# Workstreams

The OSCAL Foundation's FedRAMP TFG is currently focused on three workstreams realted to the FedRAMP PMO's Consolidated Rules 2026 (CR26):

- [**FedRAMP Published Artifacts**](https://patterns.rufrisk.com/books/fedramp-published-artifacts): Representation of the FedRAPM Rules (FRRs), Key Security Indicator (KSI) definitions, and Rev 5 Baselines in OSCAL Format. Intended to include capabilities for converting FedRAMP-published JSON to OSCAL.<br /><br />

- [**FedRAMP Deliverables**](https://patterns.rufrisk.com/books/fedramp-deliverables): Representaiton of the Certification Package Overview (CPO) and Security Decision Records (SDRs) in OSCAL Format. Possibly including capabilities for converting OSCAL to the FedRAMP-published schema files for these artifacts.<br /><br />

- [**KSI Automation**](https://patterns.rufrisk.com/books/key-security-indicators-ksis): Representaiton, process support and recommended practices for KSI source definitions, KSI automated collection tooling, KSI telemetry representation in OSCAL, and KSI-driven compliance/risk reporting in OSCAL.<br /><br />

- [**Vulnerability Evaluation and Reporting (VER)**](): Representation of vulnerability reporting in OSCAL.