-
Notifications
You must be signed in to change notification settings - Fork 202
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
assessment-assets missing in POAM's local-definitions #1291
Comments
To correct this |
Compton-US
pushed a commit
to Compton-US/OSCAL
that referenced
this issue
Aug 17, 2022
david-waltermire
pushed a commit
to Compton-US/OSCAL
that referenced
this issue
Aug 21, 2022
david-waltermire
pushed a commit
that referenced
this issue
Aug 21, 2022
Repository owner
moved this from Under Review
to Done
in NIST OSCAL Work Board
Aug 21, 2022
david-waltermire
pushed a commit
that referenced
this issue
Aug 23, 2022
aj-stein-nist
pushed a commit
to aj-stein-nist/OSCAL-forked
that referenced
this issue
Oct 6, 2022
aj-stein-nist
pushed a commit
that referenced
this issue
Oct 18, 2022
david-waltermire
pushed a commit
that referenced
this issue
Oct 31, 2022
aj-stein-nist
pushed a commit
to aj-stein-nist/OSCAL-forked
that referenced
this issue
Jan 10, 2023
aj-stein-nist
pushed a commit
to aj-stein-nist/OSCAL-forked
that referenced
this issue
Feb 6, 2023
aj-stein-nist
pushed a commit
to aj-stein-nist/OSCAL-forked
that referenced
this issue
Jun 29, 2023
aj-stein-nist
pushed a commit
to aj-stein-nist/OSCAL-forked
that referenced
this issue
Jul 10, 2023
aj-stein-nist
pushed a commit
to galtm/OSCAL
that referenced
this issue
Sep 28, 2023
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Describe the bug
In circumstances where a POAM is provided without a System Security Plan (SSP), for circumstances where no OSCAL-based SSP exists, or is not delivered with the POA&M, there is no means to specify the definitions of components and assessment-platforms used in the assessment and referenced by an origin's actor as the source of the information. As a result there is no means to resolve/lookup details about the referenced actor.
{A clear and concise description of what the bug is.}
Who is the bug affecting?
What is affected by this bug?
{Describe the impact the bug is having.}
When does this occur?
{Describe the conditions under which the bug is occurring.}
How do we replicate the issue?
{What are the steps to reproduce the behavior?
If applicable, add screenshots to help explain your problem.}
Expected behavior (i.e. solution)
The local-definition of the POAM should be revised to contain an assessment-assets field that would enable definitions for both components or assessment-platforms used in the assessment to be defined so that references can be resolved.
Other Comments
{Add any other context about the problem here.}
The text was updated successfully, but these errors were encountered: