Export OSCAL Assessment Results
Export the OSCAL Assessment Results (AR) file for an authorization package from the CAM Workspace.
Before you begin
- The authorization package must be in the Assess, Authorize, or Monitor step.
- At least one control test in the engagement must have a closed state. Accepted closed states are:
- Closed Complete
- Closed Incomplete
- Closed Skipped
Roles required:
- Information System Security Manager (sn_irm_cont_auth.info_system_sec_manager)
- Information System Security Officer (sn_irm_cont_auth.info_system_sec_officer)
- CAM Administrator (sn_irm_cont_auth.admin)
Procedure
What to do next
Validate these files using the OSCAL CLI validator and import them into other systems or share them with external auditors for assessment planning.
For information about the OSCAL fields exported in the AR file and their corresponding ServiceNow CAM fields, see OSCAL Assessment Results field mapping.