User Story:
As an OSCAL content developer, I need to have NIST SP 800-60 Volume II information types available in OSCAL format so that I can properly categorize information systems according to FIPS 199 security categorization requirements.
Goals:
Add a complete OSCAL 1.1.2 catalog containing all 171 information types from NIST SP 800-60 Volume II Revision 1 (Guide for Mapping Types of Information and Information Systems to Security Categories).
This catalog will include:
- 77 Management and Support Information Types (C.x.x.x series)
- 94 Mission-Based Information Types (D.x.x series)
- Proper FIPS 199 impact level assignments (Confidentiality, Integrity, Availability)
- Full metadata including DOI reference to the official NIST publication
- Comprehensive README documentation
This fills a gap in the OSCAL content repository, as SP 800-60 is a foundational document for federal information security but is not currently available in OSCAL format.
Dependencies:
None. This is a new contribution that adds content without modifying existing files.
Acceptance Criteria
User Story:
As an OSCAL content developer, I need to have NIST SP 800-60 Volume II information types available in OSCAL format so that I can properly categorize information systems according to FIPS 199 security categorization requirements.
Goals:
Add a complete OSCAL 1.1.2 catalog containing all 171 information types from NIST SP 800-60 Volume II Revision 1 (Guide for Mapping Types of Information and Information Systems to Security Categories).
This catalog will include:
This fills a gap in the OSCAL content repository, as SP 800-60 is a foundational document for federal information security but is not currently available in OSCAL format.
Dependencies:
None. This is a new contribution that adds content without modifying existing files.
Acceptance Criteria
nist.gov/SP800-60/v2r1/