openid / openid/fapi

FAPI2.0 OSCAL Profile

Open
#839 7 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

component: FAPI2: Security Profile migrated-from-bitbucket priority: minor type: task
Dominant language
HTML
Stars
3
Forks
3
PR merge metrics
No merged PRs in 30d

Description

Originally submitted by Damian Hickey (Damian Hickey) on 2026-01-29

Hi All,

I’ve been exploring the automated compliance documentation space which led me to https://pages.nist.gov/OSCAL/ and I was wondering if the group considered an FAPI2.0 OSCAL profile (perhaps against NIST 800-53) which would bridge the gap between the security profile and automated GRC/audit tooling? I’ve performed some initial investigation (and make no assertion it’s even feasible yet) but thought I’d reach out to the group first to see if anyone has explored this.

Thank you

Damian


Bitbucket status: open

Bitbucket origin: issue 851

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

No repository files or tests are identified. Start by reviewing the FAPI 2.0 requirements and the OSCAL documentation, then determine whether an OSCAL profile aligned with NIST 800-53 is feasible and define its scope. Done means the group has an agreed profile proposal and implementation boundaries.

Written by the indexing model from the issue text.

Assessment

Domain
documentation, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Quiet
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.