Extract and analyze security controls from OSCAL catalogs, profiles, and SSPs...
Extract, analyze, and report on security controls from OSCAL documents including catalogs, profiles, and system security plans.
Use this skill when you need to:
Control extraction works only on user-provided OSCAL documents.
| Task | Required Document |
|---|---|
| List controls | Catalog or Profile JSON/YAML/XML |
| Get control text | Catalog with the control definitions |
| Analyze SSP controls | SSP document |
| Compare baseline | Both baseline profile AND SSP |
I need the OSCAL document to extract controls from.
For NIST 800-53 controls, you can:
1. Upload the catalog file, or
2. I can fetch from: https://raw.githubusercontent.com/usnistgov/oscal-content/main/nist.gov/SP800-53/rev5/json/NIST_SP-800-53_rev5_catalog.json
I cannot list controls from memory β compliance requires authoritative sources.
OSCAL security controls have this hierarchy:
Control Family (Group)
βββ Control (e.g., AC-1)
βββ Statement (requirement text)
βββ Guidance (implementation guidance)
βββ Parameters (configurable values)
βββ Parts (additional sections)
βββ Enhancements (sub-controls like AC-1(1))
| Family | Name | Description |
|---|---|---|
| AC | Access Control | User access management |
| AT | Awareness & Training | Security training |
| AU | Audit & Accountability | Logging and monitoring |
| CA | Assessment & Authorization | Security assessments |
| CM | Configuration Management | System configurations |
| CP | Contingency Planning | Disaster recovery |
| IA | Identification & Authentication | User identity |
| IR | Incident Response | Security incidents |
| MA | Maintenance | System maintenance |
| MP | Media Protection | Media handling |
| PE | Physical & Environmental | Physical security |
| PL | Planning | Security planning |
| PM | Program Management | Security program |
| PS | Personnel Security | Personnel controls |
| RA | Risk Assessment | Risk management |
| SA | System Acquisition | Development security |
| SC | System & Communications | Network security |
| SI | System & Information Integrity | Data integrity |
From Catalog:
catalog β groups β controls
From Profile:
profile β imports β include-controls
From SSP:
system-security-plan β control-implementation β implemented-requirements
For each control, extract:
Control parts include:
To extract statement text:
name="statement"prose field for textWhen analyzing controls, calculate:
Find all controls where ID starts with family prefix (e.g., "AC-")
Check properties for baseline-impact values:
Check implementation status:
When extracting controls, provide:
CONTROLS SUMMARY
================
Total Controls: X
Enhancements: Y
By Family:
- AC (Access Control): N controls
- AU (Audit): N controls
...
Control Details:
- AC-1: Access Control Policy and Procedures
Statement: [requirement text]
Guidance: [implementation guidance]
Enhancements: AC-1(1), AC-1(2)
When asked "What access control requirements are in this catalog?":
When asked "What controls are missing in this SSP?":