Profile
OSCAL Model: Profile (Baseline)
The Profile model represents a selection and tailoring of controls from one or more catalogs. Profiles are commonly referred to as “baselines” and define which controls apply to a particular system or compliance framework.
Summit Context
This directory contains the OSCAL Profile artifacts for the Summit system by Oscalate Systems. Profiles here define the specific control baselines applicable to Summit, including any tailoring of control parameters.
What Belongs Here
- OSCAL Profile files (JSON, XML, or YAML)
- Baseline selections (e.g., FedRAMP Low, Moderate, High)
- Tailored profiles with organization-specific parameter settings
Key Concepts
- Imports: References to source catalogs or other profiles
- Merge: Rules for combining controls from multiple sources
- Modify: Tailoring operations including parameter settings and control alterations
- Select: Criteria for including or excluding specific controls
OSCAL Reference