Overview
The OSCAL Foundation's FedRAMP TFG is currently focused on three active CR26 workstreams:
-
FedRAMP Published Artifacts: Representation of the FedRAPM Rules (FRRs), Key Security Indicator (KSI) definitions, and Rev 5 Baselines in OSCAL Format. Intended to include code for converting FedRAMP-published JSON to OSCAL.
SeeMapping: FedRAMP Rules → OSCALfor more information. -
FedRAMP
CertificationDeliverables: Representaiton of the Certification Package Overview (CPO) and Security Decision Records (SDRs) in OSCAL Format.IntendedPossiblytoincludinginclude codecapabilities for converting OSCAL to the FedRAMP-published schema files for these artifacts.
The following is a DRAFT depiction of how FedRAMP CR26 native artifacts overlay with OSCAL artifacts.
- KSI Automation: Representaiton, process support and recommended practices for KSI source definitions, KSI automated collection tooling, KSI telemetry representation in OSCAL, and KSI-driven compliance/risk reporting in OSCAL.
SeeKey Security Indicators (KSIs)for more information.
The following is a DRAFT depiction of how FedRAMP CR26 native artifacts overlay with OSCAL artifacts.
