Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Baseline Documents OSCAL Version is 1.0.4 when 1.1.1 is Out #497

Closed
2 of 16 tasks
hahsan-ti opened this issue Sep 13, 2023 · 1 comment
Closed
2 of 16 tasks

Baseline Documents OSCAL Version is 1.0.4 when 1.1.1 is Out #497

hahsan-ti opened this issue Sep 13, 2023 · 1 comment
Assignees

Comments

@hahsan-ti
Copy link
Contributor

  • This is a ...

    • concern - I think something needs to be different.
    • question - I didn't understand something.
    • kudos - I found something helpful and want to encourage it in future FedRAMP publications.
    • request - I would like to see something additional provided.
  • This relates to ...

    • the FedRAMP OSCAL Registry (Excel File)
    • the Guide to OSCAL-based FedRAMP Content (PDF)
    • the Guide to OSCAL-based FedRAMP System Security Plans (SSP) (PDF)
    • the Guide to OSCAL-based FedRAMP Security Assessment Plans (SAP) (PDF)
    • the Guide to OSCAL-based FedRAMP Security Assessment Results (SAR) (PDF)
    • the Guide to OSCAL-based FedRAMP Plan of Action and Milestones (POA&M) (PDF)
    • the FedRAMP SSP OSCAL Template (JSON or XML Format)
    • the FedRAMP SAP OSCAL Template (JSON or XML Format)
    • the FedRAMP SAR OSCAL Template (JSON or XML Format)
    • the FedRAMP POA&M OSCAL Template (JSON or XML Format)
    • General/Overall
    • Other
  • Where, exactly?

  • In FedRAMP Rev 4 and 5 OSCAL files XML and others, the OSCAL version used is 1.0.4, when (at the time of creating this issue) 1.1.1 is out. For example see FedRAMP_rev5_HIGH-baseline-resolved-profile_catalog.xml line 8 or xpath: catalog/metadata/osca-version.
  • What is your feedback?

I would like to know why FedRAMP OSCAL files are behind in OSCAL versions. I'd assume that this number should be updated whenever there is a minor update -- I can live without patch updates.

I want to be using 1.1.1 but I'm using 1.0.4 because of the baseline documents.

  • What action would you like to see from the FedRAMP PMO?

Just a helpful comment :-)

  • Other information (e.g. detailed explanation, related issues, suggestions how to fix, links for us to have context, eg. slack, gitter, etc)
@volpet2014
Copy link
Contributor

FedRAMP is planning on updating to 1.1.1 by mid-October at the latest. We are working through validation issues from Rev 4 and Rev 5 baselines which are requiring changes to Schematron and Rev 5 profiles.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants