[Verse 1]
When compliance gets complex and controls feel unclear
There's a framework designed to make everything clear
NIST developed a standard to organize the mess
OSCAL is the answer for compliance success
[Chorus]
Oh-S-C-A-L spells control
Machine-readable formats for the whole lifecycle flow
JSON, XML, YAML too
Data models for compliance, tried and tested true
Not a rule language, but a structure so bright
OSCAL makes compliance artifacts right
[Verse 2]
Seven components in this comprehensive plan
Catalogs hold the controls across the security span
Profiles select the subset that your system will need
Implementation guidance helps you succeed
[Chorus]
Oh-S-C-A-L spells control
Machine-readable formats for the whole lifecycle flow
JSON, XML, YAML too
Data models for compliance, tried and tested true
Not a rule language, but a structure so bright
OSCAL makes compliance artifacts right
[Verse 3]
System security plans document what you've designed
Assessment plans detail how testing is defined
Assessment results capture findings from the review
Plans of action track milestones to push you through
[Bridge]
From catalogs to profiles
Plans to results and more
Six artifacts working together
Opening compliance doors
Machine-readable consistency
Human-readable too
OSCAL bridges the gap
Between what systems need and do
[Chorus]
Oh-S-C-A-L spells control
Machine-readable formats for the whole lifecycle flow
JSON, XML, YAML too
Data models for compliance, tried and tested true
Not a rule language, but a structure so bright
OSCAL makes compliance artifacts right
[Outro]
When controls need structure and compliance needs care
OSCAL's data model gets you there