Skip to main content

Recently Updated Pages

Inventory: Flat Approach

FedRAMP System Security Plan (SSP) System Components and Inventory

The flat approach to inventory is only intended as a starting point for service providers convert...

Updated 1 month ago by Brian Ruf

Inventory: Normalized Approach

FedRAMP System Security Plan (SSP) System Components and Inventory

The normalized approach is prefered. Organizations starting new with no legacy inventory reportin...

Updated 1 month ago by Brian Ruf

Appendix M: Integrated Inventory Workbook

FedRAMP System Security Plan (SSP) Appendices A - Q

See Inventory Approaches for guidance.

Updated 1 month ago by Brian Ruf

Control Response: Flat Approach

FedRAMP System Security Plan (SSP) FedRAMP Security Controls

The flat approach to control responses is only intended as a starting point for service providers...

Updated 1 month ago by Brian Ruf

System Security Plan Approvals

FedRAMP System Security Plan (SSP) Title Page, Prepared by/for, Approvers

SSP Approvals follow the Roles pattern, using the content-approver role. Defined Identifiers Re...

Updated 1 month ago by Brian Ruf

Title Page

FedRAMP System Security Plan (SSP) Title Page, Prepared by/for, Approvers

The SSP title page follows the Title Pages pattern.

Updated 1 month ago by Brian Ruf

4. System Owner

FedRAMP System Security Plan (SSP) Sections 1 - 11

System Owner follows the Roles pattern, using the system-owner role. Defined Identifiers Requir...

Updated 1 month ago by Brian Ruf

5. Assignment of Security Responsibility

FedRAMP System Security Plan (SSP) Sections 1 - 11

Information System Security Officer (ISSO) follows the Roles pattern, using the information-syst...

Updated 1 month ago by Brian Ruf

Appendix D: User Guide

FedRAMP System Security Plan (SSP) Appendices A - Q

This needs work that may have been completed elsewhere and nees to be moved into here. This ...

Updated 1 month ago by Brian Ruf

Appendix F: Rules of Behavior (RoB)

FedRAMP System Security Plan (SSP) Appendices A - Q

This needs work that may have been completed elsewhere and nees to be moved into here. This ...

Updated 1 month ago by Brian Ruf

Appendix G: Information System Contingency Plan (ISCP)

FedRAMP System Security Plan (SSP) Appendices A - Q

This needs work that may have been completed elsewhere and nees to be moved into here. This ...

Updated 1 month ago by Brian Ruf

Appendix H: Configuration Management Plan (CMP)

FedRAMP System Security Plan (SSP) Appendices A - Q

This needs work that may have been completed elsewhere and nees to be moved into here. This ...

Updated 1 month ago by Brian Ruf

Appendix I: Incident Response Plan (IRP)

FedRAMP System Security Plan (SSP) Appendices A - Q

This needs work that may have been completed elsewhere and nees to be moved into here. This ...

Updated 1 month ago by Brian Ruf

Appendix N: Continuous Monitoring Plan

FedRAMP System Security Plan (SSP) Appendices A - Q

This needs work that may have been completed elsewhere and nees to be moved into here. This ...

Updated 1 month ago by Brian Ruf

Appendix P: Supply Chain Risk Management Plan (SCRMP)

FedRAMP System Security Plan (SSP) Appendices A - Q

This needs work that may have been completed elsewhere and nees to be moved into here. This ...

Updated 1 month ago by Brian Ruf

Character Encoding

Core Requirements

UTF-8 Character Encoding OSCAL uses UTF-8 character encoding. JSON and YAML files are always UTF-...

Updated 2 months ago by Brian Ruf

Baselines

Supporting Resources and Valid Content

FedRAMP's baselines are available in OSCAL XML, JSON and YAML formats on the OSCAL Foundation's f...

Updated 2 months ago by Erik Cass

Appendix L: CSO-Specific Required Laws and Regulations

FedRAMP System Security Plan (SSP) Appendices A - Q

Needs Work Content cleanup YAML Example For MVP: attach a Word or PDF document enumerating t...

Updated 2 months ago by Brian Ruf

Appendix J: CIS and CRM Workbook

FedRAMP System Security Plan (SSP) Appendices A - Q

The FedRAMP Control Information Summary (CIS) and Customer Responsibility Matrix (CRM) are derive...

Updated 2 months ago by Brian Ruf

6. Leveraged FedRAMP-Authorized Services

FedRAMP System Security Plan (SSP) Sections 1 - 11

The leveraged FedRAMP-Authorized services table is used to list both underlying leveraged authori...

Updated 2 months ago by Brian Ruf