You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
For the registry, please indicate the tab and cell, or other clear identifier
For the guide, please indicate the section number and printed page number (lower right corner)
For the OSCAL XML or JSON files, please indicate XML or JSON; and indicate the line number, field id, or other clear location identifier
section 4.9, page 33
What is your feedback?
There is no field shown in the example that displays what OSCAL data should fill out the Reference # column. If the guidance could be updated to explicitly state what should go in this column and where in the OSCAL that data can be found, that would be helpful.
The Reference # column in table 9.1 is intended to refer to one of the cryptographic modules in appendix Q.
This concept in OSCAL is achieved by:
having a software or hardwarecomponent for each cryptographic module (see section 4.10 on page 34)
for each service, having a servicecomponent that references the appropriate cryptographic module component via a link.
For example:
<system-implementation>
<!-- user -->
<component uuid="uuid-of-service" type="service">
<title>[SAMPLE]Service Name</title>
<description><p>Describe the service</p></description>
<purpose>Describe the purpose the service is needed.</purpose>
<link href="uuid-of-component-used-by" rel="used-by" />
<link href=" uuid-of-component-provided-by" rel="provided-by" />
<!-- REFERENCE # -->
<link href=" uuid-of-cryptographic-module-component" rel="depends-on" />
<status state="operational" />
<protocol name="http">
<port-range start="80" end="80" transport="TCP"/>
</protocol>
<protocol name="https">
<port-range start="443" end="443" transport="TCP"/>
</protocol>
</component>
<!-- Repeat the component assembly for each row in Table 9.1 -->
<!-- system-inventory -->
</system-implementation>
The following changes will be made:
OSCAL SSP Guide
-- Update section 4.9 ensuring that all of the columns in the Table 9.1 screenshot are clearly explained and represented in the sample OSCAL code snippet.
OSCAL SSP Guide (web version)
-- For planned Markdown version of the SSP Guide, also update Attachments section table by adding hyperlinks to the appropriate section / example for the appendices that can be represented in OSCAL machine-readable format.
OSCAL SSP Template
-- Fix example to match updated SSP guide
This is a ...
This relates to ...
NOTE: For feedback related to the OSCAL syntax itself, please create or add to an issue in the NIST OSCAL Repository.
section 4.9, page 33
There is no field shown in the example that displays what OSCAL data should fill out the Reference # column. If the guidance could be updated to explicitly state what should go in this column and where in the OSCAL that data can be found, that would be helpful.
Is this report specifically related to the Word or Excel files from fedramp.gov? If so, please do not open an issue here. Follow the guidance in this repository's README and contact info@fedramp..gov.
Yes
What version of OSCAL are you using? (Check our info on supported OSCAL versions)
1.0.4
Clarification on the field in question.
The text was updated successfully, but these errors were encountered: