Skip to main content

FedRAMP System Security Plan (SSP)


Adopting OSCAL for SSP Representation

OSCAL Requirements

All OSCAL Core Requirements must be met for all OSCAL artifacts. This chapter contains informat...

Title Page, Prepared by/for, Approvers

Sections 1 - 11

Appendices A - Q

Appendicies Overview

Most attachments required by FedRAMP are called out in the NIST SP 800-53 controls appearning in ...

Appendix A: FedRAMP Security Controls

See the FedRAMP Security Controls chapter.

Appendix B: Related Acronyms

There is no OSCAL construct for representing an acronyms list. Attach a document (e.g., Word, Exc...

Appendix C: Security Policies and Procedures

See Control Response: Policies and Procedures.

Appendix D: User Guide

This needs work that may have been completed elsewhere and nees to be moved into here. This ...

Appendix E: Digital Identity Level (DIL) Determination

The Digital Identity Level (DIL) is represented on the page below. Within system-characteristics...

Appendix F: Rules of Behavior (RoB)

This needs work that may have been completed elsewhere and nees to be moved into here. This ...

Appendix G: Information System Contingency Plan (ISCP)

This needs work that may have been completed elsewhere and nees to be moved into here. This ...

Appendix H: Configuration Management Plan (CMP)

This needs work that may have been completed elsewhere and nees to be moved into here. This ...

Appendix I: Incident Response Plan (IRP)

This needs work that may have been completed elsewhere and nees to be moved into here. This ...

Appendix J: CIS and CRM Workbook

The FedRAMP Control Information Summary (CIS) and Customer Responsibility Matrix (CRM) are derive...

Appendix K: FIPS-199 Worksheet

The system's overall FIPS-199 impact level is determined primarily by the sensitivity of the info...

Appendix L: CSO-Specific Required Laws and Regulations

Needs Work Content cleanup YAML Example For MVP: attach a Word or PDF document enumerating t...

Appendix M: Integrated Inventory Workbook

See Inventory Approaches for guidance.

Appendix N: Continuous Monitoring Plan

This needs work that may have been completed elsewhere and nees to be moved into here. This ...

Appendix O: POA&M

See the FedRAMP POA&M book.

Appendix P: Supply Chain Risk Management Plan (SCRMP)

This needs work that may have been completed elsewhere and nees to be moved into here. This ...

Appendix Q: Cryptographic Modules

Cryptographic Modules Implemented for Data-in-Transit (DIT) OSCAL's component model treats indepe...

System Components and Inventory

FedRAMP Security Controls

Control Response: Approaches

OSCAL offers a great deal of flexibility for controls responses. To balance consistency, interope...

Control Response: Flat Approach

The flat approach to control responses is only intended as a starting point for service providers...

Control Response: Normalized Approach

The normalized approach is prefered. Organizations starting new with no legacy SSP content should...

Responding to Control Baselines

OSCAL references controls in baselines and catalogs. The statements are not duplicated into an O...

Responsible Roles

Every control should have one or more responsible roles identified. In OSCAL, there are three po...

Parameter Assignments

Representation If a FedRAMP control has one or more parameters, add a set-parameters array Withi...

Implementaiton Status

FedRAMP only accepts only one of five values for implementation-status: implemented, partial, pla...

Control Origination

FedRAMP accepts only one of five values for control-origination: sp-corporate, sp-system, custome...

Responding By Component

OSCAL SSPs represent control responses in control-implementation / implemented-requirements / st...

Control Implementation Statements

Typically, the controls in the FedRAMP baselines have lettered parts (a., b., etc.). A few only h...

Control Response: Policies, Procedures, Plans, RoB, and Guides

Most FedRAMP-required attachments derive their requirement from one or more NIST SP 800-53 contro...

Inheritence and Customer Responsibilities

For systems that may be leveraged, OSCAL enables a robust mechanism for providing both inheritanc...

Citing Control Statements

OSCAL SSPs cite OSCAL baseline statement identifiers when representing control implementation res...