# Notes and Agreements

As the OSCAL Foundation's FedRAMP Technology Focus Group (TFG) reaches agreements as to the path forward, they are captured here. This is a work in progress. Once the group reaches an appropriate milestone, this will be consolidated and re-organized into more consumable guidance.

<div class="callout">
  
  **DRAFT** - Please review and provide feedback. Self-register via Login to leave comments.

</div>

---

See [Taxonomy](https://patterns.rufrisk.com/books/key-security-indicators-ksis/page/taxonomy)

See [Guiding Principles](https://patterns.rufrisk.com/books/key-security-indicators-ksis/page/guiding-principles)

---

# KSI Approach

- **KSI Statement Analysis**
  - Identify KSI goal(s)

- **KSI Data Requirements**:
  - **Intent**: _A simple, unambiguous status._ Typically Pass/Fail
  - **Decision Point**: Sampling or full coverage?
  - Identify evidence to collect in support of KSI goal(s)
  - Define evidence interpretation
    - Evidence type (count, true/false, setting)
    - Collection frequency
    - Evidence fidelity
    - Correlation
    - Thresholds
      - Could be more granular than just pass/fail
      - Example: Satisfactory, Degraded, Critical

- **Organizational Considerations**:
  - **Action Triggers**: Define the triggers for that system/org
    - Define required action(s) when triggered

- **KSI Techical Collection Approach**
  - Identify all evidence source/component
    - Identify the source format(s)
  - Define centralized evidence collection target
  - Define the automation required to acquire evidence from each source/component and deliver to centralied collection target
    - **Decision Point**: Evidence delivered _raw_ or _normalized_?

- **KSI Technical Interpretation Approach**
  - Apply data requirements/thresholds to produce _Findings_
    - Findings are continuously updating as new data is received and analyzed
  -  Raise action triggers when appropriate