Patterns
OSCAL compliance-package examples, published as files rather than described in prose.
Summit, by Oscalate Systems
A model office system spanning all seven OSCAL models, from control selection to weakness tracking. The models form a chain: a catalog defines controls, a profile selects and tailors controls, component definitions describe control implementation, the SSP documents the system, the assessment plan defines assessment procedures, assessment results record findings, and the POA&M tracks remediation.
Two of the seven artifacts are published so far. The table lists all seven models to identify missing artifacts.
| # | Model | Artifact | OSCAL |
|---|---|---|---|
| 1 | Catalog | not yet published | |
| 2 | Profile | Oscalate Systems Moderate Baseline
9 KB, JSON |
1.1.2 |
| 3 | Component Definition | not yet published | |
| 4 | System Security Plan | Summit System SSP
130 KB, JSON |
1.2.1 |
| 5 | Assessment Plan | not yet published | |
| 6 | Assessment Results | not yet published | |
| 7 | Plan of Action & Milestones | not yet published |
Architecture
Two diagrams describe the system: the technical architecture and the authorization boundary.
-
Technical architecture
Components, relationships, and locations.
-
Authorization boundary
System scope, inheritance, and external elements.
-
Diagram source
PlantUML source for both diagrams.

