Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Follow up on 7th Sept meeting. #40

Closed
mcleo-d opened this issue Sep 25, 2023 Discussed in #36 · 12 comments
Closed

Follow up on 7th Sept meeting. #40

mcleo-d opened this issue Sep 25, 2023 Discussed in #36 · 12 comments
Assignees
Labels
OSCAL representation of FINOS CCC Work related to representing CCC in OSCAL, partnering with NIST to understand how to represent in OS question Further information is requested

Comments

@mcleo-d
Copy link
Member

mcleo-d commented Sep 25, 2023

Discussed in #36

Originally posted by ianmiell September 21, 2023
Hi @jonmuk @iMichaela,

As discussed in the meeting of 7th September, I'm introducing you to my colleagues @gusfcarvalho and Onsel (invite pending, https://github.com/onselakin).

As a reminder of the context, Onsel and Gustavo are working with the OSCAL standard as part of an open source project we're working on. They've had some lessons learned as a result and we're keen to discuss them with you, as well as hear from you about your perspectives on it.

If you'd like to continue the discussion by email, my email is: ian.miell [at] container-solutions.com (I don't think I have your mails). Anyone else with an interest in this group is welcome to join us.

Ian

@mcleo-d mcleo-d added question Further information is requested OSCAL representation of FINOS CCC Work related to representing CCC in OSCAL, partnering with NIST to understand how to represent in OS labels Sep 25, 2023
@mcleo-d
Copy link
Member Author

mcleo-d commented Sep 25, 2023

Hi @ianmiell

Thanks for raising the GitHub Discussion.

I have converted the item to a GitHub Issue and have assigned to @jonmuk to feedback 👍🏻

James.

@iMichaela
Copy link
Contributor

iMichaela commented Sep 26, 2023

@ianmiell -- Thank you for introducing Gustavo and Onsel. I would be very happy to learn more about their effort. I sent you an email, so we can connect and start the dialog.

@mcleo-d
Copy link
Member Author

mcleo-d commented Sep 26, 2023

Hi @ianmiell,

I have just invited @onselakin to join the project team and have followed up 1:1 over email.

It would be great if you could share your experiences with the wider project group, including @iMichaela and @jonmuk, so we can filter your experiences into the OSCAL and NIST working group deliverables?

Let me know the title of the meeting, and how much time you need to prepare, and I'll schedule and advertise it to the rest of the group.

@iMichaela - I hope this open format works for you?

James.

@iMichaela
Copy link
Contributor

@iMichaela - I hope this open format works for you?

@mcleo-d - No problem at my end.

@mcleo-d
Copy link
Member Author

mcleo-d commented Oct 3, 2023

Hi @ianmiell and @iMichaela,

Thank you for meeting last Friday and apologies that I couldn't join you on the call due to personal illness.

It would be great to get a summary of the meeting in this GitHub issue so we can keep momentum going as a full project group. I'm sure there was real value discussed.

Thank you for pushing the project forward.

James.

@iMichaela
Copy link
Contributor

@ianmiell - Do you want to summarize the conversation - your plan and the discussion. I do not want to say something that it is not for public consumption around your project.

@ianmiell
Copy link
Contributor

ianmiell commented Oct 4, 2023 via email

@ianmiell
Copy link
Contributor

ianmiell commented Oct 4, 2023

A brief summary of the meeting the other day:

Attendees:

@iMichaela - NIST
@gusfcarvalho - Container Solutions
@ianmiell - Container Solutions

  • Introduction to our open source real-time controls management and automation tooling (https://github.com/compliance-framework - not yet 'announced' or well-documented, but public)
  • Discussion about why OSCAL is not a schema, but document/filesystem-oriented instead
    • Wanted flexibility, aims to support data 'movement' between actors for interoperability
    • Didn't want to coerce users into using a database
  • Discussion about abstracting implementation from control so that different environments can have different implementations
    • This is known about, and the next version of OSCAL seeks to address this. In the meantime, our application can work around it.
  • Introduction from Michaela to various resources, eg:
    • FedRAMP
    • OscalTools website
    • OSCAL Lobby
    • OSCAL mailing lists

@mcleo-d
Copy link
Member Author

mcleo-d commented Oct 4, 2023

Hey @ianmiell and @iMichaela

Thank so much for publicising the notes from your meeting. This will be of interest to @jonmuk and @git-hub-forwork1 who have both touched upon the resources and topics mentioned in your list.

You might have noticed that I have raised the following PR that includes the roadmap items discussed on the last OSCAL call - Add CCC Roadmap to Project ReadMe

It would be great if any of the detail of your discussions could be filtered into the high level topics below. @ianmiell, it's awesome that Container Solutions has an open source project, so feel free to point to your repos if relevant to CCC.

OSCAL Working Group High Level Items

White House RFI

Also, FedRamp was raised on the White House RFI discussions last week. I thought I'd mention just in case a diamond was discussed that could be filtered into the items below 💎✨

Speak soon,

James.

@mcleo-d
Copy link
Member Author

mcleo-d commented Nov 9, 2023

Hi @ianmiell and @iMichaela,

Can you help move the actions from this GitHub Issue forward with the OSCAL representation of FINOS CCC working group or close if done.

Thank you for your help and collaboration,

James.

@ianmiell
Copy link
Contributor

ianmiell commented Nov 9, 2023

I'm happy to close. Thanks.

For reference, the Compliance Framework open source project is here: https://github.com/compliance-framework

@iMichaela
Copy link
Contributor

11/09/2023

During the meeting we decided this issue can be closed.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
OSCAL representation of FINOS CCC Work related to representing CCC in OSCAL, partnering with NIST to understand how to represent in OS question Further information is requested
Development

No branches or pull requests

4 participants