Skip to main content
Advanced Search
Search Terms
Content Type

Exact Matches
Tag Searches
Date Options
Updated after
Updated before
Created after
Created before

Search Results

63 total results found

Implementaiton Status

FedRAMP System Security Plan (SSP) FedRAMP Security Controls

FedRAMP only accepts only one of five values for implementation-status: implemented, partial, planned, alternative, and not-applicable. A control may be marked "partial" and "planned" (using two separate implementation-status fields). All other choices are mut...

Control Origination

FedRAMP System Security Plan (SSP) FedRAMP Security Controls

FedRAMP accepts only one of five values for control-origination: sp-corporate, sp-system, customer-configured, customer-provided, and inherited. Hybrid choices are expressed by identifying more than one control-origination, each in a separate prop field. For c...

Control Response Overview

FedRAMP System Security Plan (SSP) FedRAMP Security Controls

Within the OSCAL-based FedRAMP baselines, control statements and control objectives are tagged with a response-point FedRAMP Extension. Every control statement with a designated response-point in the baseline must have a statement with the control's implement...

Control Response: Policies and Procedures

FedRAMP System Security Plan (SSP) FedRAMP Security Controls

The first control in each NIST SP 800-53 control family is a policy and procedure control. These are sometimes refered to as "the dash one controls". (AC-1, AT-1, AU-1, etc.) FedRAMP does not permit these controls to be inherited. As a result, every one of the...

Control Responses

FedRAMP System Security Plan (SSP) FedRAMP Security Controls

Implementation Statements: General Organization: Multi-Part Statements There must be one statement assembly for each lettered part, such as with AC-2, parts a, b, c, etc. Multi-Part Statement Representation <!-- system-implementation --> <control-implementatio...

Control Definitions

FedRAMP System Security Plan (SSP) FedRAMP Security Controls

Conrol definitions are imported by an OSCAL SSP and referenced as needed. Importing a Baseline Import the appropriate FedRAMP Baseline, either as an OSCAL profile or as an OSCAL reserved profile catalog. system-security-plan: import-profile: href: https...

Example

FedRAMP System Security Plan (SSP) FedRAMP Security Controls

Within each of the statement assemblies, all responses appear in one or more by-component assemblies. Each by-component assembly references a component defined in the system-implementation assembly. Representation <system-implementation> <!-- leveraged-au...

Inheritence and Customer Responsibilities

FedRAMP System Security Plan (SSP) FedRAMP Security Controls

For systems that may be leveraged, OSCAL enables a robust mechanism for providing both inheritance details as well as customer responsibilities (referred to as consumer responsibilities by NIST). OSCAL is designed to enable leveraged and leveraging system SSP ...

Examples

Supporting Resources and Valid Content

This content uses YAML for examples. All examples are derived from complete example OSCAL content, which is available in all three OSCAL formats and published in the OSCAL Foundation's fedramp-resources GitHub repository: FedRAMP OSCAL Artifact Status ...

11. Seperation of Duties Matrix

FedRAMP System Security Plan (SSP) Sections 1 - 11

Milestones, Approach and Status

Overview

The OSCAL Foundation's FedRAMP Technical Focus Group (TFG) is enabling FedRAMP stakeholders to adopt OSCAL for FedRAMP package deliverables. The following is our plan of work: Milestones Phase 0 Establish Resources and Form Team [Complete] Phase 1 MVP FedRAMP...

Title Page

FedRAMP System Security Plan (SSP) Title Page, Prepared by/for, Approvers

The SSP title page follows the Title Pages pattern.

Required Root Information

Core Requirements

Core OSCAL requires somne content to be present all OSCAL artifacts. This is crtical to consistent processing. Root Element and Root-Level Universally Unique Identifier The root element must be one of the case-sensitive OSCAL model names: catalog profile mapp...

System Status

FedRAMP System Security Plan (SSP) OSCAL Requirements

FedRAMP no longer includes System Status in the SSP template; however core OSCAL requires the system status to be identified. The system statys is represented in system-characteristics. A status entry that includes: state field set to one of the allowed val...

Roles

FedRAMP Common

Every FedRAMP assessment package must identify the party (individual, team or organization) responsible for pre-defined roles, such as system owner and information system security officer (ISSO). Representing this information in OSCAL requires four important e...

Attachments

FedRAMP Common

Attachments All OSCAL models handle attachments the same way. The following is used to attach files to OSCAL-based FedRAMP artifacts, such as when attaching policies and plans to a System Security Plan (SSP) or evidence to a Security Assessment Report (SAR). I...

1. Introduction

FedRAMP System Security Plan (SSP) Sections 1 - 11

This entire chapter is FedRAMP PMO boilerplate and does not need to be represented in OSCAL content.

2. Purpose

FedRAMP System Security Plan (SSP) Sections 1 - 11

This entire chapter is FedRAMP PMO boilerplate and does not need to be represented in OSCAL content.