Skip to main content

Recently Updated Pages

Citing Control Statements

Legacy FedRAMP System Security Plan (SSP) FedRAMP Security Controls

OSCAL SSPs cite OSCAL baseline statement identifiers when representing control implementation res...

Updated 5 months ago by Brian Ruf

Parameter Assignments

Legacy FedRAMP System Security Plan (SSP) FedRAMP Security Controls

Representation If a FedRAMP control has one or more parameters, add a set-parameters array Withi...

Updated 5 months ago by Brian Ruf

Milestones, Approach and Status

Overview

The OSCAL Foundation's FedRAMP Technical Focus Group (TFG) is enabling FedRAMP stakeholders to ad...

Updated 5 months ago by Brian Ruf

Prepared By/For

Legacy FedRAMP System Security Plan (SSP) Title Page, Prepared by/for, Approvers

Prepared By and Prepared For follow the Roles pattern, using the prepared-by and prepared-for ro...

Updated 5 months ago by Erik Cass

Responsible Roles

Legacy FedRAMP System Security Plan (SSP) FedRAMP Security Controls

Every control should have one or more responsible roles identified. In OSCAL, there are three po...

Updated 5 months ago by Brian Ruf

Control Response: Policies, Procedures, Plans, RoB, and Guides

Legacy FedRAMP System Security Plan (SSP) FedRAMP Security Controls

Most FedRAMP-required attachments derive their requirement from one or more NIST SP 800-53 contro...

Updated 5 months ago by Brian Ruf

Appendix B: Related Acronyms

Legacy FedRAMP System Security Plan (SSP) Appendices A - Q

There is no OSCAL construct for representing an acronyms list. Attach a document (e.g., Word, Exc...

Updated 5 months ago by Brian Ruf

11. Seperation of Duties Matrix

Legacy FedRAMP System Security Plan (SSP) Sections 1 - 11

The metadata / roles array must have one entry for each column an id with a token (use pre-defi...

Updated 5 months ago by Brian Ruf

Appendix Q: Cryptographic Modules

Legacy FedRAMP System Security Plan (SSP) Appendices A - Q

Cryptographic Modules Implemented for Data-in-Transit (DIT) OSCAL's component model treats indepe...

Updated 5 months ago by Brian Ruf

Parties and Locations

FedRAMP Common

Individuals, teams, corporations and government agencies are represented in OSCAL metadata using ...

Updated 5 months ago by Brian Ruf

Examples

Supporting Resources and Valid Content

This content uses YAML for examples. All examples are derived from complete example OSCAL content...

Updated 5 months ago by Brian Ruf

Attachments

FedRAMP Common

Attachments All OSCAL models handle attachments the same way. The following is used to attach fil...

Updated 5 months ago by Brian Ruf

9. Services, Ports and Protocols

Legacy FedRAMP System Security Plan (SSP) Sections 1 - 11

Entries in the services, ports, and protocols table are represented as component assemblies, with...

Updated 5 months ago by Brian Ruf

8. Illustratred Architecture and Narratives

Legacy FedRAMP System Security Plan (SSP) Sections 1 - 11

The Architecture, Network and Data Flow Diagramss are each represented using the same OSCAL patte...

Updated 5 months ago by Rene M. Tshiteya

7. External Systems and Services Not Having FedRAMP Authorization

Legacy FedRAMP System Security Plan (SSP) Sections 1 - 11

FedRAMP authorized services should be used, whenever possible, since their risk is defined. Howe...

Updated 5 months ago by Rene M. Tshiteya

Validating FedRAMP Content with OSCAL CLI

Supporting Resources and Valid Content Validating Content

Get Started The oscal-cli is an open source command-line utility designed to help developers and ...

Updated 5 months ago by Rene M. Tshiteya

System Security Plan Approvals

Legacy FedRAMP System Security Plan (SSP) Title Page, Prepared by/for, Approvers

SSP Approvals follow the Roles pattern, using the content-approver role. Defined Identifiers Re...

Updated 5 months ago by Brian Ruf

Title Page

Legacy FedRAMP System Security Plan (SSP) Title Page, Prepared by/for, Approvers

The SSP title page follows the Title Pages pattern.

Updated 5 months ago by Brian Ruf

4. System Owner

Legacy FedRAMP System Security Plan (SSP) Sections 1 - 11

System Owner follows the Roles pattern, using the system-owner role. Defined Identifiers Requir...

Updated 5 months ago by Brian Ruf

5. Assignment of Security Responsibility

Legacy FedRAMP System Security Plan (SSP) Sections 1 - 11

Information System Security Officer (ISSO) follows the Roles pattern, using the information-syst...

Updated 5 months ago by Brian Ruf