Skip to main content

New Page

As the OSCAL Foundation's FedRAMP Technology Focus Group (TFG) reaches agreements as to the path forward, they are captured here. This is a work in progress. Once the group reaches an appropriate milestone, this will be consolidated and re-organized into more consumable guidance.

WORK IN PROGRESS

KSI Definition Principles

  • KSI evidence is always quantative

  • KSI evidence should ultimately be pass/fail

    • We may find this isn't always prossible, but we want to strive for this
    • measurements may be other quantifiable data, such as % based, nouns, counts
    • Quantifiable data requires thresholds
    • thresholds tranlsate measurements to pass/fail
  • FRRs define the following roles relative to KSI definition:

    • CSP to define
    • Assessor to validate
    • PMO accecpts/rejects for certification
    • Agency accepts/rejects for authorization
  • KSI fidelity needs to be clarified

  • KSI must have a sample frequency (typical), trigger, or other timing definition

  • Need to be able to distinguish:

    • Data:
      • Direct hard data (hard collection, hard correlation rules)
      • Human generated
      • Agentic AI generated
    • Assertions:
      • Logic-based correlation and thresholds
      • Agentic AI judgement
      • Human judgement
  • Agentic AI requires identification of a responsible human.

    • In FedRAMP, defaults to system owner unless otherwise named.

Probabalistic vs Deterministic KSI Handling (AKA - Use of Agentic AI)

  • PMO has stated a desire to lean into Agentic AI
  • There is a great deal of variance among Agencies on the acceptability of security telemetry, that has been generated or analyzed by Agentic AI.
  • There must be a mechanism for clarifying probabalistic telemetry from deterministic.

KSI Approach

  • KSI Statement Analysis

    • Identify KSI goal(s)
  • KSI Data Requirements:

    • Intent: A simple, unambiguous status. Typically Pass/Fail
    • Decision Point: Sampling or full coverage?
    • Identify evidence to collect in support of KSI goal(s)
    • Define evidence interpretation
      • Evidence type (count, true/false, setting)
      • Collection frequency
      • Evidence fidelity
      • Correlation
      • Thresholds
        • Could be more granular than just pass/fail
        • Example: Satisfactory, Degraded, Critical
  • Organizational Considerations:

    • Action Triggers: Define the triggers for that system/org
      • Define required action(s) when triggered
  • KSI Techical Collection Approach

    • Identify all evidence source/component
      • Identify the source format(s)
    • Define centralized evidence collection target
    • Define the automation required to acquire evidence from each source/component and deliver to centralied collection target
      • Decision Point: Evidence delivered raw or normalized?
  • KSI Technical Interpretation Approach

    • Apply data requirements/thresholds to produce Findings
      • Findings are continuously updating as new data is received and analyzed
    • Raise action triggers when appropriate