Skip to main content
Advanced Search
Search Terms
Content Type

Exact Matches
Tag Searches
Date Options
Updated after
Updated before
Created after
Created before

Search Results

78 total results found

Appendix M: Integrated Inventory Workbook

Legacy FedRAMP System Security Plan (SSP) Appendices A - Q

See Inventory Approaches for guidance.

Appendix O: POA&M

Legacy FedRAMP System Security Plan (SSP) Appendices A - Q

See the FedRAMP POA&M book.

Appendix P: Supply Chain Risk Management Plan (SCRMP)

Legacy FedRAMP System Security Plan (SSP) Appendices A - Q

This needs work that may have been completed elsewhere and nees to be moved into here. This needs MVP and Normalized content examples MVP Key Points Include: The SR-2 (id=sr-2 control should have links entries to the user guide This is not normalized a...

Control Response: Approaches

Legacy FedRAMP System Security Plan (SSP) FedRAMP Security Controls

OSCAL offers a great deal of flexibility for controls responses. To balance consistency, interoperability and ease of adoption, the OSCAL Foundation recommends two approaches: Flat Approach: Aligns with FedRAMP's SSP Word template where control responses are ...

Control Response: Normalized Approach

Legacy FedRAMP System Security Plan (SSP) FedRAMP Security Controls

The normalized approach is prefered. Organizations starting new with no legacy SSP content should use this. For organizations converting from a legacy FedRAMP SSP Word template, consider starting with the Control Response: Flat Approach and migrating to the no...

Control Response: Flat Approach

Legacy FedRAMP System Security Plan (SSP) FedRAMP Security Controls

The flat approach to control responses is only intended as a starting point for service providers converting from a legacy FedRAMP SSP Word template. If you are not converting a legacy SSP, use the Control Response: Normalized Approach. With the flat approach...

Welcome

Overview

The goal of the OSCAL Patterns Library is to maximize interoperability across OSCAL tools. The library accomplishes this by defining the recommended OSCAL representation for specific use cases. Recommendations are based on the consensus of participating Founda...

Comments Summary

Reports

:root { --accent: #2d6be4; --accent-dim: #e8effe; --border: #dde1e9; --surface2: #f0f2f5; --muted: #6b7280; --tag-open: #16a34a; --tag-arc: #92400e; --radius: 6px; --mono: "JetBrains Mono", "Fira Mono", monospace; } .cr-meta { font-size: .8rem; color: var(--mu...

Parties and Locations

FedRAMP Common

Individuals, teams, corporations and government agencies are represented in OSCAL metadata using the parties array. Location information can be included within a party's information or defined separately for sharing. Locations Define a common location to be as...

Citing Control Statements

Legacy FedRAMP System Security Plan (SSP) FedRAMP Security Controls

OSCAL SSPs cite OSCAL baseline statement identifiers when representing control implementation responses. Citing the identifiers correctly is critical to machine processing. Within OSCAL baselines, identifiers are assigned to statement parts and item parts for ...

Defining Allowed Values

Overview Metaschema Authoring Principles

This page is still under development. The <allowed-values> assembly provides a consistent and unambiguous list of machine-readable tokens to be used as data for an identified OSCAL field or flag values. Human readability is coincidental and not their intended...

Baselines

FedRAMP Published Artifacts

This page will continue to evolve as the TFG reaches consensus on the best representation. There are several draft efforts to produce appropriate OSCAL catalogs and profiles representing the FedRAMP Rules (FRR) and certification classes. These include (in no p...

Mapping: FedRAMP Rules → OSCAL

FedRAMP Published Artifacts

DRAFT - PLEASE PROVIDE INPUT Updated: September 8, 2026 Latest Work Found Here This document maps every field defined in the FRR portion of fedramp-consolidated-rules.schema.json to its corresponding location in the OSCAL catalog produced by src/frr2oscal.py....

Notes and Agreements

Key Security Indicators (KSIs)

As the OSCAL Foundation's FedRAMP Technology Focus Group (TFG) reaches agreements as to the path forward, they are captured here. This is a work in progress. Once the group reaches an appropriate milestone, this will be consolidated and re-organized into more ...

KSI Example

Key Security Indicators (KSIs)

WORK IN PROGRESS The OSCAL Foundation's FedRAMP TFG elected to focus on [KSI-IAM-AAM] Identity and Access Management: Automated Account Management. This is an example of how KSIs could be implemented in OSCAL. It does not necessary reflect exactly what should ...

CR26 Overview

FedRAMP TFG CR26 Efforts

DRAFT - PLEASE PROVIDE INPUT The following is a depiction of how the FedRAMP Published Artifacts, Deliverables and KSI Automation fit together under FedRAMP Consolidated Rules 2026 (CR26). The effort to map these in detail and produce related OSCAL content is ...

New Page

Component Patterns

Relationships: Overview

Component Patterns Component Relationships and Interactions

In information systems, components interact with each other. Simple and complex component relationships can be represented accurately using OSCAL. Relationship Types Relationship representations include: third-party validations connectivity data flows compone...