Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

SAP, SAR and POA&M Sample Files #639

Closed
7 tasks
brian-ruf opened this issue Mar 19, 2020 · 7 comments · Fixed by #681
Closed
7 tasks

SAP, SAR and POA&M Sample Files #639

brian-ruf opened this issue Mar 19, 2020 · 7 comments · Fixed by #681
Assignees
Labels
enhancement Scope: Content Development of OSCAL content and examples. User Story

Comments

@brian-ruf
Copy link
Contributor

brian-ruf commented Mar 19, 2020

User Story:

As an OSCAL syntax modeler, I need to verify and demonstrate the validity and viability of the OSCAL represent the information models for the security assessment plan (SAP), security assessment report (SAR), and plan of actions and milestones (POA&M), so that examples can be provided and the syntax usage can be demonstrated when applied to known scenarios.

Goals:

  • Create sample files representing a FedRAMP SAP, SAR, and POA&M using the Assessment Planning, Assessment Results, and POA&M models.

Dependencies:

Issue #621 SAP, SAR, and POA&M Syntax Modeling in Metaschema

Acceptance Criteria

  • All OSCAL website and readme documentation affected by the changes in this issue have been updated. Changes to the OSCAL website can be made in the docs/content directory of your branch.

  • A Pull Request (PR) is submitted that fully addresses the goals of this User Story. This issue is referenced in the PR.

  • The CI-CD build process runs without any reported errors on the PR. This can be confirmed by reviewing that all checks have passed in the PR.

  • All examples are complete and work with upstream OSCAL files, including FedRAMP SSP, FedRAMP Baseline/Profile, and NIST 800-53r4 Catalog.

  • Syntax is updated to reflect any issues or gaps

  • Examples are added to metaschema for assemblies, at a level appropriate to demonstrate usage in documentation.

  • Ensure FedRAMP extensions are removed from core OSCAL syntax and instead addressed in FedRAMP materials.

Notes:

These sample files will be developed in parallel to the development of OSCAL-based SAP, SAR, and POA&M guidance documents for FedRAMP, such that the files serve as NIST OSCAL examples, and support the guidance documents.

@brian-ruf brian-ruf changed the title SAP, SAR and POA&M Sample Files and Refinement SAP, SAR and POA&M Sample Files and Syntax Refinement Mar 19, 2020
@brian-ruf brian-ruf linked a pull request Jun 1, 2020 that will close this issue
8 tasks
@brian-ruf
Copy link
Contributor Author

FedRAMP sample files are HERE, but still subject to change. The SSP file is out of date.

@brian-ruf
Copy link
Contributor Author

Status 25-June-2020

In a meeting between @brianrufgsa, @david-waltermire-nist, and @wendellpiez we agreed that if the FedRAMP Automation repository is setup such that NIST can trust the validity of the OSCAL templates FedRAMP generated for SAP, SAR, and POA&M, that NIST would point to those as a FedRAMP use-case example.

Later NIST may generate more simplified examples of specific features included in the assessment plan, assessment results, and POA&M models.

@brian-ruf
Copy link
Contributor Author

In a meeting between @brianrufgsa and Cisco, it became apparent that the mitigating-factor assembly could benefit from prop/annotation fields to allow for extensions.

We should also evaluate the addition of a link/@href field, which could be used as a pointer to vendor support articles and other online information to consider when adjusting risk. This can currently be accomplished using a resource in the back-matter and linked using the subject-reference field; however, a direct link/@href field may be more appropriate in this instance.

@david-waltermire david-waltermire added Scope: Modeling Issues targeted at development of OSCAL formats Scope: Content Development of OSCAL content and examples. and removed Scope: Modeling Issues targeted at development of OSCAL formats labels Jul 2, 2020
@david-waltermire david-waltermire changed the title SAP, SAR and POA&M Sample Files and Syntax Refinement SAP, SAR and POA&M Sample Files Jul 2, 2020
@david-waltermire
Copy link
Contributor

@david-waltermire-nist will create a new issue tracking the FedRAMP repo CI/CD work that needs to be done, and a separate issue for updating the content readmes to point to the FedRAMP examples.

@brian-ruf
Copy link
Contributor Author

Added GSA/fedramp-automation#45 to track FedRAMP repo CI/CD work as described in @david-waltermire-nist status above.

@david-waltermire
Copy link
Contributor

This work depends on deployment of the CI/CD build in the FedRAMP Automation Repo, which is now complete. This wortk will continue in the next sprint.

@david-waltermire
Copy link
Contributor

The CI/CD build is complete and examples can be found in the FedRAMP automation repository,

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement Scope: Content Development of OSCAL content and examples. User Story
Projects
None yet
Development

Successfully merging a pull request may close this issue.

2 participants