[Verse 1]
OSCAL gives us structure, a foundation so strong
But every organization has needs that don't quite belong
To the standard alone, so we extend and we grow
FedRAMP shows the way, here's what you need to know
[Chorus]
Properties and annotations, links that bridge the gap
Extensions keep us flexible while staying on the map
Interoperable pathways, custom fields that flow
Extend but don't break it, that's the way to go
[Verse 2]
FedRAMP takes the baseline, adds their federal touch
Authorization boundaries, they need to capture much
More than standard OSCAL, so they build upon the base
Extension model working, everything in its place
[Chorus]
Properties and annotations, links that bridge the gap
Extensions keep us flexible while staying on the map
Interoperable pathways, custom fields that flow
Extend but don't break it, that's the way to go
[Verse 3]
Properties add metadata, simple name-value pairs
Annotations give you prose, for details that nobody declares
Links connect your objects to external resources wide
Three mechanisms working, standing side by side
[Bridge]
Don't reinvent the wheel, don't break what's working well
Use the extension points, let interop excel
Your custom fields can coexist with standard OSCAL core
Backwards compatibility, that's what extensions are for
[Chorus]
Properties and annotations, links that bridge the gap
Extensions keep us flexible while staying on the map
Interoperable pathways, custom fields that flow
Extend but don't break it, that's the way to go
[Outro]
Build your org extensions on OSCAL's solid ground
Keep the ecosystem healthy, let compatibility be found