https://pages.nist.gov/OSCAL/
OSCAL - Open Security Controls Assessment Language
open securityoscalcontrolsassessmentlanguage
https://www.opensecurityarchitecture.org/blog/5/
Blog - Page 5 | Open Security Architecture
Updates and insights from the Open Security Architecture community.
blog pageopen securityarchitecture
https://opensecurityarchitecture.org/foundations/policy-templates/
Policy Templates | Open Security Architecture
Free NIST-mapped Information Security Policy and Acceptable Use Policy templates from Open Security Architecture.
policy templatesopen securityarchitecture
https://www.opensecurityarchitecture.org/patterns/sp-014/
Awareness and Training Pattern | Open Security Architecture
Security architecture for building and sustaining an effective security awareness and training program. Covers role-based training, phishing simulation,...
open securityawarenesstrainingpatternarchitecture
https://opensecurityarchitecture.org/frameworks/fips-140/
FIPS 140-3 Mappings | Open Security Architecture
FIPS 140-3 Security Requirements for Cryptographic Modules clause-to-control mappings. 11 clauses mapped to SP 800-53 controls.
open securityfipsmappingsarchitecture
https://opensecurityarchitecture.org/controls/si-17/
SI-17 - Fail-safe Procedures | Open Security Architecture
Implement the indicated fail-safe procedures when the indicated failures occur: [Assignment: organization-defined parameters].
fail safeopen securitysiproceduresarchitecture
https://www.opensecurityarchitecture.org/controls/ia-03/
IA-03 - Device Identification And Authentication | Open Security Architecture
The information system identifies and authenticates specific devices before establishing a connection.
device identificationopen securityiaauthenticationarchitecture
https://www.opensecurityarchitecture.org/controls/pt-05/
PT-05 - Privacy Notice | Open Security Architecture
privacy noticeopen securityptarchitecture
https://opensecurityarchitecture.org/controls/ac-17/
AC-17 - Remote Access | Open Security Architecture
The organization authorizes, monitors, and controls all methods of remote access to the information system.
remote accessopen securityarchitecture
https://www.elastic.co/blog/open-security-impact-elastic-ai-assistant
Open Security impact: Elastic AI Assistant | Elastic Blog
Learn how Elastic's commitment to Open Security increases accuracy, efficiency, and usability in the Elastic AI Assistant....
open securityai assistantimpactelasticblog
https://opensecurityarchitecture.org/controls/ma-07/
MA-07 - Field Maintenance | Open Security Architecture
Restrict or prohibit field maintenance on [Assignment: organization-defined parameters] to [Assignment: organization-defined parameters].
field maintenanceopen securityarchitecture
https://www.opensecurityarchitecture.org/controls/pl-10/
PL-10 - Baseline Selection | Open Security Architecture
Select a control baseline for the system.
open securityplbaselineselectionarchitecture
https://opensecurityarchitecture.org/foundations/links/231-security-metrics
Home | Open Security Architecture
Open Security Architecture - Reusable security patterns, control mappings, and capability models for proportionate, consistent, and traceable security...
home opensecurityarchitecture
https://opensecurityarchitecture.org/controls/au-05/
AU-05 - Response To Audit Processing Failures | Open Security Architecture
The information system alerts appropriate organizational officials in the event of an audit processing failure and takes the following additional actions:...
open securityauresponseprocessingfailures
https://opensecurityarchitecture.org/controls/sc-39/
SC-39 - Process Isolation | Open Security Architecture
Maintain a separate execution domain for each executing system process.
open securityscprocessisolationarchitecture
https://securitybrief.co.uk/story/cisco-mcafee-collaborate-open-security-platform
Cisco & McAfee collaborate on open security platform
A collaboration between Cisco and McAfee will share security incident and contextual information in real time in an effort to detect and stop threats.
open securityciscomcafeecollaborateplatform
https://opensecurityarchitecture.org/controls/sa-10/
SA-10 - Developer Configuration Management | Open Security Architecture
The organization requires that information system developers create and implement a configuration management plan that controls changes to the system during...
configuration managementopen securitysadeveloperarchitecture
https://opensecurityarchitecture.org/controls/cp-04/
CP-04 - Contingency Plan Testing And Exercises | Open Security Architecture
The organization: (i) tests and/or exercises the contingency plan for the information system [Assignment: organization-defined frequency, at least annually]...
contingency planopen securitycptestingexercises
https://www.opensecurityarchitecture.org/controls/ia-12/
IA-12 - Identity Proofing | Open Security Architecture
a. Identity proof users that require accounts for logical access to systems based on appropriate identity assurance level requirements as specified in...
identity proofingopen securityiaarchitecture
https://opensecurityarchitecture.org/about/privacy-policy/
Privacy Policy | Open Security Architecture
How we handle your data -- we collect very little and respect your privacy.
privacy policyopen securityarchitecture
https://www.opensecurityarchitecture.org/controls/ac-11/
AC-11 - Session Lock | Open Security Architecture
The information system prevents further access to the system by initiating a session lock after [Assignment: organization-defined time period] of inactivity,...
open securityacsessionlockarchitecture
https://www.opensecurityarchitecture.org/controls/sa-23/
SA-23 - Specialization | Open Security Architecture
Employ [Assignment: organization-defined parameters] on [Assignment: organization-defined parameters] supporting mission essential services or functions to...
open securitysaspecializationarchitecture
https://blog.radicallyopensecurity.com/
Radically Open Security Blog //
Radically Open Security Blog,
radically open securityblog
https://www.opensecurityarchitecture.org/controls/sc-35/
SC-35 - External Malicious Code Identification | Open Security Architecture
Include system components that proactively seek to identify network-based malicious code or malicious websites.
malicious codeopen securityscexternalidentification
https://www.opensecurityarchitecture.org/frameworks/cmmc-2/
CMMC 2.0 Mappings | Open Security Architecture
Cybersecurity Maturity Model Certification 2.0 Level 2 clause-to-control mappings. 14 clauses mapped to SP 800-53 controls.
open securitycmmcmappingsarchitecture
https://www.opensecurityarchitecture.org/controls/ir-08/
IR-08 - Incident Response Plan | Open Security Architecture
a. Develop an incident response plan that: 1. Provides the organization with a roadmap for implementing its incident response capability; 2. Describes the...
incident response planopen securityirarchitecture
https://www.opensecurityarchitecture.org/controls/sc-13/
SC-13 - Use Of Cryptography | Open Security Architecture
For information requiring cryptographic protection, the information system implements cryptographic mechanisms that comply with applicable laws, Executive...
open securityscusecryptographyarchitecture
https://opensecurityarchitecture.org/controls/ac-18/
AC-18 - Wireless Access Restrictions | Open Security Architecture
The organization: (i) establishes usage restrictions and implementation guidance for wireless technologies; and (ii) authorizes, monitors, controls wireless...
wireless accessopen securityrestrictionsarchitecture
https://stenciltown.omnigroup.com/stencils/open-security-architecture/
Stenciltown - Open Security Architecture
A collection of free-forever stencils for OmniGraffle with creative commons licenses. Share your own and bookmark your favorites.
open securitystenciltownarchitecture
https://opensecurityconference.org/support/sponsorship/
Open Security Conference - Sponsorship
Welcome to the Open Security Conference (osco), the people-centred international gathering for everyone interested in cybersecurity. Join us 5-8 November 2026...
open securityconferencesponsorship
https://www.opensecurityarchitecture.org/controls/si-02/
SI-02 - Flaw Remediation | Open Security Architecture
The organization identifies, reports, and corrects information system flaws.
open securitysiflawremediationarchitecture
https://www.opensecurityarchitecture.org/blog/secure-scrum/
Secure Scrum | Open Security Architecture
For 10 years agile development has been finding more and more followers and practitioners. It seems like a sure bet that SCRUM will be the leading process...
open securitysecurescrumarchitecture
https://www.opensecurityarchitecture.org/controls/sc-07/
SC-07 - Boundary Protection | Open Security Architecture
The information system monitors and controls communications at the external boundary of the information system and at key internal boundaries within the system.
open securityscboundaryprotectionarchitecture
https://www.opensecurityarchitecture.org/blog/4/
Blog - Page 4 | Open Security Architecture
Updates and insights from the Open Security Architecture community.
blog pageopen securityarchitecture
https://opensecurityarchitecture.org/patterns/sp-015/
Secure Remote Working | Open Security Architecture
Comprehensive remote and hybrid working security pattern covering endpoint hardening, ZTNA and VPN architectures, BYOD and corporate device management, split...
secure remoteopen securityworkingarchitecture
https://www.opensecurityarchitecture.org/frameworks/mas-trm/
MAS TRM Mappings | Open Security Architecture
MAS Technology Risk Management Guidelines clause-to-control mappings. 14 clauses mapped to SP 800-53 controls.
open securitymastrmmappingsarchitecture
https://opensecurityarchitecture.org/controls/sc-09/
SC-09 - Transmission Confidentiality | Open Security Architecture
The information system protects the confidentiality of transmitted information.
open securitysctransmissionconfidentialityarchitecture
https://www.opensecurityarchitecture.org/controls/cm-02/
CM-02 - Baseline Configuration | Open Security Architecture
The organization develops, documents, and maintains a current baseline configuration of the information system.
open securitycmbaselineconfigurationarchitecture
https://www.deepwatch.com/deepwatch-unlocks-new-capabilities-and-increased-flexibility-with-its-open-security-data-architecture/
Deepwatch Introduces its Open Security Data Architecture
Mar 5, 2024 - Deepwatch introduces its Open Security Data Architecture to unlock new capabilities and flexibility, delivering optimal outcomes for cyber resilience.
open securitydeepwatchintroducesdataarchitecture
https://opensecurityarchitecture.org/patterns/sp-034/
Cyber Resilience | Open Security Architecture
Enterprise architecture pattern for designing systems that survive cyber attacks, maintain critical operations under degraded conditions, and recover rapidly....
cyber resilienceopen securityarchitecture
https://www.opensecurityarchitecture.org/patterns/sp-032/
Modern Authentication | Open Security Architecture
Enterprise authentication architecture pattern covering directory services, federation, and token-based authentication using OIDC, OAuth 2.0, and JWT. Provides...
open securitymodernauthenticationarchitecture
https://opensecuritycontroller.org/
Open Security Controller
open securitycontroller
https://www.opensecurityarchitecture.org/controls/pl-11/
PL-11 - Baseline Tailoring | Open Security Architecture
Tailor the selected control baseline by applying specified tailoring actions.
open securityplbaselinetailoringarchitecture
https://www.opensecurityarchitecture.org/controls/pt-01/
PT-01 - Policy and Procedures | Open Security Architecture
policy and proceduresopen securityptarchitecture
https://opensecurityarchitecture.org/controls/sc-37/
SC-37 - Out-of-band Channels | Open Security Architecture
Employ the following out-of-band channels for the physical delivery or electronic transmission of [Assignment: organization-defined parameters] to [Assignment:...
out of bandopen securityscchannelsarchitecture
https://www.opensecurityarchitecture.org/controls/au-14/
AU-14 - Session Audit | Open Security Architecture
a. Provide and implement the capability for [Assignment: organization-defined users or roles] to [Selection (one or more): record; view; hear; log] the content...
open securityausessionarchitecture
https://opensecurityarchitecture.org/patterns/sp-042/
Third Party Risk Management | Open Security Architecture
Architecture pattern for managing security risk from third party vendors, service providers, and supply chain dependencies. Covers vendor security assessment...
third party risk managementopen securityarchitecture
https://opensecurityarchitecture.org/controls/ac-24/
AC-24 - Access Control Decisions | Open Security Architecture
Establish procedures to ensure [Assignment: organization-defined access control decisions] are applied to each access request prior to access enforcement.
access controlopen securitydecisionsarchitecture
https://2025.opensecurityconference.org/coc
Open Security Conference - Code of Conduct
Welcome to the Open Security Conference (osco), the people-centred international gathering for everyone interested in cybersecurity. Join us 2-5 October 2025...
open securityconferencecodeconduct
https://www.opensecurityarchitecture.org/patterns/sp-011/
Cloud Computing Pattern | Open Security Architecture
Security architecture for organisations consuming or providing cloud services, addressing the shared responsibility model, data sovereignty, identity...
cloud computingopen securitypatternarchitecture
https://www.opensecurityarchitecture.org/about/who-uses-osa/
Who uses OSA? | Open Security Architecture
Security professionals, consultants, students, and academics worldwide rely on OSA patterns and controls.
open securityusesosaarchitecture
https://www.opensecurityarchitecture.org/attack/
MITRE ATT&CK Coverage Matrix | Open Security Architecture
open securitymitreattckcoverage
https://opensecurityarchitecture.org/controls/cp-01/
CP-01 - Contingency Planning Policy And Procedures | Open Security Architecture
The organization develops, disseminates, and periodically reviews/updates: (i) a formal, documented, contingency planning policy that addresses purpose, scope,...
policy and procedurescontingency planningopen securitycparchitecture
https://cdnapisec.kaltura.com/html5/html5lib/v2.101/mwEmbedFrame.php/p/684682/uiconf_id/31013851/entry_id/1_e861yoyu?wid=_684682&iframeembed=true&playerId=kaltura_player_1684176576&entry_id=1_e861yoyu&flashvars%5BstreamerType%5D=auto
Open Security Controls Assessment Language 4th Annual OSCAL Conference and Workshop
open securitycontrolsassessmentlanguage
https://www.opensecurityarchitecture.org/controls/pm-28/
PM-28 - Risk Framing | Open Security Architecture
a. Identify and document: 1. Assumptions affecting risk assessments, risk responses, and risk monitoring; 2. Constraints affecting risk assessments, risk...
open securitypmriskframingarchitecture
https://www.opensecurityarchitecture.org/blog/declassified-1970-us-dod-cybersecurity-document-still-relevant/
Declassified 1970 US DoD cybersecurity document still relevant | Open Security Architecture
Just read a great article on Ars Technica covering a 1970 DoD analysis of computer system vulnerabilities...
us dodopen securitycybersecurity
https://www.opensecurityarchitecture.org/controls/ac-15/
AC-15 - Automated Marking | Open Security Architecture
The information system marks output using standard naming conventions to identify any special dissemination, handling, or distribution instructions.
open securityacautomatedmarkingarchitecture
https://opensecurityarchitecture.org/controls/si-10/
SI-10 - Information Accuracy, Completeness, Validity, And Authenticity | Open Security Architecture
The information system checks information for accuracy, completeness, validity, and authenticity.
open securitysiinformationaccuracycompleteness
https://opensecurityarchitecture.org/library/0802control-catalogue/32-08-02-ac-10
Home | Open Security Architecture
Open Security Architecture - Reusable security patterns, control mappings, and capability models for proportionate, consistent, and traceable security...
home opensecurityarchitecture
https://www.opensecurityarchitecture.org/controls/pe-12/
PE-12 - Emergency Lighting | Open Security Architecture
The organization employs and maintains automatic emergency lighting that activates in the event of a power outage or disruption and that covers emergency exits...
emergency lightingopen securityarchitecture
https://www.opensecurityarchitecture.org/controls/pe-21/
PE-21 - Electromagnetic Pulse Protection | Open Security Architecture
Employ [Assignment: organization-defined parameters] against electromagnetic pulse damage for [Assignment: organization-defined parameters].
electromagnetic pulseopen securityprotectionarchitecture
https://www.opensecurityarchitecture.org/frameworks/apra-cps-234/coverage/
APRA CPS 234 Coverage Analysis | Open Security Architecture
SP 800-53 coverage analysis for APRA Prudential Standard CPS 234 Information Security. 11 clauses analysed, 79% average coverage.
coverage analysisopen securityapracpsarchitecture
https://2024.opensecurityconference.org/support/
Open Security Conference - Support Us
Welcome to the Open Security Conference (osco), the people-centred international gathering for everyone interested in cybersecurity. Join us 4-6 October 2024...
open securityconference supportus
https://www.opensecurityarchitecture.org/frameworks/bot-cyber/coverage/
BOT Cyber Resilience Coverage Analysis | Open Security Architecture
SP 800-53 coverage analysis for Bank of Thailand Cyber Resilience Guidelines for Financial Institutions. 26 clauses analysed, 77% average coverage.
cyber resiliencecoverage analysisopen securitybotarchitecture
https://www.opensecurityarchitecture.org/controls/sc-43/
SC-43 - Usage Restrictions | Open Security Architecture
Establish usage restrictions and implementation guidelines for the following system components: [Assignment: organization-defined parameters] ; and Authorize,...
usage restrictionsopen securityscarchitecture
https://www.opensecurityarchitecture.org/blog/cloud-computing-research/
Cloud Computing research | Open Security Architecture
I've been spending time researching the Cloud Computing pattern in the last week or so and I must say I am learning a lot. I've been a big fan of Nick Carr...
cloud computingopen securityresearcharchitecture
https://opensecurityarchitecture.org/attack/?pattern=SP-035
MITRE ATT&CK Coverage Matrix | Open Security Architecture
open securitymitreattckcoverage
https://www.amd.com/en/blogs/2024/amd-s-commitment-to-open-security-technologies-in-.html
The AMD Commitment to Open Security Technologies in the Data Center
Expanding the Horizon of Data Center Security In recent years, the complexity of data center security has surged, presenting new challenges and opportunities....
open securityin dataamdcommitmenttechnologies
https://www.opensecurityarchitecture.org/controls/cm-13/
CM-13 - Data Action Mapping | Open Security Architecture
Develop and document a map of system data actions.
action mappingopen securitycmdataarchitecture
https://opensecurityarchitecture.org/foundations/
Foundations | Open Security Architecture
Core concepts and principles underlying the Open Security Architecture framework.
open securityfoundationsarchitecture
https://opensecurityarchitecture.org/library/0802control-catalogue/64-08-02-sc-04
Home | Open Security Architecture
Open Security Architecture - Reusable security patterns, control mappings, and capability models for proportionate, consistent, and traceable security...
home opensecurityarchitecture
https://www.opensecurityarchitecture.org/controls/cp-09/
CP-09 - Information System Backup | Open Security Architecture
The organization conducts backups of user-level and system-level information (including system state information) contained in the information system...
information systemopen securitycpbackuparchitecture
https://www.uml.edu/news/press-releases/2025/socrelease100725.aspx
UMass Lowell to Open Security Operations Center | News
security operations centerumass lowellopennews
https://www.opensecurityarchitecture.org/controls/
Control Catalogue | Open Security Architecture
NIST 800-53 Rev 5 control catalogue with mappings to ISO 27001, CIS Controls, NIST CSF, and more.
open securitycontrolcataloguearchitecture
https://www.opensecurityarchitecture.org/controls/ac-25/
AC-25 - Reference Monitor | Open Security Architecture
Implement a reference monitor for [Assignment: organization-defined access control policies] that is tamperproof, always invoked, and small enough to be...
open securityacreferencemonitorarchitecture
https://opensecurityarchitecture.org/controls/sc-13/
SC-13 - Use Of Cryptography | Open Security Architecture
For information requiring cryptographic protection, the information system implements cryptographic mechanisms that comply with applicable laws, Executive...
open securityscusecryptographyarchitecture
https://www.opensecurityarchitecture.org/frameworks/ferc-cip/coverage/
FERC CIP Orders Coverage Analysis | Open Security Architecture
SP 800-53 coverage analysis for FERC Orders Directing NERC CIP Standard Development. 8 clauses analysed, 70% average coverage.
coverage analysisopen securityfercciporders
https://www.opensecurityarchitecture.org/controls/pm-23/
PM-23 - Data Governance Body | Open Security Architecture
Establish a Data Governance Body consisting of [Assignment: organization-defined roles] with [Assignment: organization-defined responsibilities].
data governanceopen securitypmbodyarchitecture
https://noxsystems.com/tag/open-security-architecture-2/
Open Security Architecture Archive - NOX SYSTEMS | Security beyond limits
open securityarchitecturearchivenoxsystems
https://www.opensecurityarchitecture.org/controls/pm-06/
PM-06 - Measures of Performance | Open Security Architecture
Develop, monitor, and report on the results of information security and privacy measures of performance.
open securitypmmeasuresperformancearchitecture
https://www.opensecurityarchitecture.org/controls/sr-12/
SR-12 - Component Disposal | Open Security Architecture
open securitysrcomponentdisposalarchitecture
https://www.prosegur.co.uk/security/events/mutua-madrid-open
Mutua Madrid Open | Security Events | Prosegur UK
Discover our security solutions at the Mutua Madrid Open, Prosegur UK.
mutua madrid opensecurity eventsproseguruk
https://www.opensecurityarchitecture.org/controls/si-11/
SI-11 - Error Handling | Open Security Architecture
The information system identifies and handles error conditions in an expeditious manner without providing information that could be exploited by adversaries.
error handlingopen securitysiarchitecture
https://opensecurityarchitecture.org/frameworks/doe-c2m2/
DOE C2M2 v2.1 Mappings | Open Security Architecture
DOE Cybersecurity Capability Maturity Model v2.1 clause-to-control mappings. 10 clauses mapped to SP 800-53 controls.
open securitydoemappingsarchitecture
https://www.opensecurityarchitecture.org/controls/ac-13/
AC-13 - Supervision And Review -- Access Control | Open Security Architecture
The organization supervises and reviews the activities of users with respect to the enforcement and usage of information system access controls.
access controlopen securitysupervisionreviewarchitecture
https://www.opensecurityarchitecture.org/blog/updated-icon-pack/
Updated icon pack | Open Security Architecture
There is a new icon pack available (11.02) that includes the icons created for the Industrial Control Systems pattern.
icon packopen securityupdatedarchitecture
https://opensecurityarchitecture.org/
Home | Open Security Architecture
Open Security Architecture - Reusable security patterns, control mappings, and capability models for proportionate, consistent, and traceable security...
home opensecurityarchitecture
https://www.opensecurityarchitecture.org/controls/pe-11/
PE-11 - Emergency Power | Open Security Architecture
The organization provides a short-term uninterruptible power supply to facilitate an orderly shutdown of the information system in the event of a primary power...
emergency poweropen securityarchitecture
https://www.opensecurityarchitecture.org/frameworks/cbn-csf/
CBN CSF Mappings | Open Security Architecture
CBN Risk-Based Cybersecurity Framework for DMBs and PSBs clause-to-control mappings. 25 clauses mapped to SP 800-53 controls.
open securitycbncsfmappingsarchitecture
https://www.opensecurityarchitecture.org/controls/ca-03/
CA-03 - Information System Connections | Open Security Architecture
The organization authorizes all connections from the information system to other information systems outside of the accreditation boundary through the use of...
information systemopen securitycaconnectionsarchitecture
https://2024.opensecurityconference.org/open-space/
Open Security Conference - Open Space
Welcome to the Open Security Conference (osco), the people-centred international gathering for everyone interested in cybersecurity. Join us 4-6 October 2024...
open securityconferencespace
https://www.opensecurityarchitecture.org/api/
API Documentation | Open Security Architecture
REST API for accessing OSA security patterns, NIST 800-53 controls, and compliance framework mappings
api documentationopen securityarchitecture
https://www.opensecurityarchitecture.org/controls/sa-02/
SA-02 - Allocation Of Resources | Open Security Architecture
The organization determines, documents, and allocates as part of its capital planning and investment control process, the resources required to adequately...
open securitysaallocationresourcesarchitecture
https://crosscon.eu/
Cross-platform Open Security Stack for Connected Devices | Crosscon
cross platformopen securityconnected devicesstack
https://www.opensecurityarchitecture.org/controls/au-01/
AU-01 - Audit And Accountability Policy And Procedures | Open Security Architecture
The organization develops, disseminates, and periodically reviews/updates: (i) a formal, documented, audit and accountability policy that addresses purpose,...
accountability policyopen securityauproceduresarchitecture
https://opensecurityconference.org/location/
Open Security Conference - Location
Welcome to the Open Security Conference (osco), the people-centred international gathering for everyone interested in cybersecurity. Join us 5-8 November 2026...
open securityconferencelocation
https://www.opensecurityarchitecture.org/controls/pm-20/
PM-20 - Dissemination of Privacy Program Information | Open Security Architecture
Maintain a central resource page on the organization's principal public website that serves as a central source of information for the organization's privacy...
privacy programopen securitypmdisseminationinformation
https://www.opensecurityarchitecture.org/patterns/sp-046/
External Attack Surface Management | Open Security Architecture
Comprehensive pattern for discovering, monitoring, and managing an organisation's internet-facing digital assets. Covers automated asset discovery, DNS and...
external attack surfaceopen securitymanagementarchitecture
https://www.opensecurityarchitecture.org/controls/pe-18/
PE-18 - Location Of Information System Components | Open Security Architecture
The organization positions information system components within the facility to minimize potential damage from physical and environmental hazards and to...
information systemopen securitylocationcomponentsarchitecture
https://www.opensecurityarchitecture.org/controls/sa-04/
SA-04 - Acquisitions | Open Security Architecture
The organization includes security requirements and/or security specifications, either explicitly or by reference, in information system acquisition contracts...
open securitysaacquisitionsarchitecture