Skip to main content
Advanced Search
Search Terms
Content Type

Exact Matches
Tag Searches
Date Options
Updated after
Updated before
Created after
Created before

Search Results

127 total results found

Baselines

FedRAMP Published Artifacts

This page will continue to evolve as the TFG reaches consensus on the best representation. There are several draft efforts to produce appropriate OSCAL catalogs and profiles representing the FedRAMP Rules (FRR) and certification classes. These include (in no p...

Mapping: FedRAMP Rules → OSCAL

FedRAMP Published Artifacts

DRAFT - PLEASE PROVIDE INPUT Updated: September 8, 2026 Latest Work Found Here This document maps every field defined in the FRR portion of fedramp-consolidated-rules.schema.json to its corresponding location in the OSCAL catalog produced by src/frr2oscal.py....

Key Security Indicators (KSIs)

Notes and Agreements

Key Security Indicators (KSIs)

As the OSCAL Foundation's FedRAMP Technology Focus Group (TFG) reaches agreements as to the path forward, they are captured here. This is a work in progress. Once the group reaches an appropriate milestone, this will be consolidated and re-organized into more ...

KSI Example

Key Security Indicators (KSIs)

WORK IN PROGRESS The OSCAL Foundation's FedRAMP TFG elected to focus on [KSI-IAM-AAM] Identity and Access Management: Automated Account Management. This is an example of how KSIs could be implemented in OSCAL. It does not necessary reflect exactly what should ...

FedRAMP Deliverables

Representing the FedRAMP Certification Package Overview (CPO) and Security Decision Record (SDO) in OSCAL and translating between OSCAL and the FedRAMP-published bespoke schema. Although also FedRAMP Artifacts, KSIs are receiving separate focus.

FedRAMP TFG CR26 Efforts

CR26 Overview

FedRAMP TFG CR26 Efforts

DRAFT - PLEASE PROVIDE INPUT The following is a depiction of how the FedRAMP Published Artifacts, Deliverables and KSI Automation fit together under FedRAMP Consolidated Rules 2026 (CR26). The effort to map these in detail and produce related OSCAL content is ...

Component Patterns

Patterns that apply to components in component definitions (cDefs) and system security plans (SSPs).

New Page

Component Patterns

Component Relationships and Interactions

Component Patterns

Patterns for representing the relationships and interactions between components.

Relationships: Overview

Component Patterns Component Relationships and Interactions

In information systems, components interact with each other. Simple and complex component relationships can be represented accurately using OSCAL. Relationship Types Relationship representations include: third-party validations connectivity data flows compone...

Taxonomy

Key Security Indicators (KSIs)

DRAFT - Please review and provide feedback. Self-register via Login to leave comments. We defined the following DRAFT KSI Taxonomy to align with CR26 terminology and Security Decision Record (SDR) schema fields. We expanded on this where necessary; expansio...

Guiding Principles

Key Security Indicators (KSIs)

DRAFT - Please review and provide feedback. Self-register via Login to leave comments. We defined the following DRAFT guiding principles in alignment with the Taxonomy. Data Analysis: The Data Analysis must clearly define the intended result of data collect...

Overview

Key Security Indicators (KSIs)

Links to the OSCAL Foundation's FedRAMP Technology Focus Group (TFG) FedRAMP KSI efforts: Taxonomy Guiding Principles KSI Example Notes and Agreements

Overview

FedRAMP Published Artifacts

CR26 Deliverables Overview

FedRAMP Deliverables

DRAFT - PLEASE PROVIDE INPUT The following is an overview of how the FedRAMP CR26 Deliverables are represented using OSCAL models. Certification Package Overview (CPO): System details are very similar to legacy SSP front-matter. Requires summary of assess...

Workstreams

FedRAMP TFG CR26 Efforts

The OSCAL Foundation's FedRAMP TFG is currently focused on three workstreams realted to the FedRAMP PMO's Consolidated Rules 2026 (CR26): FedRAMP Published Artifacts: Representation of the FedRAPM Rules (FRRs), Key Security Indicator (KSI) definitions, and R...