oscal-compass-lab
- 18 skills
- 0 followers
- 19 hours ago last updated
- ▌ Trestle Poam · oscal-compass-lab bundleUse this skill for the OSCAL Plan of Action and Milestones (POA&M) model in Compliance Trestle. Use it for POA&M, plan of action, milestones, remediation, findings tracking, and risk management. Use it to manage security finding remediation workflows.
- ▌ Trestle Workspace · oscal-compass-labUse this skill for Compliance Trestle workspace structure, init, and directory conventions. Use it for trestle workspaces, directory layout, .trestle config, and model directories. Use it to set up and organize an OSCAL compliance workspace.
- ▌ Trestle Assessment · oscal-compass-lab bundleUse this skill for OSCAL assessment plans and assessment results models in Compliance Trestle. Use it for assessment plans, assessment results, security assessments, SAP, SAR, assessment activities, findings, observations, or assessment-related OSCAL models.
- ▌ Trestle Governance · oscal-compass-labUse this skill for the Compliance Trestle document governance system. The system checks document structure and YAML headers. Use it for document governance, header checks, template validation, governed headings, and governed folders. Use it for trestle author docs, headers, folders, template setup, or CI/CD document validation.
- ▌ Trestle Validation · oscal-compass-labUse this skill for Compliance Trestle validation, common errors, and troubleshooting. Use it for validation errors, trestle validate failures, and OSCAL schema checks. Use it to fix compliance document issues or to troubleshoot trestle problems.
- ▌ Trestle Task System · oscal-compass-labUse this skill for the Compliance Trestle task system for data conversion and transformation. Use it for CSV import, XLSX import, XCCDF results, Tanium results, and CIS benchmarks. Use it for config.ini task configuration, trestle tasks, or conversion of scan results to assessment results.
- ▌ Trestle Oscal Models · oscal-compass-labUse this skill for OSCAL model types, their relationships, and how Compliance Trestle manages them. Use it for OSCAL documents, model types, catalogs, profiles, SSPs, and component definitions. Use it when users ask how compliance models relate to each other.
- ▌ Trestle Jinja Templating · oscal-compass-labUse this skill for the Compliance Trestle Jinja2 templating system for compliance documents. Use it for Jinja templates, document generation from OSCAL data, and custom trestle Jinja tags. Tags include mdsection_include, md_clean_include, and md_datestamp. Filters include as_list, get_party, parties_for_role, and diagram_href. Use it for SSP document rendering, lookup tables, or bracket formatting.
- ▌ Import Legacy Ssp · oscal-compass-labImport a legacy SSP, PDF, DOCX, or Markdown package into a traceable OSCAL Document Workbench workspace using extraction, source mapping, Trestle bootstrap, and validation.
- ▌ Workspace Validate · oscal-compass-labValidate the current Compliance Trestle workspace with trestle validate, report failures clearly, and recommend fixes using the validation assistant workflow.
- ▌ Trestle Authoring Workflow · oscal-compass-labUse this skill for the Compliance Trestle authoring workflow. The workflow is the generate-edit-assemble cycle that converts OSCAL documents to markdown and back. Use it for authoring catalogs, profiles, SSPs, or component definitions. Use it for editing control markdown, YAML headers, or the roundtrip workflow between JSON and markdown.
- ▌ Trestle Compliance Pipeline · oscal-compass-lab bundleUse this skill for end-to-end compliance pipelines with Compliance Trestle. Topics include GRC personas, artifact ownership, multi-repository coordination, two-phase component definition authoring, CI/CD pipeline integration, and the Compliance-to-Policy (C2P) bridge. Use it for compliance pipelines, personas, artifact ownership, multi-repo workflows, component definition dual-mapping (control-to-rule, rule-to-check), C2P, or end-to-end workflow design.
- ▌ Review Oscal Mappings · oscal-compass-labReview source-to-OSCAL mappings, triage needs_review rows, and update the review queue before treating generated OSCAL as ready for stakeholders.
- ▌ Validate Oscal Package · oscal-compass-labValidate an OSCAL package or Compliance Trestle workspace and produce a validation report, failing loudly when required tools are missing.
- ▌ Trestle Control Implementation · oscal-compass-labUse this skill to write control implementation responses, rules, parameters, and component-level responses. Use it for inheritance and leveraged SSPs in Compliance Trestle. Use it for control responses, implementation status, rules, parameters, component definitions, SSP implementation details, or compliance documentation content.
- ▌ Oscal Document Engineering · oscal-compass-lab bundleConvert, validate, and maintain OSCAL documents from legacy SSP/PDF/DOCX/Markdown source material.
- ▌ Compliance Trestle Engineering · oscal-compass-lab bundleUse Compliance Trestle to manage OSCAL catalogs, profiles, component definitions, SSPs, markdown assembly, validation, and source-traceable updates from legacy compliance documents.
- ▌ Oscal Document Workbench Expert · oscal-compass-labConvert legacy SSP/PDF/DOCX source material into traceable, validated OSCAL workspaces with Compliance Trestle and OSCAL CLI.