fedramp-automation icon indicating copy to clipboard operation
fedramp-automation copied to clipboard

Are security-eauth-level and Digital Identity Determination required in <system-characteristics>?

Open telosBA opened this issue 2 years ago • 0 comments

  • This is a ...

    • [x] concern - I think something needs to be different.
    • [x] question - I didn't understand something.
    • [ ] kudos - I found something helpful and want to encourage it in future FedRAMP publications.
    • [ ] request - I would like to see something additional provided.
  • This relates to ...

    • [ ] the FedRAMP OSCAL Registry (Excel File)
    • [ ] the Guide to OSCAL-based FedRAMP Content (PDF)
    • [x] the Guide to OSCAL-based FedRAMP System Security Plans (SSP) (PDF)
    • [ ] the Guide to OSCAL-based FedRAMP Security Assessment Plans (SAP) (PDF)
    • [ ] the Guide to OSCAL-based FedRAMP Security Assessment Reports (SAR) (PDF)
    • [ ] the Guide to OSCAL-based FedRAMP Plan of Action and Milestones (POA&M) (PDF)
    • [x] the FedRAMP SSP OSCAL Template (JSON or XML Format)
    • [ ] the FedRAMP SAP OSCAL Template (JSON or XML Format)
    • [ ] the FedRAMP SAR OSCAL Template (JSON or XML Format)
    • [ ] the FedRAMP POA&M OSCAL Template (JSON or XML Format)
    • [ ] General/Overall
    • [ ] Other

NOTE: For feedback related to the OSCAL syntax itself, please create or add to an issue in the NIST OSCAL Repository.

  • Where, exactly?
    • For the registry, please indicate the tab and cell, or other clear identifier
    • For the guide, please indicate the section number and printed page number (lower right corner)
    • For the OSCAL XML or JSON files, please indicate XML or JSON; and indicate the line number, field id, or other clear location identifier

FedRAMP SSP Guide p.13 FedRAMP-SSP-OSCAL-Template.xml Lines 522-527

  • What is your feedback?

While noted as required in the FedRAMP SSP Guide, security-eauth-level is not included in NIST OSCAL Schema Additionally, the FedRAMP SSP Guide notes that IAL, AAL, and FAL are not required, but the validator returns an error when they are not included in the XML file.

1.0.2

  • What action would you like to see from the FedRAMP PMO?

Is security-eauth-level required despite not being included in OSCAL Schema?

identity-assurance-level, authenticator-assurance-level, and federation-assurance-level are listed as not required by FedRAMP but cause an error in validation when not present. Are they required?

  • Other information (e.g. detailed explanation, related issues, suggestions how to fix, links for us to have context, eg. slack, gitter, etc)

telosBA avatar May 06 '22 15:05 telosBA