Advanced Search
Search Results
127 total results found
Baselines
This page will continue to evolve as the TFG reaches consensus on the best representation. There are several draft efforts to produce appropriate OSCAL catalogs and profiles representing the FedRAMP Rules (FRR) and certification classes. These include (in no p...
Mapping: FedRAMP Rules → OSCAL
DRAFT - PLEASE PROVIDE INPUT Updated: September 8, 2026 Latest Work Found Here This document maps every field defined in the FRR portion of fedramp-consolidated-rules.schema.json to its corresponding location in the OSCAL catalog produced by src/frr2oscal.py....
Key Security Indicators (KSIs)
Notes and Agreements
As the OSCAL Foundation's FedRAMP Technology Focus Group (TFG) reaches agreements as to the path forward, they are captured here. This is a work in progress. Once the group reaches an appropriate milestone, this will be consolidated and re-organized into more ...
KSI Example
WORK IN PROGRESS The OSCAL Foundation's FedRAMP TFG elected to focus on [KSI-IAM-AAM] Identity and Access Management: Automated Account Management. This is an example of how KSIs could be implemented in OSCAL. It does not necessary reflect exactly what should ...
FedRAMP Deliverables
Representing the FedRAMP Certification Package Overview (CPO) and Security Decision Record (SDO) in OSCAL and translating between OSCAL and the FedRAMP-published bespoke schema. Although also FedRAMP Artifacts, KSIs are receiving separate focus.
FedRAMP TFG CR26 Efforts
CR26 Overview
DRAFT - PLEASE PROVIDE INPUT The following is a depiction of how the FedRAMP Published Artifacts, Deliverables and KSI Automation fit together under FedRAMP Consolidated Rules 2026 (CR26). The effort to map these in detail and produce related OSCAL content is ...
Component Patterns
Patterns that apply to components in component definitions (cDefs) and system security plans (SSPs).
New Page
Component Relationships and Interactions
Patterns for representing the relationships and interactions between components.
Relationships: Overview
In information systems, components interact with each other. Simple and complex component relationships can be represented accurately using OSCAL. Relationship Types Relationship representations include: third-party validations connectivity data flows compone...
Taxonomy
DRAFT - Please review and provide feedback. Self-register via Login to leave comments. We defined the following DRAFT KSI Taxonomy to align with CR26 terminology and Security Decision Record (SDR) schema fields. We expanded on this where necessary; expansio...
Guiding Principles
DRAFT - Please review and provide feedback. Self-register via Login to leave comments. We defined the following DRAFT guiding principles in alignment with the Taxonomy. Data Analysis: The Data Analysis must clearly define the intended result of data collect...
Overview
Links to the OSCAL Foundation's FedRAMP Technology Focus Group (TFG) FedRAMP KSI efforts: Taxonomy Guiding Principles KSI Example Notes and Agreements
Overview
CR26 Deliverables Overview
DRAFT - PLEASE PROVIDE INPUT The following is an overview of how the FedRAMP CR26 Deliverables are represented using OSCAL models. Certification Package Overview (CPO): System details are very similar to legacy SSP front-matter. Requires summary of assess...
Workstreams
The OSCAL Foundation's FedRAMP TFG is currently focused on three workstreams realted to the FedRAMP PMO's Consolidated Rules 2026 (CR26): FedRAMP Published Artifacts: Representation of the FedRAPM Rules (FRRs), Key Security Indicator (KSI) definitions, and R...