Recently Updated Pages
Comments Summary
:root { --accent: #2d6be4; --accent-dim: #e8effe; --border: #dde1e9; --surface2: #f0f2f5; --muted...
Attachments
Attachments All OSCAL models handle attachments the same way. The following is used to attach fil...
Title Pages
All FedRAMP artifacts include a title page. The content found on the title page is represented u...
Appendicies Overview
Most attachments required by FedRAMP are called out in the NIST SP 800-53 controls appearning in ...
Appendix O: POA&M
See the FedRAMP POA&M book.
Appendix Q: Cryptographic Modules
Cryptographic Modules Implemented for Data-in-Transit (DIT) This page needs work: The examples ...
9. Services, Ports and Protocols
Entries in the services, ports, and protocols table are represented as component assemblies, with...
Appendix B: Related Acronyms
There is no OSCAL construct for representing an acronyms list. Attach a document (e.g., Word, Exc...
8. Illustratred Architecture and Narratives
The Architecture, Network and Data Flow Diagramss are each represented using the same OSCAL patte...
7. External Systems and Services Not Having FedRAMP Authorization
FedRAMP authorized services should be used, whenever possible, since their risk is defined. Howe...
Validating FedRAMP Content with OSCAL CLI
Get Started The oscal-cli is an open source command-line utility designed to help developers and ...
The Tiered Validation Model
Validating OSCAL content is a tiered process that ensures data integrity from basic file structur...
Getting Started
Welcome to the OSCAL Foundation Patterns Library! The goal of the OSCAL Patterns Library is to ma...
Retrofit Adoption Path
If you need to convert legacy documentation to OSCAL, follow this path. If you are approaching OS...
Control Response: Approaches
OSCAL offers a great deal of flexibility for controls responses. To balance consistency, interope...
Control Response: Normalized Approach
The normalized approach is prefered. Organizations starting new with no legacy SSP content should...
3. System Information
System Information CSP Name The cloud service provider (CSP) name and abbreviation are represent...
Inventory Approaches
OSCAL makes two approaches available for depicting the system inventory: Flat Approach: Aligns ...
Inventory: Flat Approach
The flat approach to inventory is only intended as a starting point for service providers convert...
Inventory: Normalized Approach
The normalized approach is prefered. Organizations starting new with no legacy inventory reportin...