-
Notifications
You must be signed in to change notification settings - Fork 17
docs: establishing lexicon of terms #196
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
Conversation
Signed-off-by: Hannah Braswell <[email protected]>
Signed-off-by: Hannah Braswell <[email protected]>
|
@jpower432 @eddie-knight Any thoughts on including the |
@hbraswelrh Do you mean defining terms like |
I meant more-so having "Gemara Layer 1, 2, etc.," but I guess having the |
|
@eddie-knight the last column is the "Do Not Use" column for words that shouldn't be used to interchangeably with the term. It essentially acts as banned synonyms specific to the project to reduce confusion and misuse. |
| | **Continuous ATO** | A modern approach to authorization where the Authority To Operate is maintained through continuous monitoring, automated assessments, and real-time risk data, rather than through static, point-in-time audits. | | | | ||
| | **Gemara** | Open source logical model to describe the categories of compliance activities, how they interact, and the associated schemas to enable automated interoperability between them. Governed by the Open Source Security Foundation under an Apache 2 license. | Layers 1-6 | | | ||
| | **OSCAL** | The Open Security Controls Assessment Language. A set of standardized, machine-readable formats (XML, JSON, YAML) for expressing and exchanging security control and assessment information, developed and governed by the United States' National Institute of Standards and Technology (NIST). | | | | ||
| | **OSCAL Compass** | Open source toolkit that enables the creation, validation, and governance of compliance artifacts. It leverages NIST's OSCAL as a standard data format and provides an OSCAL SDK. Governed by the Cloud Native Computing Foundation under an Apache 2 license. | | | |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
| | **OSCAL Compass** | Open source toolkit that enables the creation, validation, and governance of compliance artifacts. It leverages NIST's OSCAL as a standard data format and provides an OSCAL SDK. Governed by the Cloud Native Computing Foundation under an Apache 2 license. | | | |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I'm thinking the lexicon should focus on compliance, governance, and security terms used throughout the README.md and schemas vs specific frameworks and tools. I would suggest definitions like this be removed. WDYT?
Description
This PR defines a lexicon of terms for
gemara. The definitions should be referenced when using the terms to describe thegemaraproject. The content was adapted from the provided material on issue #189The "Do Not Use" column is for banned synonyms. Words in the "Do Not Use" column should never be used as synonyms for the associated terms.
Schema Changes
Schema Changes Made
schemas/layer-1.cue) changesschemas/layer-2.cue) changesschemas/layer-3.cue) changesschemas/layer-4.cue) changesSchema Change Details
Testing
gitleaksRelated Issues
Reviewer Hints
Do Not Usecolumn.