Skip to main content

Recently Updated Pages

Baselines

Supporting Resources and Valid Content

FedRAMP's baselines are available in OSCAL XML, JSON and YAML formats on the OSCAL Foundation's f...

Updated 1 day ago by Erik Cass

Responsible Roles

FedRAMP System Security Plan (SSP) FedRAMP Security Controls

Every control should have one or more responsible roles identified. In OSCAL, there are three op...

Updated 3 days ago by Brian Ruf

Appendix L: CSO-Specific Required Laws and Regulations

FedRAMP System Security Plan (SSP) Appendices A - Q

Needs Work Content cleanup YAML Example For MVP: attach a Word or PDF document enumerating t...

Updated 1 week ago by Brian Ruf

Appendix J: CIS and CRM Workbook

FedRAMP System Security Plan (SSP) Appendices A - Q

The FedRAMP Control Information Summary (CIS) and Customer Responsibility Matrix (CRM) are derive...

Updated 1 week ago by Brian Ruf

Appendix A: FedRAMP Security Controls

FedRAMP System Security Plan (SSP) Appendices A - Q

See [Controls citation and link]

Updated 1 week ago by Brian Ruf

6. Leveraged FedRAMP-Authorized Services

FedRAMP System Security Plan (SSP) Sections 1 - 11

The leveraged FedRAMP-Authorized services table is used to list both underlying leveraged authori...

Updated 1 week ago by Brian Ruf

Appendix K: FIPS-199 Worksheet

FedRAMP System Security Plan (SSP) Appendices A - Q

The system's overall FIPS-199 impact level is determined primarily by the sensitivity of the info...

Updated 1 week ago by Brian Ruf

Appendix E: Digital Identity Level (DIL) Determination

FedRAMP System Security Plan (SSP) Appendices A - Q

The Digital Identity Level (DIL) is represented on the page below. Within system-characteristics...

Updated 1 week ago by Brian Ruf

Components

System Security Plans

OSCAL component include: this system, a special component that represents the entire system and ...

Updated 1 week ago by Brian Ruf

Revision History

FedRAMP Common

Document Revision History The OSCAL revision history requires one FedRAMP extension to meet FedRA...

Updated 1 week ago by Erik Cass

Control Response: Policies and Procedures

FedRAMP System Security Plan (SSP) FedRAMP Security Controls

The first control in each NIST SP 800-53 control family is a policy and procedure control. These ...

Updated 2 weeks ago by Erik Cass

Control Response Overview

FedRAMP System Security Plan (SSP) FedRAMP Security Controls

Within the OSCAL-based FedRAMP baselines, control statements and control objectives are tagged w...

Updated 2 weeks ago by Erik Cass

Implementaiton Status

FedRAMP System Security Plan (SSP) FedRAMP Security Controls

FedRAMP only accepts only one of five values for implementation-status: implemented, partial, pla...

Updated 2 weeks ago by Erik Cass

Parameter Assignments

FedRAMP System Security Plan (SSP) FedRAMP Security Controls

Need rework and to cover aggregated parameters Every applicable control must have at least one re...

Updated 3 weeks ago by Erik Cass

Control Origination

FedRAMP System Security Plan (SSP) FedRAMP Security Controls

FedRAMP accepts only one of five values for control-origination: sp-corporate, sp-system, custome...

Updated 3 weeks ago by Erik Cass

Examples

Supporting Resources and Valid Content

This content uses YAML for examples. All examples are derived from complete example OSCAL content...

Updated 3 weeks ago by Brian Ruf

Required Metadata

Core Requirements

All OSCAL artifacts must have the following content in metadata: title: The artifact's title las...

Updated 3 weeks ago by Brian Ruf

Required Root Information

Core Requirements

Core OSCAL requires somne content to be present all OSCAL artifacts. This is crtical to consisten...

Updated 3 weeks ago by Brian Ruf

10. Cryptographic Modules Implemented for DAR and DIT

FedRAMP System Security Plan (SSP) Sections 1 - 11

This is address in Appendix Q: Cryptographic Modules.

Updated 3 weeks ago by Brian Ruf

11. Seperation of Duties Matrix

FedRAMP System Security Plan (SSP) Sections 1 - 11

Updated 3 weeks ago by Brian Ruf