Skip to main content
Advanced Search
Search Terms
Content Type

Exact Matches
Tag Searches
Date Options
Updated after
Updated before
Created after
Created before

Search Results

103 total results found

11. Seperation of Duties Matrix

FedRAMP System Security Plan (SSP) Sections 1 - 11

Milestones, Approach and Status

Overview

The OSCAL Foundation's FedRAMP Technical Focus Group (TFG) is enabling FedRAMP stakeholders to adopt OSCAL for FedRAMP package deliverables. The following is our plan of work: Milestones Phase 0 Establish Resources and Form Team [Complete] Phase 1 MVP FedRAMP...

LICENSE

Unless otherwise marked, this content is released as Creative Commons Zero (CC0). It may be used freely and without attribution.

Core Requirements

OSCAL requirements common to all content.

Title Page

FedRAMP System Security Plan (SSP) Title Page, Prepared by/for, Approvers

The SSP title page follows the Title Pages pattern.

Required Root Information

Core Requirements

Core OSCAL requires somne content to be present all OSCAL artifacts. This is crtical to consistent processing. Root Element and Root-Level Universally Unique Identifier The root element must be one of the case-sensitive OSCAL model names: catalog profile mapp...

OSCAL Requirements

FedRAMP System Security Plan (SSP)

All OSCAL Core Requirements must be met for all OSCAL artifacts. This chapter contains information about OSCAL SSP requirements that are not explicit FedRAMP SSP requirements.

System Status

FedRAMP System Security Plan (SSP) OSCAL Requirements

FedRAMP no longer includes System Status in the SSP template; however core OSCAL requires the system status to be identified. The system statys is represented in system-characteristics. A status entry that includes: state field set to one of the allowed val...

Roles

FedRAMP Common

Every FedRAMP assessment package must identify the party (individual, team or organization) responsible for pre-defined roles, such as system owner and information system security officer (ISSO). Representing this information in OSCAL requires four important e...

Attachments

FedRAMP Common

Attachments All OSCAL models handle attachments the same way. The following is used to attach files to OSCAL-based FedRAMP artifacts, such as when attaching policies and plans to a System Security Plan (SSP) or evidence to a Security Assessment Report (SAR). I...

Sections 1 - 11

FedRAMP System Security Plan (SSP)

1. Introduction

FedRAMP System Security Plan (SSP) Sections 1 - 11

This entire chapter is FedRAMP PMO boilerplate and does not need to be represented in OSCAL content.

2. Purpose

FedRAMP System Security Plan (SSP) Sections 1 - 11

This entire chapter is FedRAMP PMO boilerplate and does not need to be represented in OSCAL content.

4. System Owner

FedRAMP System Security Plan (SSP) Sections 1 - 11

System Owner follows the Roles pattern, using the system-owner role. Defined Identifiers Required Role ID: system-owner

5. Assignment of Security Responsibility

FedRAMP System Security Plan (SSP) Sections 1 - 11

Information System Security Officer (ISSO) follows the Roles pattern, using the information-system-security-officer role. Defined Identifiers Required Role ID: information-system-security-officer

10. Cryptographic Modules Implemented for DAR and DIT

FedRAMP System Security Plan (SSP) Sections 1 - 11

This is address in Appendix Q: Cryptographic Modules.

Required Metadata

Core Requirements

All OSCAL artifacts must have the following content in metadata: title: The artifact's title last-modified: The date/timestamp of the last modification to any content in the artifact. This is an date-time-with-timezone format. version: The version of the cont...

Adopting OSCAL for SSP Representation

FedRAMP System Security Plan (SSP)