Recently Updated Pages
Citing Control Statements
OSCAL SSPs cite OSCAL baseline statement identifiers when representing control implementation res...
Parameter Assignments
Representation If a FedRAMP control has one or more parameters, add a set-parameters array Withi...
Milestones, Approach and Status
The OSCAL Foundation's FedRAMP Technical Focus Group (TFG) is enabling FedRAMP stakeholders to ad...
Prepared By/For
Prepared By and Prepared For follow the Roles pattern, using the prepared-by and prepared-for ro...
Responsible Roles
Every control should have one or more responsible roles identified. In OSCAL, there are three po...
Control Response: Policies, Procedures, Plans, RoB, and Guides
Most FedRAMP-required attachments derive their requirement from one or more NIST SP 800-53 contro...
Appendix B: Related Acronyms
There is no OSCAL construct for representing an acronyms list. Attach a document (e.g., Word, Exc...
11. Seperation of Duties Matrix
The metadata / roles array must have one entry for each column an id with a token (use pre-defi...
Appendix Q: Cryptographic Modules
Cryptographic Modules Implemented for Data-in-Transit (DIT) OSCAL's component model treats indepe...
Parties and Locations
Individuals, teams, corporations and government agencies are represented in OSCAL metadata using ...
Examples
This content uses YAML for examples. All examples are derived from complete example OSCAL content...
Attachments
Attachments All OSCAL models handle attachments the same way. The following is used to attach fil...
9. Services, Ports and Protocols
Entries in the services, ports, and protocols table are represented as component assemblies, with...
8. Illustratred Architecture and Narratives
The Architecture, Network and Data Flow Diagramss are each represented using the same OSCAL patte...
7. External Systems and Services Not Having FedRAMP Authorization
FedRAMP authorized services should be used, whenever possible, since their risk is defined. Howe...
Validating FedRAMP Content with OSCAL CLI
Get Started The oscal-cli is an open source command-line utility designed to help developers and ...
System Security Plan Approvals
SSP Approvals follow the Roles pattern, using the content-approver role. Defined Identifiers Re...
Title Page
The SSP title page follows the Title Pages pattern.
4. System Owner
System Owner follows the Roles pattern, using the system-owner role. Defined Identifiers Requir...
5. Assignment of Security Responsibility
Information System Security Officer (ISSO) follows the Roles pattern, using the information-syst...