OSCAL

The Open Security Controls Assessment Language, a NIST machine-readable format for controls, assessments and evidence, used here as the format for audit-ready evidence 1.

Developed in
ch. 05, Pattern: Machine-Readable Evidence (OSCAL)
Chapters
ch. 04, The Stack · ch. 05, Patterns · ch. 10, Reading List
Source
1 numbered reference, listed below

Where it is used

15 chapters of the Body of Knowledge use the term. Each link opens the first section that does.

Patterns that use this term

12 pattern pages use the term; the 10 that use it most:

Sources

  1. [1] NIST AI Risk Management Framework 1.0 (Govern, Map, Measure, Manage); OSCAL. NIST. 2023. https://www.nist.gov/itl/ai-risk-management-framework (verified: primary)

Definitions of legal terms paraphrase the cited text, which governs. Dated statements are as of .

Cite this term

García Aibar, J. (2026). OSCAL. In AI Governance Engineering: The Thesis & Body of Knowledge (v0.5.0), Glossary. https://doi.org/10.5281/zenodo.22956197. https://aigovernanceengineer.com/glossary/oscal. CC BY 4.0

BibTeX

@misc{aige2026oscal,
  author  = {Jorge García Aibar},
  title   = {{OSCAL}},
  note    = {Glossary, AI Governance Engineering: The Thesis \& Body of Knowledge, version 0.5.0},
  year    = {2026},
  doi     = {10.5281/zenodo.22956197},
  url     = {https://aigovernanceengineer.com/glossary/oscal}
}