Background
Aligned with [#1688] (https://github.com/usnistgov/OSCAL/issues/1688). See: Original HackMD
Organization
This document aims to capture a list of value streams for OSCAL adopters of how to use OSCAL models as part of my governance program. A value stream is a thematic collection of work items, varying in scope of work by quantity or quality (large epics to small issues), related to the same theme in that work.
[[The list is partial, not exhaustive. We would like to hear from readers and community members on ways they have found to use OSCAL models, together or separately, to accomplish their goals.]]
[[above 'my governance program'? Maybe as part of a risk management program? System security assurance program? etc. maybe it is intended to be 'any governance program'?]]