Views:

Import and export custom compliance frameworks using OSCAL-formatted YAML files in Compliance Management.

Compliance Management supports importing and exporting custom compliance frameworks using Open Security Controls Assessment Language (OSCAL)-formatted YAML files. Importing frameworks eliminates the need to build frameworks from scratch. Exporting frameworks allows you to share and reuse standardized frameworks across different TrendAI Vision One™ instances.

Import a custom framework

  1. Go to Cyber Risk Exposure ManagementCyber Governance & Risk ComplianceCompliance Management.
  2. On the Overview tab, click Create custom framework and select Import framework.
  3. Upload an OSCAL-formatted YAML file.
    Note
    Note
    The uploaded file must be in OSCAL-compliant YAML format. The framework title, description, control families, and controls are parsed from the file content.
  4. Review the imported framework details, including the title, description, and control families.
  5. Click Save.
    The imported framework appears in your list of custom frameworks.

Export a custom framework

  1. Go to Cyber Risk Exposure ManagementCyber Governance & Risk ComplianceCompliance Management.
  2. On the Overview tab, locate the custom framework you want to export.
  3. Click the more button next to the framework and select Export framework.
  4. Save the exported OSCAL-formatted YAML file to your local machine.
    The exported file can be imported into another TrendAI Vision One™ instance to reuse the framework across environments.

Review imported controls

After importing a framework, verify that the controls were imported correctly.
  1. Go to Cyber Risk Exposure ManagementCyber Governance & Risk ComplianceCompliance Management.
  2. Click Settings and select Select Frameworks and Standards.
  3. Click the more button next to the custom framework and select Edit.
    The custom framework builder displays the imported control families and controls for review.
  4. Verify that the control families, controls, and mappings are correct.
Note
Note
You can also verify controls from the Overview tab. Click the custom framework and select Compliance Analysis, then click Check configurations to confirm that compliance results reflect the imported controls.