Recently Updated Pages
Adoption Strategies
The best way to adopt OSCAL for your system depends on your circumstances. The OSCAL Foundation d...
New Adoption Path
If you are approaching OSCAL to intially create your system security plan and do not have legacy ...
Appendix M: Integrated Inventory Workbook
See Inventory Approaches for guidance.
Control Response: Flat Approach
The flat approach to control responses is only intended as a starting point for service providers...
Prepared By/For
"Prepared by" and "Prepared for" follow the Roles pattern, using the prepared-by and prepared-fo...
System Security Plan Approvals
SSP Approvals follow the Roles pattern, using the content-approver role. Defined Identifiers Re...
Title Page
The SSP title page follows the Title Pages pattern.
4. System Owner
System Owner follows the Roles pattern, using the system-owner role. Defined Identifiers Requir...
5. Assignment of Security Responsibility
Information System Security Officer (ISSO) follows the Roles pattern, using the information-syst...
Appendix C: Security Policies and Procedures
This needs work that may have been completed elsewhere and nees to be moved into here. This ...
Appendix D: User Guide
This needs work that may have been completed elsewhere and nees to be moved into here. This ...
Appendix F: Rules of Behavior (RoB)
This needs work that may have been completed elsewhere and nees to be moved into here. This ...
Appendix G: Information System Contingency Plan (ISCP)
This needs work that may have been completed elsewhere and nees to be moved into here. This ...
Appendix H: Configuration Management Plan (CMP)
This needs work that may have been completed elsewhere and nees to be moved into here. This ...
Appendix I: Incident Response Plan (IRP)
This needs work that may have been completed elsewhere and nees to be moved into here. This ...
Appendix N: Continuous Monitoring Plan
This needs work that may have been completed elsewhere and nees to be moved into here. This ...
Appendix P: Supply Chain Risk Management Plan (SCRMP)
This needs work that may have been completed elsewhere and nees to be moved into here. This ...
Control Definitions
Conrol definitions are imported by an OSCAL SSP and referenced as needed. Importing a Baseline I...
Milestones, Approach and Status
The OSCAL Foundation's FedRAMP Technical Focus Group (TFG) is enabling FedRAMP stakeholders to ad...
Character Encoding
UTF-8 Character Encoding OSCAL uses UTF-8 character encoding. JSON and YAML files are always UTF-...