Recently Updated Pages
Baselines
FedRAMP's baselines are available in OSCAL XML, JSON and YAML formats on the OSCAL Foundation's f...
Responsible Roles
Every control should have one or more responsible roles identified. In OSCAL, there are three op...
Appendix L: CSO-Specific Required Laws and Regulations
Needs Work Content cleanup YAML Example For MVP: attach a Word or PDF document enumerating t...
Appendix J: CIS and CRM Workbook
The FedRAMP Control Information Summary (CIS) and Customer Responsibility Matrix (CRM) are derive...
Appendix A: FedRAMP Security Controls
See [Controls citation and link]
6. Leveraged FedRAMP-Authorized Services
The leveraged FedRAMP-Authorized services table is used to list both underlying leveraged authori...
Appendix K: FIPS-199 Worksheet
The system's overall FIPS-199 impact level is determined primarily by the sensitivity of the info...
Appendix E: Digital Identity Level (DIL) Determination
The Digital Identity Level (DIL) is represented on the page below. Within system-characteristics...
Components
OSCAL component include: this system, a special component that represents the entire system and ...
Revision History
Document Revision History The OSCAL revision history requires one FedRAMP extension to meet FedRA...
Control Response: Policies and Procedures
The first control in each NIST SP 800-53 control family is a policy and procedure control. These ...
Control Response Overview
Within the OSCAL-based FedRAMP baselines, control statements and control objectives are tagged w...
Implementaiton Status
FedRAMP only accepts only one of five values for implementation-status: implemented, partial, pla...
Parameter Assignments
Need rework and to cover aggregated parameters Every applicable control must have at least one re...
Control Origination
FedRAMP accepts only one of five values for control-origination: sp-corporate, sp-system, custome...
Examples
This content uses YAML for examples. All examples are derived from complete example OSCAL content...
Required Metadata
All OSCAL artifacts must have the following content in metadata: title: The artifact's title las...
Required Root Information
Core OSCAL requires somne content to be present all OSCAL artifacts. This is crtical to consisten...
10. Cryptographic Modules Implemented for DAR and DIT
This is address in Appendix Q: Cryptographic Modules.