OSCAL and Compliance Automation

14 chapters

Chapters

  1. 1 The Three-Layer Architecture
    OSCAL and Compliance Automation · 3:58
    Explore the foundational structure of OSCAL through its three-layer architecture, where controls, implementation, and assessment work together in a connected chain to drive compliance automation.
  2. 1 Supported Formats
    OSCAL and Compliance Automation · 2:49
    Dive into the three core formats supported by OSCAL—XML, JSON, and YAML—and discover the strengths each brings to compliance automation, from XML's mature schema validation to JSON's modern API-friendly design.
  3. 3 Working with OSCAL Data
    OSCAL and Compliance Automation · 3:24
    Dive into the practical side of OSCAL as you explore its three core data formats—XML, JSON, and YAML—and learn how schema validation keeps your compliance data accurate and reliable.
  4. 4 Hands-On Exercise Ideas
    OSCAL and Compliance Automation · 3:40
    Dive into practical, hands-on exercises that bring OSCAL concepts to life, including parsing NIST SP 800-53 revision 5 catalog data in JSON format and extracting specific control families like access control to sharpen your compliance automation skills.
  5. 3 Commercial GRC Platforms with OSCAL Support
    OSCAL and Compliance Automation · 3:12
    Explore three leading commercial GRC platforms — RegScale, Xacta, and Ignyte — that natively support OSCAL, and discover how their automation capabilities can streamline compliance workflows and simplify FedRAMP certification.
  6. Lab 7: Tool Integration
    OSCAL and Compliance Automation · 2:47
    Hands-on practice with IBM Trestle brings spreadsheet data to life, walking you through the transformation of simple Excel rows and columns into fully structured OSCAL compliance frameworks.
  7. Lab 3: Create a Component Definition
    OSCAL and Compliance Automation · 1:53
    Hands-on practice takes center stage as learners build their own component definition from scratch, selecting a familiar technology and mapping three to five security controls to document how it meets compliance requirements.
  8. 2 OSCAL and CMMC
    OSCAL and Compliance Automation · 2:51
    Exploring the powerful intersection of CMMC and OSCAL, this song breaks down how structured data formats like JSON and XML streamline compliance documentation and simplify the mapping of practices to controls.
  9. 2 OSCAL Extensions and Customization
    OSCAL and Compliance Automation · 2:36
    Diving into how OSCAL's core framework can be stretched and tailored to meet unique organizational requirements, this track explores the power of extensions, custom properties, and annotations — using FedRAMP as a real-world example of how flexibility and standardization can coexist.
  10. Key Talking Points
    OSCAL and Compliance Automation · 3:04
    Tackling the frustrations of manual compliance processes, this track breaks down how OSCAL's machine-readable data framework offers a smarter, more efficient alternative to the endless cycle of spreadsheets and repeated audit requests.
  11. 3 The SCAP Protocol Suite
    OSCAL and Compliance Automation · 4:21
    Explore how the SCAP Protocol Suite transforms human-readable security checklists like STIGs into automated, machine-processable standards, and discover the six key specifications that work together to power modern compliance scanning.
  12. 17a: When Business Leadership Values the Credential, Not the Security
    OSCAL and Compliance Automation · 3:54
    Explores the business reality where organizations pursue security certifications primarily as market differentiators and client requirements rather than genuine security improvements, helping listeners understand the commercial motivations that drive compliance programs.
  13. 4 Practical Integration Patterns
    OSCAL and Compliance Automation · 3:54
    Discover how to build a complete System Security Plan by mapping components to STIG guides and documenting compliance gaps using OSCAL definitions as your foundation.
  14. Why the Fractional Model Fits This Condition
    OSCAL and Compliance Automation · 2:44
    Exploring why budget constraints, credential requirements, and cost-efficiency make the fractional model an ideal fit for organizations that need InfoSec expertise without the financial burden of a full-time team.