---
sourceDocument: Zurich Governance, Risk, and Compliance
sourceDocumentLink: https://www.servicenow.com/docs/r/zurich/governance-risk-compliance

 Release :

    - zurich

ft:locale :

    - en-US

ft:publication_title :

    - Zurich Governance, Risk, and Compliance

ft:clusterId :

    - grc

bundleId :

    - grc

workflow :

    - Technology


---

# OSCAL namespace

# OSCAL namespace {#ariaid-title1}

* Release version: Zurich
* 
* Updated July 31, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

To include CAM specific information, custom properties with a unique namespace are used to add impact and tailor the content as needed.
{#oscal-namespace__table_s4j_5vv_12c__entry__2}

| Field | Description |
|-|-|
| impact | Captures control objective impact. |
| justification | Justification for making baseline control not applicable. Present only when a baseline control is made not applicable. |
| source | Source of baseline control objective. |
| active | Indicates whether a control objective is active. |
| behavior | Comparing the control objective reference in the policy with those in the baseline controls. For matching records (same reference ID as in the baseline controls): * Override: Replaces the baseline control objective with the one from the selected policy. * Move to N/A: Moves the control objective with the matching reference ID to the Not Applicable state. * Skip: Ignores the matching record; no changes will be made to the Authorization Package from the selected policy. {#oscal-namespace__ul_jyc_jw3_yfc} For distinct records (reference ID does not exist in baseline controls): * Create new: Adds the new control objective from the selected policy to the Authorization Package. * Skip: Ignores the distinct record; it will not be added to the Authorization Package. {#oscal-namespace__auth-package-overview-ws_ul_hh3_w3d_yfc} For more information, see [View package details in CAM Workspace](https://www.servicenow.com/docs/_fxidPyubXvx8plvrbSRsw "Use the authorization package overview page to view documents and evidence that help you to assess your organization's security posture."). |
| configuration | Applying a policy to the baseline controls using configurations such as Addition, Subtraction, and Custom Action. |
| action | Combination of behavior and configuration. |
| order | The order in which you applied the policy. |
| impact-change-justification | If recommended impact is changed. This property will contain the justification for change. |
| category | Category of Information type. |
| sub_category | Subcategory of information type. |
| pii-in-identifiable-form | PII information pii-in-identifiable-form. |
| pii-information-about-public | PII information pii-information-about-public. |
| privacy-impact-assessment | PII information privacy-impact-assessment. |
| system-of-records-notice | PII information system-of-records-notice. |
| privacy-sensitive-system | PII information privacy-sensitive-system. |
[ ]

{#oscal-namespace__table_s4j_5vv_12c}

