Skip to main content

Recently Updated Pages

Appendix C: Security Policies and Procedures

FedRAMP System Security Plan (SSP) Appendices A - Q

See Control Response: Policies and Procedures.

Updated 1 month ago by Brian Ruf

Appendix B: Related Acronyms

FedRAMP System Security Plan (SSP) Appendices A - Q

There is no OSCAL construct for representing an acronyms list. Attach a document (e.g., Word, Exc...

Updated 1 month ago by Brian Ruf

Appendix A: FedRAMP Security Controls

FedRAMP System Security Plan (SSP) Appendices A - Q

See the FedRAMP Security Controls chapter.

Updated 1 month ago by Brian Ruf

11. Seperation of Duties Matrix

FedRAMP System Security Plan (SSP) Sections 1 - 11

The metadata / roles array must have one entry for each column an id with a token (use pre-defi...

Updated 1 month ago by Brian Ruf

Appendix Q: Cryptographic Modules

FedRAMP System Security Plan (SSP) Appendices A - Q

Cryptographic Modules Implemented for Data-in-Transit (DIT) OSCAL's component model treats indepe...

Updated 1 month ago by Brian Ruf

Parties and Locations

FedRAMP Common

Individuals, teams, corporations and government agencies are represented in OSCAL metadata using ...

Updated 1 month ago by Brian Ruf

Examples

Supporting Resources and Valid Content

This content uses YAML for examples. All examples are derived from complete example OSCAL content...

Updated 1 month ago by Brian Ruf

Attachments

FedRAMP Common

Attachments All OSCAL models handle attachments the same way. The following is used to attach fil...

Updated 1 month ago by Brian Ruf

Title Pages

FedRAMP Common

All FedRAMP artifacts include a title page. The content found on the title page is represented u...

Updated 1 month ago by Brian Ruf

Appendicies Overview

FedRAMP System Security Plan (SSP) Appendices A - Q

Most attachments required by FedRAMP are called out in the NIST SP 800-53 controls appearning in ...

Updated 1 month ago by Brian Ruf

Appendix O: POA&M

FedRAMP System Security Plan (SSP) Appendices A - Q

See the FedRAMP POA&M book.

Updated 1 month ago by Brian Ruf

9. Services, Ports and Protocols

FedRAMP System Security Plan (SSP) Sections 1 - 11

Entries in the services, ports, and protocols table are represented as component assemblies, with...

Updated 1 month ago by Brian Ruf

8. Illustratred Architecture and Narratives

FedRAMP System Security Plan (SSP) Sections 1 - 11

The Architecture, Network and Data Flow Diagramss are each represented using the same OSCAL patte...

Updated 1 month ago by Rene M. Tshiteya

7. External Systems and Services Not Having FedRAMP Authorization

FedRAMP System Security Plan (SSP) Sections 1 - 11

FedRAMP authorized services should be used, whenever possible, since their risk is defined. Howe...

Updated 1 month ago by Rene M. Tshiteya

Validating FedRAMP Content with OSCAL CLI

Supporting Resources and Valid Content Validating Content

Get Started The oscal-cli is an open source command-line utility designed to help developers and ...

Updated 1 month ago by Rene M. Tshiteya

The Tiered Validation Model

Supporting Resources and Valid Content Validating Content

Validating OSCAL content is a tiered process that ensures data integrity from basic file structur...

Updated 1 month ago by Rene M. Tshiteya

Control Response: Approaches

FedRAMP System Security Plan (SSP) FedRAMP Security Controls

OSCAL offers a great deal of flexibility for controls responses. To balance consistency, interope...

Updated 1 month ago by Brian Ruf

Control Response: Normalized Approach

FedRAMP System Security Plan (SSP) FedRAMP Security Controls

The normalized approach is prefered. Organizations starting new with no legacy SSP content should...

Updated 1 month ago by Brian Ruf

3. System Information

FedRAMP System Security Plan (SSP) Sections 1 - 11

System Information CSP Name The cloud service provider (CSP) name and abbreviation are represent...

Updated 1 month ago by Erik Cass

Inventory Approaches

FedRAMP System Security Plan (SSP) System Components and Inventory

OSCAL makes two approaches available for depicting the system inventory: Flat Approach: Aligns ...

Updated 1 month ago by Brian Ruf