Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

add a flag to import a group of controls #823

Open
NapoleonMusonera opened this issue Nov 26, 2024 · 1 comment
Open

add a flag to import a group of controls #823

NapoleonMusonera opened this issue Nov 26, 2024 · 1 comment
Labels
good first issue Good for newcomers

Comments

@NapoleonMusonera
Copy link

Add a flag to encampus the whole family control

NIST 800-53R5 has 20 family controls, over 1000 individual controls.... not all are applicable with lula compliance checksbut one that applicable, we can enhance and make it easy for the Security Control Auditors (SCAs)

Links to any relevant code/ Add any other context or screenshots about the technical debt here.

currently, this how am using the lula....tagging individual requirements

#lula generate component -c https://raw.githubusercontent.com/usnistgov/oscal-content/refs/heads/main/nist.gov/SP800-53/rev5/yaml/NIST_SP-800-53_rev5_HIGH-baseline-resolved-profile_catalog.yaml --component 'my component" -r ac-4,ac-5,ac-6 -o ac-controls.yaml.

Expected Deliverable

#lula generate component -c https://raw.githubusercontent.com/usnistgov/oscal-content/refs/heads/main/nist.gov/SP800-53/rev5/yaml/NIST_SP-800-53_rev5_HIGH-baseline-resolved-profile_catalog.yaml --component 'my component" -F AC-Controls -o ac-controls.yaml.

@github-actions github-actions bot added the triage Awaiting triage from the team label Nov 26, 2024
@brandtkeller
Copy link
Member

Thanks for the issue @NapoleonMusonera !

I appreciate the identification of an improvement to the user experience given the potential number of controls. We can certainly look at finding a mechanism to supporting this behavior.

More specific to the deliverable - Lula is an OSCAL tool and each Catalog (800-53R5 is one such catalog) has different structures for naming conventions on controls and groups of controls.

I believe we can find a way to import a group of controls - but it may look different than your requirements above.

@brandtkeller brandtkeller changed the title add a flag to encampus the whole family control add a flag to import a group of controls Dec 6, 2024
@brandtkeller brandtkeller added good first issue Good for newcomers and removed triage Awaiting triage from the team labels Dec 9, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
good first issue Good for newcomers
Projects
Status: 🆕 New
Development

No branches or pull requests

2 participants