Skip to content

brian-ruf/fedramp-automation

 
 

Repository files navigation

FedRAMP

Federal Risk and Authorization Management Program (FedRAMP) Automation

Based on the Open Security Controls Assessment Language (OSCAL)

February 25, 2021

Guides and Templates updated to OSCAL Release Candidate #2 (RC-2) Syntax

The FedRAMP Program Management Office (PMO) has drafted FedRAMP-specific extensions and guidance to ensure our stakeholders can fully express a FedRAMP Security Authorization Package using NIST's OSCAL SSP syntax.

To accompany these guides, the FedRAMP PMO has also drafted OSCAL files in XML and JSON formats to serve as an example and template for each major deliverable.

We Want Your Feedback!

The FedRAMP PMO is releasing the following files for public review and comment:

  • FedRAMP OSCAL Registry (Updated): This registry is the authoritative source for all FedRAMP extensions to the OSCAL syntax, FedRAMP-defined identifiers, and accepted values. The draft for public comment is available here.

  • Implementation Guides: These documents enables tool developers to generate OSCAL-based FedRAMP deliverabes that are fully compliant with FedRAMP’s extensions, defined identifiers, conformity tags, and acceptable values. The drafts for public comment are available here.

  • OSCAL-based FedRAMP Templates: The template files are pre-populated with FedRAMP extensions, defined-identifiers, and conformity tags where practical. They also include sample data, and are the basis for their respective guidance documents above. The drafts for public comment are available in both XML and JSON formats here.

  • FedRAMP Baselines (Updated): The FedRAMP baselines for High, Moderate, Low, and Tailored for Low Impact-Software as a Service (LI-SaaS) in OSCAL (XML and JSON formats) are available here.

Please ask questions or provide feedback on the items above above either via email to [email protected], as a comment to an existing issue, or as a new issue.

Dependencies

FedRAMP's work is based on NIST's OSCAL 1.0.0-Milestone3 release, and requires an understanding of the core OSCAL syntax, as well as NIST-provided resources to function correctly.

IMPORTANT: NIST has made minor syntax updates since releasing Mielstone 3, which are also reflected in these guides. The most notable are changes to the POA&M syntax, which renamed "results" to "poam-items" and "finding" to "poam-item".

The following NIST resources are available:

NIST offers a complete package containing the NIST OSCAL converters, syntax validation tools, 800-53 and FedRAMP baselines content is available for download in both ZIP and BZ2 formats.

Please ask questions or provide feedback on the above NIST dependencie either via email to [email protected], as a comment to an existing issue, or as a new issue via the NIST OSCAL GitHub site.

FedRAMP looks forward to receiving your comments and sharing additional progress.

Releases

No releases published

Packages

No packages published

Languages

  • HTML 91.6%
  • XSLT 8.4%