSCAL release version and document version kept distinct?Yes.
Can OSCAL represent controls and assessment lifecycle artifacts?Yes, per the official model reference.
Has StegVerse installed a six-family governance mapping?Yes.
Has native OSCAL validator/converter execution been observed in this transition?No.
Does schema validity prove represented controls are implemented or effective?No.
Does an OSCAL responsible-party record establish current delegation?No.
Does OSCAL establish StegVerse standing or execution authority?No.
Is NIST certification or endorsement claimed?No.

Non-Claims

OSCAL is not a StegVerse canonical formalism.
OSCAL does not prove transition admissibility.
Schema-valid OSCAL content does not prove represented controls are implemented, effective, current, or applicable.
Responsible-party declarations do not independently establish current delegation.
Assessment findings are evidence, not consequence-binding authority.
Machine readability does not create standing.
The StegVerse six-case fixture is bounded crosswalk evidence, not NIST certification or endorsement.
Comparative testing claim allowed: false.
Execution authority claim allowed: false.
Publication creates no standing.

Replay And Reconstruction Boundary

The current source-level packet is reconstructable from the pinned OSCAL release and pinned public sample identity. A stronger native interoperability claim would require a frozen validation/conversion tool version, exact input package, commands, raw output, timestamps, environment, expected output, and an independent replay or reconstruction receipt.

No such stronger runtime claim is made here.

Validation Completion Criteria

The official model release, pinned public sample, version distinctions, terminology reconciliation, six-family mapping, governance-chain placement, failure boundaries, and non-authority language must all remain installed and validator-compatible. Canonical validation must observe OSCAL manifest, terminology, page remediation, benchmark mapping/fixture, report, provenance, and governance-compatibility checks without OSCAL-specific failures.

Next Safe Build Target

After the current source-versioned bounded crosswalk is canonically validated, a stronger optional evidence transition may execute a frozen official OSCAL validation/conversion tool against the pinned sample, preserving exact tool version, command, raw output, timestamps, environment, source hashes, and replay receipt. That stronger transition is not required to claim the bounded source-reviewed terminal class and must not be inferred from page publication alone.

Challenge Path

A challenge must identify the OSCAL source/release, model/document version distinction, affected model or artifact, disputed mapping, failure class, or authority boundary, and provide inspectable evidence for correction.

This page reflects a bounded admissibility packet. Publication does not create standing. The reflected claim inherits only the standing reconstructable from referenced evidence, authority, and admissibility conditions.