Главная
Study mode:
on
1
Intro
2
Major challenges in security controls assessment
3
What is OSCAL?
4
OSCAL goals
5
A note about terminology
6
OSCAL Workflow
7
Phased Development of OSCAL
8
The OSCAL Catalog Model
9
The OSCAL Catalog Format - Other Features
10
OSCAL Catalog Example
11
The OSCAL Profile Model
12
OSCAL Profile Example
13
The OSCAL Profile Format - Other Features
14
The OSCAL Implementation Model
15
Remaining Work
16
Why Does this All Matter?
17
Summary
18
Apply What You Have Learned Today
19
Questions and Answers
Description:
Explore the NIST Open Security Controls Assessment Language (OSCAL) project in this 43-minute conference talk from RSA Conference. Discover how OSCAL simplifies security automation by standardizing control, implementation, and assessment information using an open, machine-readable format. Learn to leverage automation for securing systems against multiple standards, understand OSCAL's design and applications, and find out how to contribute to this emerging standard. Delve into the OSCAL Catalog Model, Profile Model, and Implementation Model, and grasp their significance in addressing the complexities of various security standards like COBIT, ISO/IEC 27001, NIST 800.53, and PCI. Gain insights from experts Anil Karmel and David Waltermire on overcoming major challenges in security controls assessment and implementing OSCAL effectively in your organization.

Security Automation Simplified via NIST OSCAL - We’re Not in Kansas Anymore

RSA Conference
Add to list