December 9, 2025


Episode 20


My Personal Level Up: 

Cracking the Code of OSCAL's Technical Architecture



Author: Carl Markowski

Risk management is a part of cybersecurity that many professionals either love or despise. Now, this is not without reason, and that stems from the tired, yet accurate, stereotypes that have plagued the Risk Management Framework (RMF) for years. These stereotypes include the reality of endless paperwork, the cost of “extremely time-consuming” processes, and the resulting burden of “immediately outdated and inaccurate information.” The evolution of this methodology has been notoriously slow and ineffective, a problem that can only be fixed by motivated cyber engineers who aren't afraid of a challenge.

Who Am I?

Before tackling OSCAL (Open Security Control Assessment Language), you’re probably wondering, “Who is this guy and why is he doing this?” Hello, my name is Carl Markowski, and I am an Associate Cyber Engineer at Dark Wolf Solutions with just under half a decade of experience in the industry. I am a United States Marine Corps veteran, having served as a Data System Administrator with 1st Battalion 7th Marines (Oohrah to any Marines reading this!). I also recently graduated from the University of Colorado, Colorado Springs with a bachelor’s degree in Computer Science. 

Ever since serving as a system administrator, I have been fascinated with cybersecurity. This led me to pursue a career with two simple guiding hopes: One, make a genuine difference in the industry; and Two, be a forever student. These two guiding principles are the “Why” to this journey and will help fuel my desire to break through the inevitable roadblocks in this journey.