OSCAL namespace
To include CAM specific information, custom properties with a unique namespace are used to add impact and tailor the content as needed.
| Field | Description |
|---|---|
| impact | Captures control objective impact. |
| justification | Justification for making baseline control not applicable. Present only when a baseline control is made not applicable. |
| source | Source of baseline control objective. |
| active | Indicates whether a control objective is active. |
| behavior | Comparing the control objective reference in the policy with those in the baseline controls. For matching records (same reference ID as in the baseline controls):
For distinct records (reference ID does not exist in baseline controls): For more information, see View package details in CAM Workspace.
|
| configuration | Applying a policy to the baseline controls using configurations such as Addition, Subtraction, and Custom Action. |
| action | Combination of behavior and configuration. |
| order | The order in which you applied the policy. |
| impact-change-justification | If recommended impact is changed. This property will contain the justification for change. |
| category | Category of Information type. |
| sub_category | Subcategory of information type. |
| pii-in-identifiable-form | PII information pii-in-identifiable-form. |
| pii-information-about-public | PII information pii-information-about-public. |
| privacy-impact-assessment | PII information privacy-impact-assessment. |
| system-of-records-notice | PII information system-of-records-notice. |
| privacy-sensitive-system | PII information privacy-sensitive-system. |