Skip to main content
Advanced Search
Search Terms
Content Type

Exact Matches
Tag Searches
Date Options
Updated after
Updated before
Created after
Created before

Search Results

103 total results found

FedRAMP

Federal Risk and Authorization Management Program (FedRAMP) a United States Federal compliance program based on the National Institute of Standards and Technology (NIST) Risk Management Framework (RMF). This work is based on the efforts of the OSCAL Foundatio...

fedramp

FedRAMP System Security Plan (SSP)

FedRAMP
SSP

Core OSCAL

Patterns for expressing information in OSCAL that are universal across frameworks. All content is considered to be in the public domain and free for all to use without constraint unless otherwise marked. [A specific open source license will be identified by t...

3. System Information

FedRAMP System Security Plan (SSP) Sections 1 - 11

System Information CSP Name The cloud service provider (CSP) name and abbreviation are represented in the SSP metadata. A roles extry must exist with id = cloud-service-provider A parties entry must exist with the CSP's name and short-name. A responsible-par...

FedRAMP POA&M

FedRAMP Common

While each FedRAMP template has a unique purpose, they share common information elements, such as title and publication date. These common elements are expressed using the same OSCAL syntax for the SSP, SAP, SAR, and POA&M. This section provides OSCAL syntax f...

Supporting Resources and Valid Content

Baselines

Supporting Resources and Valid Content

FedRAMP's baselines are available in OSCAL XML, JSON and YAML formats on the OSCAL Foundation's fedramp-resources GitHub repository. The OSCAL Foundation is making FedRAMP baselines available both as OSCAL profiles and as pre-processed resolved profile catalog...

Title Pages

FedRAMP Common

All FedRAMP artifacts include a title page. The content found on the title page is represented using core OSCAL content in metadata. title the artifact title as FedRAMP requires it to appear published the formal publication date of the artifact (using OSCAL ...

Prepared By/For

FedRAMP System Security Plan (SSP) Title Page, Prepared by/for, Approvers

"Prepared by" and "Prepared for" follow the Roles pattern, using the prepared-by and prepared-for roles. For an SSP: prepared-by may identify the cloud service provider or a thrid party advisory organization prepared-for always identifes the cloud service pr...

System Security Plan Approvals

FedRAMP System Security Plan (SSP) Title Page, Prepared by/for, Approvers

SSP Approvals follow the Roles pattern, using the content-approver role. Defined Identifiers Required Role IDs: content-approver

Appendix K: FIPS-199 Worksheet

FedRAMP System Security Plan (SSP) Appendices A - Q

The system's overall FIPS-199 impact level is determined primarily by the sensitivity of the information it processes. The overall FIPS-199 impact level is represented under system-characteristics: security-sensitivity-level The value must be one of fips-19...

6. Leveraged FedRAMP-Authorized Services

FedRAMP System Security Plan (SSP) Sections 1 - 11

The leveraged FedRAMP-Authorized services table is used to list both underlying leveraged authorizations, such as a SaaS running on an IaaS, and use of external cloud services with FedRAMP authorizations, such as a FedRAMP-authorized third party identity manag...

7. External Systems and Services Not Having FedRAMP Authorization

FedRAMP System Security Plan (SSP) Sections 1 - 11

FedRAMP authorized services should be used, whenever possible, since their risk is defined. However, there are instances where CSOs have external systems or services that are not FedRAMP authorized. In OSCAL, these external systems and services must be ident...

Appendix E: Digital Identity Level (DIL) Determination

FedRAMP System Security Plan (SSP) Appendices A - Q

The Digital Identity Level (DIL) is represented on the page below. Within system-characteristics there must be three entries to the props array as follows: name set to identity-assurance-level and a value set to 1, 2 or 3. name set to authenticator-assurance...

Appendix Q: Cryptographic Modules

FedRAMP System Security Plan (SSP) Appendices A - Q

Cryptographic Modules Implemented for Data-in-Transit (DIT) This page needs work: The examples needs to be converted to YAML A description of the YAML constructs needs to be provided OSCAL's component model treats independent validation of products and ser...

8. Illustratred Architecture and Narratives

FedRAMP System Security Plan (SSP) Sections 1 - 11

The Architecture, Network and Data Flow Diagramss are each represented using the same OSCAL patterns, with only the top level assemby name changing. Authorization Boundary The OSCAL approach to this type of diagram is to treat the image data as either a linked...

9. Services, Ports and Protocols

FedRAMP System Security Plan (SSP) Sections 1 - 11

Entries in the services, ports, and protocols table are represented as component assemblies, with the component-type flag set to "service". Use a protocol assembly for each protocol associated with the service. For a single port, set the port-range start flag ...