Skip to main content

OSCAL

Generated Evaluation Status

This section is generated from the framework manifest and compatibility report. Do not edit it manually.

  • Framework ID: oscal
  • Manifest: docs/external-frameworks/oscal.json
  • Compatibility report: ./reports/oscal.compatibility.json
  • Evidence class: SOURCE_REVIEWED
  • Independently reproducible: False
  • Comparative-testing claim allowed: False
  • Missing reproducibility gates: shared_test_vector, raw_output, timestamp, runtime_configuration, source_version_or_hash, replay_commands, declared_expected_outcome, independent_reproduction
  • Evaluation result: COMPATIBILITY_EVIDENCE_ONLY
  • Cycle status: FIRST_FRAMEWORK_CYCLE_COMPLETE
  • Execution authority claim: False
  • Next bounded action: Add executable observations, raw outputs, pinned versions, replay commands, and independent reproduction before making comparative-testing claims.
  • Posting source: generated compatibility report
  • Generated status is descriptive compatibility evidence only.

Generated Authored Analysis Boundary

This section is generated. Do not edit it manually.

  • Framework ID: oscal
  • Framework name: OSCAL
  • Generated sections above this boundary may be rebuilt from registry, manifest, compatibility-report, and result artifacts.
  • Authored analysis below this boundary may contain interpretation, notes, and framework-specific discussion.
  • Generators must preserve authored analysis unless a future validator explicitly declares a migration path.
  • Boundary rule: generated material is descriptive compatibility evidence only and does not create certification, endorsement, adoption, proof, or operational permission.

Generated Transition Mapping

This section is generated from the framework manifest. Do not edit it manually.

FieldGenerated Value
framework_identityOSCAL
source_referencehttps://pages.nist.gov/OSCAL/
source_versionofficial NIST source recorded
allowed_use_boundarycontrol and assessment evidence only
claimsmachine-readable control and assessment models
non_claimsno admissibility proof or execution authority
input_artifact_typecontrol or assessment model
output_artifact_typestructured control evidence
actor_or_authority_modelexternal control model; authority not inherited
evidence_modelofficial source plus bounded crosswalk
policy_or_rule_modelcontrol catalogs and profiles
delegation_modelnot established
decision_or_result_modelassessment evidence
execution_authority_claimfalse
receipt_or_trace_modelmanifest and report references
reconstruction_modelstructured artifacts support reconstruction
SPE_overlapcontrol evidence may inform standing review
StegVerse_ecosystem_overlapevidence and reconstruction boundary
fail_closed_conditionsmissing source, mapping, or authority overclaim

Generated mapping is compatibility evidence only.

Generated Framework Metadata

This section is generated from the external-framework registry. Do not edit it manually.

  • Framework ID: oscal
  • Name: OSCAL
  • Registry status: SOURCED-CROSSWALK-PROVISIONAL
  • Testbench state: SOURCE_RECORDED_CROSSWALK_PROVISIONAL
  • Manifest path: docs/external-frameworks/oscal.json
  • Source reference: https://pages.nist.gov/OSCAL/
  • Metadata boundary: generated metadata is descriptive only; it does not create certification, endorsement, formalism adoption, admissibility proof, or execution authority.

Evidence posture

evidence_class: SOURCE_REVIEWED
page_completeness: COMPLETE_WITH_EXTERNAL_GATES
runtime_observation: none attached
independent_reproduction: false
comparative_testing_claim_allowed: false
execution_authority_claim_allowed: false

Published scope

OSCAL provides machine-readable models for control catalogs, profiles, implementation descriptions, assessment plans, assessment results, and plans of action and milestones.

Canonical source: https://pages.nist.gov/OSCAL/

Source snapshot posture: the canonical NIST source is recorded, but no pinned OSCAL release, model profile, validation toolchain, sample assessment package, conversion output, or independent reconstruction receipt is attached.

Native terms

OSCAL termMeaning hereStegVerse relationship
CatalogStructured control definitions.Policy/control source evidence.
ProfileSelected and tailored controls.Scoped policy evidence requiring provenance.
Component definitionReusable implementation description.Implementation-claim evidence, not operational proof.
System security planSystem control implementation description.Declared posture evidence.
Assessment resultsFindings and observations from assessment.Review evidence; not execution authority.

Relationship to admissibility

OSCAL asks: How can controls, implementation claims, assessments, and findings be represented consistently?
StegVerse asks: Does the specific transition have current standing and permission to bind consequence now?

OSCAL artifacts may contribute structured control and assessment evidence to reconstruction. Machine readability improves transport and inspection but does not establish the truth, freshness, legitimacy, or consequence-binding authority of the represented claims.

Observation boundary

No public OSCAL interoperability conversion or runtime validation result is claimed.

shared test vector: missing
raw output: missing
timestamp: missing
runtime configuration: missing
source version or hash: missing
replay commands: missing
declared expected outcome: missing
independent reproduction: missing

StegVerse analysis

CriterionCurrent result
IdentityOSCAL can name parties and roles but does not prove current identity.
AuthorityControl ownership and assessment roles do not create execution authority.
PolicyStrong overlap for structured policy and control references.
DelegationResponsibility assignments require separate current delegation evidence.
EvidenceOSCAL can carry structured evidence references and findings.
ReplayabilityRequires pinned OSCAL version, profile, source package, validation tools, and conversion rules.
ReconstructabilityStrong potential when source packages, references, and transformations are retained.
Failure behaviorInvalid models, unresolved references, stale assessments, or transformation loss must fail closed.
InteroperabilityOSCAL records can enter a Commitment Candidate as structured control and assessment evidence.

Commit-time interoperability contract

transition_id
oscal_model_type
oscal_document_reference
oscal_document_hash
oscal_version
profile_reference
control_references
assessment_result_references
responsible_party_references
validation_tool_reference
transformation_receipt
policy_reference
delegation_reference
evidence_references
source_timestamp
validity_window

Failure classes

Failure classAppliesCurrent evidence posture
Semantic equivalence divergenceYesOSCAL control status is not StegVerse admissibility.
Authority driftYesNamed roles may no longer hold current authority.
Stale evidenceYesAssessments and implementation claims age.
Replay divergenceYesModel versions and transformations can change meaning.
Recoverability lossYesBroken references or missing source packages impair reconstruction.
Source-claim mismatchYesStructured claims can diverge from actual implementation.
Evidence class confusionYesAssessment results must not be presented as reproduced runtime behavior.

Machine-readable companions

manifest: docs/external-frameworks/oscal.json
compatibility report: docs/external-frameworks/reports/oscal.compatibility.json
canonical registry: docs/external-frameworks/index.json
canonical union: static/external-frameworks/canonical-union-inventory.v1.json

Maintenance and challenge path

Maintenance owner: StegVerse-Labs/admissibility-wiki, External Frameworks audit surface.

A challenge must identify oscal, the disputed mapping or source claim, the affected OSCAL model or version, supporting evidence, and the requested correction. A structured OSCAL record cannot increase standing merely because it validates against a schema.

Validation completion criteria

pinned OSCAL release and schemas
public source package and hashes
validation and transformation commands
raw validation or conversion outputs
reference-resolution results
timestamps and toolchain configuration
predeclared expected boundaries
independent reconstruction receipt
non-claim language preserved

Benchmark relevance

evidence_freshness_boundary, reconstruction_boundary, authority_boundary, interoperability_path

Non-claims

OSCAL inclusion is not certification, equivalence, transition admissibility, or execution authority. Schema-valid OSCAL content is not proof that the represented controls are implemented, current, effective, or authorized.

Next safe build target

Attach one pinned OSCAL package with source hash, schema version, validation command, raw output, reference-resolution record, expected StegVerse evidence posture, and independent reconstruction receipt.

This page reflects a bounded admissibility packet. Publication does not create standing. The reflected claim inherits only the standing reconstructable from referenced evidence, authority, and admissibility conditions.