Skip to main content

Recently Updated Pages

Comments Summary

Reports

:root { --accent: #2d6be4; --accent-dim: #e8effe; --border: #dde1e9; --surface2: #f0f2f5; --muted...

Updated 3 hours ago by Brian Ruf

Workstreams

FedRAMP TFG CR26 Efforts

The OSCAL Foundation's FedRAMP TFG is currently focused on three workstreams realted to the FedRA...

Updated 5 days ago by Brian Ruf

Taxonomy

Key Security Indicators (KSIs)

DRAFT - Please review and provide feedback. Self-register via Login to leave comments. We defi...

Updated 5 days ago by Brian Ruf

CR26 Overview

FedRAMP TFG CR26 Efforts

DRAFT - PLEASE PROVIDE INPUT The following is a depiction of how the FedRAMP Published Artifacts,...

Updated 1 week ago by Brian Ruf

CR26 Deliverables Overview

FedRAMP Deliverables

DRAFT - PLEASE PROVIDE INPUT The following is an overview of how the FedRAMP CR26 Deliverables ar...

Updated 1 week ago by Brian Ruf

Mapping: FedRAMP Rules → OSCAL

FedRAMP Published Artifacts

DRAFT - PLEASE PROVIDE INPUT Updated: September 8, 2026 Latest Work Found Here This document map...

Updated 1 week ago by Brian Ruf

Baselines

FedRAMP Published Artifacts

This page will continue to evolve as the TFG reaches consensus on the best representation. There ...

Updated 1 week ago by Brian Ruf

Overview

FedRAMP Published Artifacts

Updated 1 week ago by Brian Ruf

Overview

Key Security Indicators (KSIs)

Links to the OSCAL Foundation's FedRAMP Technology Focus Group (TFG) FedRAMP KSI efforts: Taxono...

Updated 1 week ago by Brian Ruf

Guiding Principles

Key Security Indicators (KSIs)

DRAFT - Please review and provide feedback. Self-register via Login to leave comments. We defin...

Updated 1 week ago by Brian Ruf

Notes and Agreements

Key Security Indicators (KSIs)

As the OSCAL Foundation's FedRAMP Technology Focus Group (TFG) reaches agreements as to the path ...

Updated 1 week ago by Brian Ruf

Relationships: Overview

Component Patterns Component Relationships and Interactions

In information systems, components interact with each other. Simple and complex component relatio...

Updated 2 weeks ago by Brian Ruf

KSI Example

Key Security Indicators (KSIs)

WORK IN PROGRESS The OSCAL Foundation's FedRAMP TFG elected to focus on [KSI-IAM-AAM] Identity an...

Updated 1 month ago by Brian Ruf

Welcome

Overview

The goal of the OSCAL Patterns Library is to maximize interoperability across OSCAL tools. The li...

Updated 1 month ago by Brian Ruf

Appendix O: POA&M

Legacy FedRAMP System Security Plan (SSP) Appendices A - Q

See the FedRAMP POA&M book.

Updated 1 month ago by Brian Ruf

3. System Information

Legacy FedRAMP System Security Plan (SSP) Sections 1 - 11

System Information CSP Name The cloud service provider (CSP) name and abbreviation are represent...

Updated 1 month ago by Erik Cass

Title Pages

FedRAMP Common

All FedRAMP artifacts include a title page. The content found on the title page is represented u...

Updated 1 month ago by Brian Ruf

Appendicies Overview

Legacy FedRAMP System Security Plan (SSP) Appendices A - Q

Most attachments required by FedRAMP are called out in the NIST SP 800-53 controls appearning in ...

Updated 1 month ago by Brian Ruf

Inventory Approaches

Legacy FedRAMP System Security Plan (SSP) System Components and Inventory

OSCAL makes two approaches available for depicting the system inventory: Flat Approach: Aligns ...

Updated 1 month ago by Brian Ruf

Inventory: Flat Approach

Legacy FedRAMP System Security Plan (SSP) System Components and Inventory

The flat approach to inventory is only intended as a starting point for service providers convert...

Updated 1 month ago by Brian Ruf