[Verse 1]
OSCAL promises structure for compliance work
But when you dig deeper, here's where it lurks
It's just a data format, not a language true
Describes what controls are, not what they do
No logic evaluation, no executable code
Just metadata sitting in descriptive mode
[Chorus]
Three weaknesses hiding in the standard light
Descriptive not prescriptive, can't make it right
Complex schemas tangled, tools still behind
Human eyes can't read what machines designed
OSCAL's got limits, don't be fooled by the name
Data format playing a different game
[Verse 2]
JSON and XML nested ten levels deep
Verbose and complicated, makes authors weep
Hand-crafting OSCAL is practically banned
Need tooling support but it's still unplanned
Schema complexity weighs the system down
Maturity gaps make stakeholders frown
[Chorus]
Three weaknesses hiding in the standard light
Descriptive not prescriptive, can't make it right
Complex schemas tangled, tools still behind
Human eyes can't read what machines designed
OSCAL's got limits, don't be fooled by the name
Data format playing a different game
[Bridge]
Natural language hiding in the core
Control descriptions still ambiguous as before
Free-text fields preserve the problem whole
Structure wraps around but doesn't solve the goal
Machine-readable design leaves humans out
Compliance officers filled with doubt
[Verse 3]
FedRAMP and NIST drive adoption rates
But international spaces hesitate
ISO frameworks and EU regulation
Slow to embrace this US federation
Canadian compliance stays on the side
Geographic limits hard to override
[Chorus]
Three weaknesses hiding in the standard light
Descriptive not prescriptive, can't make it right
Complex schemas tangled, tools still behind
Human eyes can't read what machines designed
OSCAL's got limits, don't be fooled by the name
Data format playing a different game
[Outro]
Policy documents still need their place
OSCAL supplements but can't replace
Remember these limits when you design
Formal languages need clearer lines