Michaela Iorga

Results 20 issues of Michaela Iorga

# User Story: As an OSCAL content consumer, I need an accurate representation in the OSCAL SP800-53/rev4 catalog of the controls described in the document SP 800-53rev4 Appendix J. ##...

# Describe the bug The instructions in the README.md file need to be updated to ensure all developers are always installing the latest `oscal-cli` version. If maven path is consistent...

documentation

### User Story 1. In the Control Mapping Model, the `provenance/confidence-score` had a type `string` but could serve better if it would allow doe a numeric score and a description...

enhancement
User Story

### User Story Conversation with CNCS, IBM and ReHat resulted in the need of an array of `component` in the `source-ssp` in order to preserve the `by-component` granularity of the...

enhancement
User Story

# Describe the bug In XML version of any OSCAL content, empty fields like are passed as valid, but when converted to JSON, those fields are removed being empty, resulting...

bug

# Describe the bug ### Describe the bug While browsing the example files, it was noted that there are many typos and spelling errors. For example: - `examples\ap\*\ifa_assessment-plan-example.[json|xml|yaml]`: ```diff -...

bug

# Describe the bug A community member reposted that the SP 800-53 rev5 (and later) catalog is not correctly represented in OSCAL since AU-8(1) and AU-8(2) do not show moved...

bug

# User Story: To update oscal-cli to the most recently published OSCAL models, I want the maintainers to update this underlying library to leverage the v1.1.3 models, not v1.1.2. ##...

enhancement

### Describe the bug The constraints defined for the `assessment-plan/local-definitions/object-and-methods/part/@name` and `assessment-plan/local-definitions/object-and-methods/part/prop/@name` are conflicting. The following sample: ``` IFA Assessment Plan 2023-05-18T13:57:28.355446-04:00 1.0 1.1.2 IFA Security Control Assessor Amy Assessor...

bug

### Describe the bug A test of the profile resolution was observed failing. Further investigation of the bug is necessary to determine if the bug is in the test case...

bug