[Verse 1]
Three layers stack like building floors
Controls define what must be done
Catalog holds the golden rules
Profile picks the needed ones
[Verse 2]
Implementation takes the stage
Components show how systems work
SSP documents the plan
Real machines with real configurations
[Chorus]
Left to right the data streams
Right to left we trace it back
Controls to code to evidence
OSCAL keeps us on the track
Three layers deep, the story's clear
Definition, action, proof appear
[Verse 3]
Assessment comes to close the loop
Plans describe what tests we'll run
Results reveal what actually happened
Findings show where gaps exist
[Verse 4]
POA&M tracks the remediation
From abstract rules to concrete fixes
Every layer speaks its language
XML connects the pieces
[Chorus]
Left to right the data streams
Right to left we trace it back
Controls to code to evidence
OSCAL keeps us on the track
Three layers deep, the story's clear
Definition, action, proof appear
[Bridge]
When auditors come knocking
Traceability saves the day
From control back to implementation
Every claim has proof to stay
[Final Chorus]
Left to right the data streams
Right to left we trace it back
Controls to code to evidence
OSCAL keeps us on the track
Three layers deep, the story's clear
Definition, action, proof appear
The architecture holds it all together