Recently Updated Pages
Inventory: Flat Approach
The flat approach to inventory is only intended as a starting point for service providers convert...
Inventory: Normalized Approach
The normalized approach is prefered. Organizations starting new with no legacy inventory reportin...
Appendix M: Integrated Inventory Workbook
See Inventory Approaches for guidance.
Control Response: Flat Approach
The flat approach to control responses is only intended as a starting point for service providers...
System Security Plan Approvals
SSP Approvals follow the Roles pattern, using the content-approver role. Defined Identifiers Re...
Title Page
The SSP title page follows the Title Pages pattern.
4. System Owner
System Owner follows the Roles pattern, using the system-owner role. Defined Identifiers Requir...
5. Assignment of Security Responsibility
Information System Security Officer (ISSO) follows the Roles pattern, using the information-syst...
Appendix D: User Guide
This needs work that may have been completed elsewhere and nees to be moved into here. This ...
Appendix F: Rules of Behavior (RoB)
This needs work that may have been completed elsewhere and nees to be moved into here. This ...
Appendix G: Information System Contingency Plan (ISCP)
This needs work that may have been completed elsewhere and nees to be moved into here. This ...
Appendix H: Configuration Management Plan (CMP)
This needs work that may have been completed elsewhere and nees to be moved into here. This ...
Appendix I: Incident Response Plan (IRP)
This needs work that may have been completed elsewhere and nees to be moved into here. This ...
Appendix N: Continuous Monitoring Plan
This needs work that may have been completed elsewhere and nees to be moved into here. This ...
Appendix P: Supply Chain Risk Management Plan (SCRMP)
This needs work that may have been completed elsewhere and nees to be moved into here. This ...
Character Encoding
UTF-8 Character Encoding OSCAL uses UTF-8 character encoding. JSON and YAML files are always UTF-...
Baselines
FedRAMP's baselines are available in OSCAL XML, JSON and YAML formats on the OSCAL Foundation's f...
Appendix L: CSO-Specific Required Laws and Regulations
Needs Work Content cleanup YAML Example For MVP: attach a Word or PDF document enumerating t...
Appendix J: CIS and CRM Workbook
The FedRAMP Control Information Summary (CIS) and Customer Responsibility Matrix (CRM) are derive...
6. Leveraged FedRAMP-Authorized Services
The leveraged FedRAMP-Authorized services table is used to list both underlying leveraged authori...