Skip to main content

Recently Updated Pages

Adoption Strategies

FedRAMP System Security Plan (SSP) Adopting OSCAL for SSP Representation

The best way to adopt OSCAL for your system depends on your circumstances. The OSCAL Foundation d...

Updated 1 day ago by Brian Ruf

New Adoption Path

FedRAMP System Security Plan (SSP) Adopting OSCAL for SSP Representation

If you are approaching OSCAL to intially create your system security plan and do not have legacy ...

Updated 1 day ago by Brian Ruf

Appendix M: Integrated Inventory Workbook

FedRAMP System Security Plan (SSP) Appendices A - Q

See Inventory Approaches for guidance.

Updated 1 day ago by Brian Ruf

Control Response: Flat Approach

FedRAMP System Security Plan (SSP) FedRAMP Security Controls

The flat approach to control responses is only intended as a starting point for service providers...

Updated 1 day ago by Brian Ruf

Prepared By/For

FedRAMP System Security Plan (SSP) Title Page, Prepared by/for, Approvers

"Prepared by" and "Prepared for" follow the Roles pattern, using the prepared-by and prepared-fo...

Updated 1 day ago by Brian Ruf

System Security Plan Approvals

FedRAMP System Security Plan (SSP) Title Page, Prepared by/for, Approvers

SSP Approvals follow the Roles pattern, using the content-approver role. Defined Identifiers Re...

Updated 1 day ago by Brian Ruf

Title Page

FedRAMP System Security Plan (SSP) Title Page, Prepared by/for, Approvers

The SSP title page follows the Title Pages pattern.

Updated 1 day ago by Brian Ruf

4. System Owner

FedRAMP System Security Plan (SSP) Sections 1 - 11

System Owner follows the Roles pattern, using the system-owner role. Defined Identifiers Requir...

Updated 1 day ago by Brian Ruf

5. Assignment of Security Responsibility

FedRAMP System Security Plan (SSP) Sections 1 - 11

Information System Security Officer (ISSO) follows the Roles pattern, using the information-syst...

Updated 1 day ago by Brian Ruf

Appendix C: Security Policies and Procedures

FedRAMP System Security Plan (SSP) Appendices A - Q

This needs work that may have been completed elsewhere and nees to be moved into here. This ...

Updated 1 day ago by Brian Ruf

Appendix D: User Guide

FedRAMP System Security Plan (SSP) Appendices A - Q

This needs work that may have been completed elsewhere and nees to be moved into here. This ...

Updated 1 day ago by Brian Ruf

Appendix F: Rules of Behavior (RoB)

FedRAMP System Security Plan (SSP) Appendices A - Q

This needs work that may have been completed elsewhere and nees to be moved into here. This ...

Updated 1 day ago by Brian Ruf

Appendix G: Information System Contingency Plan (ISCP)

FedRAMP System Security Plan (SSP) Appendices A - Q

This needs work that may have been completed elsewhere and nees to be moved into here. This ...

Updated 1 day ago by Brian Ruf

Appendix H: Configuration Management Plan (CMP)

FedRAMP System Security Plan (SSP) Appendices A - Q

This needs work that may have been completed elsewhere and nees to be moved into here. This ...

Updated 1 day ago by Brian Ruf

Appendix I: Incident Response Plan (IRP)

FedRAMP System Security Plan (SSP) Appendices A - Q

This needs work that may have been completed elsewhere and nees to be moved into here. This ...

Updated 1 day ago by Brian Ruf

Appendix N: Continuous Monitoring Plan

FedRAMP System Security Plan (SSP) Appendices A - Q

This needs work that may have been completed elsewhere and nees to be moved into here. This ...

Updated 1 day ago by Brian Ruf

Appendix P: Supply Chain Risk Management Plan (SCRMP)

FedRAMP System Security Plan (SSP) Appendices A - Q

This needs work that may have been completed elsewhere and nees to be moved into here. This ...

Updated 1 day ago by Brian Ruf

Control Definitions

FedRAMP System Security Plan (SSP) FedRAMP Security Controls

Conrol definitions are imported by an OSCAL SSP and referenced as needed. Importing a Baseline I...

Updated 1 day ago by Brian Ruf

Milestones, Approach and Status

Overview

The OSCAL Foundation's FedRAMP Technical Focus Group (TFG) is enabling FedRAMP stakeholders to ad...

Updated 1 day ago by Brian Ruf

Character Encoding

Core Requirements

UTF-8 Character Encoding OSCAL uses UTF-8 character encoding. JSON and YAML files are always UTF-...

Updated 1 day ago by Brian Ruf