-
Notifications
You must be signed in to change notification settings - Fork 123
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
800-53 rev5 control title deficiencies #112
Comments
The table includes around 25 items, maybe half of which are errors in the source OSCAL. For the others, the spreadsheet-extractor XSLTs must be examined to rectify if they are failing. Use this opportunity also to document the spreadsheet extractor for future uses. |
@wendellpiez Can you analyze where the errors are occurring and create a checklist in this issue identifying the classes and quantities of errors that need to be fixed. We can use this to verify the result of your fixes after the repairs are made. |
Noting that errors, where they are found, tend to be in the neighborhood of punctuation such as / (solidus) and ( ) (parentheses). We could do some top-down inspection to help validate that we have them all. |
To look for (at least):
|
That only works if one anticipates Chicago style. The superior AP style uses spaces around the em dash.. |
Turns out that's not a problem anywhere in any case. 😎 |
WorksheetAC-20(3)Should this be "Non-organizationally-owned"? Otherwise I don't see an issue. Rev 5 PDF has "NON-ORGANIZATIONALLY OWNED SYSTEMS" (all caps) for the enhancement title (revised from Rev 4 "NON-ORGANIZATIONALLY OWNED SYSTEMS / COMPONENTS / DEVICES").
CM-7(4)Apparent lapse in profile spreadsheet extraction (enhancement title dropped after em dash).
CM-7(5)Apparent lapse in profile spreadsheet extraction (enhancement title dropped after em dash).
CP-9(7)Apparent lapse in profile spreadsheet extraction (enhancement title dropped after em dash).
IA-2Spreadsheet extractor un-capitalizes after open parenthesis? The same issue recurs in 13 enhancements when title is expanded.
IA-5(15)Requires correction in source.
IA-8(5)IA-8 title in current version has (correctly) "Identification and Authentication (Non-organizational Users)". I have no accounting for why 'PIV' might become 'PVI'.
PE-13(1)Apparent collapse of em dash to hyphen in spreadsheet extraction?
PE-13(2)Another apparent collapse of em dash to hyphen in spreadsheet extraction?
PE-19(1)Very strange variance in 800-53b spreadsheet? (A word promoted up from control text?)
PS-3(3)Very strange variance in 800-53b spreadsheet?
SA-4(7)Requires correction in source.
SA-9(8)Currently the catalog has "Processing and Storage Location — U.S. Jurisdiction". (This looks fine in the file sent with the bug report also.)
SA-10(2)Variance in 800-53b spreadsheet extraction? (word dropped).
SR-2(1)Requires correction in source.
Summary / crunchRequires correction in sourceIA-5(15) - "GSA" Variances in spreadsheet extractionScroll up for the details -
Look okay
|
…pdated Schematron name and value checker to run cleanly.
Current status: the single problem identified and confirmed in source data is corrected PR #137. With respect to reported lapses in spreadsheet extraction logic, let's make a spinoff issue to track any down? There is nothing to correct in this repository for those (and nothing to be done if we cannot confirm a cause). |
…hematron name and value checker to run cleanly.
The OSCAL content has been corrected and the NIST RMF team has been notified about the issues in the spreadsheets. |
…pdated Schematron name and value checker to run cleanly.
…hematron name and value checker to run cleanly.
…pdated Schematron name and value checker to run cleanly.
…pdated Schematron name and value checker to run cleanly.
Describe the bug
Errors in control titles (
/catalog//control/title
elements).See attached.
Who is the bug affecting?
Users of oscal-content.
What is affected by this bug?
Use of oscal-content to present control information.
When does this occur?
As of this writing.
How do we replicate the issue?
See attached.
{What are the steps to reproduce the behavior?
Perform a text comparison of control titles amongst the sources.
Expected behavior (i.e. solution)
Corrected control titles
Other Comments
XML conversions of the spreadsheets were used.
One class of errors is mishandled abbreviations/acronyms.
There are errors not only in the OSCAL content but in the spreadsheets (the OSCAL content can/could be correct).
Comparisons to the normative SP 800-53 rev5 PDF document rendition are of course not possible (because it is PDF and as well someone chose to CAPITALIZE ALL CONTROL ENHANCEMENT TITLES).
Attachment: table.zip
The text was updated successfully, but these errors were encountered: