Skip to main content

Recently Updated Pages

Comments Summary

Reports

:root { --accent: #2d6be4; --accent-dim: #e8effe; --border: #dde1e9; --surface2: #f0f2f5; --muted...

Updated 2 hours ago by Brian Ruf

Defining Allowed Values

Overview Metaschema Authoring Principles

This page is still under development. The <allowed-values> assembly provides a consistent and una...

Updated 2 months ago by Brian Ruf

Components

System Security Plans

OSCAL component are the backbone of an OSCAL System Security Plan (SSP), enabling data normalizat...

Updated 3 months ago by Brian Ruf

Native Adoption Path

FedRAMP System Security Plan (SSP) Adopting OSCAL for SSP Representation

If you are approaching OSCAL to intially create your system security plan and do not have legacy ...

Updated 3 months ago by Brian Ruf

SSP Adoption Strategies

FedRAMP System Security Plan (SSP) Adopting OSCAL for SSP Representation

The best way to adopt OSCAL for your system depends on your circumstances. The OSCAL Foundation d...

Updated 3 months ago by Brian Ruf

Welcome

Overview

The goal of the OSCAL Patterns Library is to maximize interoperability across OSCAL tools. The li...

Updated 3 months ago by Brian Ruf

Retrofit Adoption Path

FedRAMP System Security Plan (SSP) Adopting OSCAL for SSP Representation

If you need to convert legacy documentation to OSCAL, follow this path. If you are approaching OS...

Updated 3 months ago by Brian Ruf

Roles

FedRAMP Common

Every FedRAMP assessment package must identify the party (individual, team or organization) respo...

Updated 3 months ago by Brian Ruf

Control Origination

FedRAMP System Security Plan (SSP) FedRAMP Security Controls

FedRAMP accepts only one of five values for control-origination: sp-corporate, sp-system, custome...

Updated 3 months ago by Brian Ruf

Implementaiton Status

FedRAMP System Security Plan (SSP) FedRAMP Security Controls

FedRAMP only accepts only one of five values for implementation-status: implemented, partial, pla...

Updated 3 months ago by Brian Ruf

Inheritence and Customer Responsibilities

FedRAMP System Security Plan (SSP) FedRAMP Security Controls

For systems that may be leveraged, OSCAL enables a robust mechanism for providing both inheritanc...

Updated 3 months ago by Brian Ruf

Responding By Component

FedRAMP System Security Plan (SSP) FedRAMP Security Controls

OSCAL SSPs represent control responses in control-implementation / implemented-requirements / st...

Updated 3 months ago by Brian Ruf

Control Implementation Statements

FedRAMP System Security Plan (SSP) FedRAMP Security Controls

Typically, the controls in the FedRAMP baselines have lettered parts (a., b., etc.). A few only h...

Updated 3 months ago by Brian Ruf

Citing Control Statements

FedRAMP System Security Plan (SSP) FedRAMP Security Controls

OSCAL SSPs cite OSCAL baseline statement identifiers when representing control implementation res...

Updated 3 months ago by Brian Ruf

Responding to Control Baselines

FedRAMP System Security Plan (SSP) FedRAMP Security Controls

OSCAL references controls in baselines and catalogs. The statements are not duplicated into an O...

Updated 3 months ago by Brian Ruf

Parameter Assignments

FedRAMP System Security Plan (SSP) FedRAMP Security Controls

Representation If a FedRAMP control has one or more parameters, add a set-parameters array Withi...

Updated 3 months ago by Brian Ruf

Milestones, Approach and Status

Overview

The OSCAL Foundation's FedRAMP Technical Focus Group (TFG) is enabling FedRAMP stakeholders to ad...

Updated 3 months ago by Brian Ruf

Prepared By/For

FedRAMP System Security Plan (SSP) Title Page, Prepared by/for, Approvers

Prepared By and Prepared For follow the Roles pattern, using the prepared-by and prepared-for ro...

Updated 3 months ago by Erik Cass

Responsible Roles

FedRAMP System Security Plan (SSP) FedRAMP Security Controls

Every control should have one or more responsible roles identified. In OSCAL, there are three po...

Updated 3 months ago by Brian Ruf

Control Response: Policies, Procedures, Plans, RoB, and Guides

FedRAMP System Security Plan (SSP) FedRAMP Security Controls

Most FedRAMP-required attachments derive their requirement from one or more NIST SP 800-53 contro...

Updated 3 months ago by Brian Ruf