Skip to main content

Recently Updated Pages

Inventory: Normalized Approach

Legacy FedRAMP System Security Plan (SSP) System Components and Inventory

The normalized approach is prefered. Organizations starting new with no legacy inventory reportin...

Updated 1 month ago by Brian Ruf

Responding By Component

Legacy FedRAMP System Security Plan (SSP) FedRAMP Security Controls

OSCAL SSPs represent control responses in control-implementation / implemented-requirements / st...

Updated 1 month ago by Brian Ruf

Control Implementation Statements

Legacy FedRAMP System Security Plan (SSP) FedRAMP Security Controls

Typically, the controls in the FedRAMP baselines have lettered parts (a., b., etc.). A few only h...

Updated 1 month ago by Brian Ruf

Responding to Control Baselines

Legacy FedRAMP System Security Plan (SSP) FedRAMP Security Controls

OSCAL references controls in baselines and catalogs. The statements are not duplicated into an O...

Updated 1 month ago by Brian Ruf

Retrofit Adoption Path

Legacy FedRAMP System Security Plan (SSP) Adopting OSCAL for SSP Representation

If you need to convert legacy documentation to OSCAL, follow this path. If you are approaching OS...

Updated 1 month ago by Brian Ruf

SSP Adoption Strategies

Legacy FedRAMP System Security Plan (SSP) Adopting OSCAL for SSP Representation

The best way to adopt OSCAL for your system depends on your circumstances. The OSCAL Foundation d...

Updated 1 month ago by Brian Ruf

Native Adoption Path

Legacy FedRAMP System Security Plan (SSP) Adopting OSCAL for SSP Representation

If you are approaching OSCAL to intially create your system security plan and do not have legacy ...

Updated 1 month ago by Brian Ruf

The Tiered Validation Model

Supporting Resources and Valid Content Validating Content

Validating OSCAL content is a tiered process that ensures data integrity from basic file structur...

Updated 1 month ago by Rene M. Tshiteya

Appendix A: FedRAMP Security Controls

Legacy FedRAMP System Security Plan (SSP) Appendices A - Q

See the FedRAMP Security Controls chapter.

Updated 1 month ago by Brian Ruf

Appendix C: Security Policies and Procedures

Legacy FedRAMP System Security Plan (SSP) Appendices A - Q

See Control Response: Policies and Procedures.

Updated 1 month ago by Brian Ruf

Appendix M: Integrated Inventory Workbook

Legacy FedRAMP System Security Plan (SSP) Appendices A - Q

See Inventory Approaches for guidance.

Updated 1 month ago by Brian Ruf

Control Response: Approaches

Legacy FedRAMP System Security Plan (SSP) FedRAMP Security Controls

OSCAL offers a great deal of flexibility for controls responses. To balance consistency, interope...

Updated 1 month ago by Brian Ruf

Control Response: Normalized Approach

Legacy FedRAMP System Security Plan (SSP) FedRAMP Security Controls

The normalized approach is prefered. Organizations starting new with no legacy SSP content should...

Updated 1 month ago by Brian Ruf

Control Response: Flat Approach

Legacy FedRAMP System Security Plan (SSP) FedRAMP Security Controls

The flat approach to control responses is only intended as a starting point for service providers...

Updated 1 month ago by Brian Ruf

Defining Allowed Values

Overview Metaschema Authoring Principles

This page is still under development. The <allowed-values> assembly provides a consistent and una...

Updated 4 months ago by Brian Ruf

Components

System Security Plans

OSCAL component are the backbone of an OSCAL System Security Plan (SSP), enabling data normalizat...

Updated 5 months ago by Brian Ruf

Roles

FedRAMP Common

Every FedRAMP assessment package must identify the party (individual, team or organization) respo...

Updated 5 months ago by Brian Ruf

Control Origination

Legacy FedRAMP System Security Plan (SSP) FedRAMP Security Controls

FedRAMP accepts only one of five values for control-origination: sp-corporate, sp-system, custome...

Updated 5 months ago by Brian Ruf

Implementaiton Status

Legacy FedRAMP System Security Plan (SSP) FedRAMP Security Controls

FedRAMP only accepts only one of five values for implementation-status: implemented, partial, pla...

Updated 5 months ago by Brian Ruf

Inheritence and Customer Responsibilities

Legacy FedRAMP System Security Plan (SSP) FedRAMP Security Controls

For systems that may be leveraged, OSCAL enables a robust mechanism for providing both inheritanc...

Updated 5 months ago by Brian Ruf