Catalog
OSCAL Model: Catalog
The Catalog model defines a structured collection of security and privacy controls. It serves as the foundational source of truth for all controls that may be selected and applied in profiles and system security plans.
Summit Context
This directory contains the OSCAL Catalog artifacts for the Summit system by Oscalate Systems. The catalog defines the complete set of controls available for selection and implementation.
What Belongs Here
- OSCAL Catalog files (JSON, XML, or YAML)
- Custom control definitions specific to the Summit system
- Control group and family structures
Key Concepts
- Controls: Individual security requirements or guidelines
- Groups: Logical groupings of related controls (e.g., families)
- Parameters: Configurable values within controls (e.g., password length)
- Parts: Sub-sections of controls (e.g., statements, guidance)
OSCAL Reference