You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
the Guide to OSCAL-based FedRAMP System Security Plans (SSP)
the FedRAMP SSP OSCAL Template (JSON or XML Format)
the FedRAMP OSCAL Validations
User Story
This reflects Stage 1A, SSP Completeness portion of the FedRAMP Automation Team's Constraint Management Strategy [Assess: FedRAMP only] for grouping and prioritizing constraint work.
Using the Legacy Word SSP Template as a reference, the FedRAMP Automation Team will work on SSP-related completeness checks that can be implemented via metaschema constraints in the following sequence and groupings:
The following SSP template topic areas are deferred pending modeling and analysis work:
11 Separation of Duties: Defer this until the Separation of Duties matrix is properly modeled.
Appendix Q Cryptographic Modules Table
10 Cryptographic Modules Implemented for Data At Rest (DAR)/Data In Transit (DIT)
The following SSP template topics will be generated, and will not have completeness checks:
Appendix J Control Implementation Summary (CIS) and Customer Responsibilities Matrix (CRM) Workbook
OSCAL based SSPs and POA&Ms are treated as separate artifacts. As such, Appendix O POA&M from the FedRAMP SSP Word template is not within the scope of SSP completeness checks and will instead be treated as a separate workstream under the constraint strategy.
Goals
SSP Completeness checks are defined, tested and documented
This is a ...
fix - something needs to be different
This relates to ...
User Story
This reflects Stage 1A, SSP Completeness portion of the FedRAMP Automation Team's Constraint Management Strategy [Assess: FedRAMP only] for grouping and prioritizing constraint work.
Using the Legacy Word SSP Template as a reference, the FedRAMP Automation Team will work on SSP-related completeness checks that can be implemented via metaschema constraints in the following sequence and groupings:
The following SSP template topic areas are deferred pending modeling and analysis work:
The following SSP template topics will be generated, and will not have completeness checks:
OSCAL based SSPs and POA&Ms are treated as separate artifacts. As such, Appendix O POA&M from the FedRAMP SSP Word template is not within the scope of SSP completeness checks and will instead be treated as a separate workstream under the constraint strategy.
Goals
SSP Completeness checks are defined, tested and documented
Task List
The text was updated successfully, but these errors were encountered: