Skip to main content

Recently Updated Pages

Comments Summary

Reports

:root { --accent: #2d6be4; --accent-dim: #e8effe; --border: #dde1e9; --surface2: #f0f2f5; --muted...

Updated 2 hours ago by Brian Ruf

Defining Allowed Values

Overview Metaschema Authoring Principles

This page is still under development. The <allowed-values> assembly provides a consistent and una...

Updated 2 days ago by Brian Ruf

Components

System Security Plans

OSCAL component are the backbone of an OSCAL System Security Plan (SSP), enabling data normalizat...

Updated 1 month ago by Brian Ruf

Native Adoption Path

FedRAMP System Security Plan (SSP) Adopting OSCAL for SSP Representation

If you are approaching OSCAL to intially create your system security plan and do not have legacy ...

Updated 1 month ago by Brian Ruf

SSP Adoption Strategies

FedRAMP System Security Plan (SSP) Adopting OSCAL for SSP Representation

The best way to adopt OSCAL for your system depends on your circumstances. The OSCAL Foundation d...

Updated 1 month ago by Brian Ruf

Welcome

Overview

The goal of the OSCAL Patterns Library is to maximize interoperability across OSCAL tools. The li...

Updated 1 month ago by Brian Ruf

Retrofit Adoption Path

FedRAMP System Security Plan (SSP) Adopting OSCAL for SSP Representation

If you need to convert legacy documentation to OSCAL, follow this path. If you are approaching OS...

Updated 1 month ago by Brian Ruf

Roles

FedRAMP Common

Every FedRAMP assessment package must identify the party (individual, team or organization) respo...

Updated 1 month ago by Brian Ruf

Control Origination

FedRAMP System Security Plan (SSP) FedRAMP Security Controls

FedRAMP accepts only one of five values for control-origination: sp-corporate, sp-system, custome...

Updated 1 month ago by Brian Ruf

Implementaiton Status

FedRAMP System Security Plan (SSP) FedRAMP Security Controls

FedRAMP only accepts only one of five values for implementation-status: implemented, partial, pla...

Updated 1 month ago by Brian Ruf

Inheritence and Customer Responsibilities

FedRAMP System Security Plan (SSP) FedRAMP Security Controls

For systems that may be leveraged, OSCAL enables a robust mechanism for providing both inheritanc...

Updated 1 month ago by Brian Ruf

Responding By Component

FedRAMP System Security Plan (SSP) FedRAMP Security Controls

OSCAL SSPs represent control responses in control-implementation / implemented-requirements / st...

Updated 1 month ago by Brian Ruf

Control Implementation Statements

FedRAMP System Security Plan (SSP) FedRAMP Security Controls

Typically, the controls in the FedRAMP baselines have lettered parts (a., b., etc.). A few only h...

Updated 1 month ago by Brian Ruf

Citing Control Statements

FedRAMP System Security Plan (SSP) FedRAMP Security Controls

OSCAL SSPs cite OSCAL baseline statement identifiers when representing control implementation res...

Updated 1 month ago by Brian Ruf

Responding to Control Baselines

FedRAMP System Security Plan (SSP) FedRAMP Security Controls

OSCAL references controls in baselines and catalogs. The statements are not duplicated into an O...

Updated 1 month ago by Brian Ruf

Parameter Assignments

FedRAMP System Security Plan (SSP) FedRAMP Security Controls

Representation If a FedRAMP control has one or more parameters, add a set-parameters array Withi...

Updated 1 month ago by Brian Ruf

Milestones, Approach and Status

Overview

The OSCAL Foundation's FedRAMP Technical Focus Group (TFG) is enabling FedRAMP stakeholders to ad...

Updated 1 month ago by Brian Ruf

Prepared By/For

FedRAMP System Security Plan (SSP) Title Page, Prepared by/for, Approvers

Prepared By and Prepared For follow the Roles pattern, using the prepared-by and prepared-for ro...

Updated 1 month ago by Erik Cass

Responsible Roles

FedRAMP System Security Plan (SSP) FedRAMP Security Controls

Every control should have one or more responsible roles identified. In OSCAL, there are three po...

Updated 1 month ago by Brian Ruf

Control Response: Policies, Procedures, Plans, RoB, and Guides

FedRAMP System Security Plan (SSP) FedRAMP Security Controls

Most FedRAMP-required attachments derive their requirement from one or more NIST SP 800-53 contro...

Updated 1 month ago by Brian Ruf