fedramp-automation
fedramp-automation copied to clipboard
The requirement of having one user per responsible-role should be removed
-
This is a ...
- [x] concern - I think something needs to be different.
- [x] question - I didn't understand something.
- [ ] kudos - I found something helpful and want to encourage it in future FedRAMP publications.
- [ ] request - I would like to see something additional provided.
-
This relates to ...
- [ ] the FedRAMP OSCAL Registry (Excel File)
- [ ] the Guide to OSCAL-based FedRAMP Content (PDF)
- [ ] the Guide to OSCAL-based FedRAMP System Security Plans (SSP) (PDF)
- [ ] the Guide to OSCAL-based FedRAMP Security Assessment Plans (SAP) (PDF)
- [ ] the Guide to OSCAL-based FedRAMP Security Assessment Reports (SAR) (PDF)
- [ ] the Guide to OSCAL-based FedRAMP Plan of Action and Milestones (POA&M) (PDF)
- [ ] the FedRAMP SSP OSCAL Template (JSON or XML Format)
- [ ] the FedRAMP SAP OSCAL Template (JSON or XML Format)
- [ ] the FedRAMP SAR OSCAL Template (JSON or XML Format)
- [ ] the FedRAMP POA&M OSCAL Template (JSON or XML Format)
- [ ] General/Overall
- [x] Other
NOTE: For feedback related to the OSCAL syntax itself, please create or add to an issue in the NIST OSCAL Repository.
-
Where, exactly?
- For the registry, please indicate the tab and cell, or other clear identifier
- For the guide, please indicate the section number and printed page number (lower right corner)
- For the OSCAL XML or JSON files, please indicate XML or JSON; and indicate the line number, field id, or other clear location identifier UI Validator
-
What is your feedback? There exists a schematron check within the “SSP Template 13” section of the UI validator that checks that each responsible-role is referenced in
. This is problematic, due to the
tag specifically referencing a frontend user. Sometimes, the entity responsible for a role will not be one that directly interacts with a system that is recording these responsibilities. Therefore, there will not be a user tag that can be attributed to these entities. -
Is this report specifically related to the Word or Excel files from fedramp.gov? If so, please do not open an issue here. Follow the guidance in this repository's README and contact [email protected].
-
What version of OSCAL are you using? (Check our info on supported OSCAL versions) 1.0.4
-
What action would you like to see from the FedRAMP PMO? Either update requirement for users per responsible role or, if the requirement already accommodates this, address this bug in the UI Validator.
-
Other information (e.g. detailed explanation, related issues, suggestions how to fix, links for us to have context, eg. slack, gitter, etc)
This is a FedRAMP requirement stated on pg 37, Section 5.2 Responsible Roles and Parameter Assignments of the Guide to OSCAL-based FedRAMP System Security Plans.
"FedRAMP further requires the specified role-id must also have been referenced in the system-implementation/user assembly"
A change to the FedRAMP policy and documentation will be required before updates can be made to the validation tool.
This looks like a duplicate of #233.