AC-8 REQ does not have a response point in Baseline profile. How to address? #410
Labels
bug
Something isn't working
enhancement
New feature or request
scope: baselines
scope: documentation
Action Item
This is a ...
This relates to ...
NOTE: For issues related to the OSCAL syntax itself, please create or add to an issue in the NIST OSCAL Repository.
Describe the problem or enhancement
In manual SSP process, FedRAMP specific REQs were included in the base line and had sections to answer, like NIST CONTROL STATEMENTS. In FedRAMP HIGH Baseline Profile,
<style> </style>Example: AC-8 Req.
Additional FedRAMP Requirements and Guidance
Requirement 1: The service provider shall determine elements of the cloud environment that require the System Use Notification control. The elements of the cloud environment that require System Use Notification are approved and accepted by the JAB/AO.
Requirement 2: The service provider shall determine how System Use Notification is going to be verified and provide appropriate periodicity of the check. The System Use Notification verification and periodicity are approved and accepted by the JAB/AO. If performed as part of a Configuration Baseline check, then the % of items requiring setting that are checked and that pass (or fail) check can be provided.
Requirement 3: If not performed as part of a Configuration Baseline check, then there must be documented agreement on how to provide results of verification and the necessary periodicity of the verification by the service provider. The documented agreement on how to provide verification of the results are approved and accepted by the JAB/AO.
However, they do not have response points in OSCAL High baseline profile. Need to confirm that they have just rolled into AC-8 in general, or should they have response points (And a catalog specific to FedRAMP Requirements that are not included in the NIST catalog?)
Goals:
Determine how systems are supposed to handle control statements that were part of manual process, and do not have a counterpart in the new process. Where should that response data previously captured go?
If requirements need response points, requesting also objectives to be able to fully handle requirement through the models.
Dependencies:
Manual Process
Acceptance Criteria
{The items above are general acceptance criteria for all User Stories. Please describe anything else that must be completed for this issue to be considered resolved.}
Other Comments
FedRAMP HIGH
<title>AC-8 Additional FedRAMP Requirements and Guidance</title>
The service provider shall determine elements of the cloud environment
that require the System Use Notification control. The elements of the
cloud environment that require System Use Notification are approved and
accepted by the JAB/AO.
The service provider shall determine how System Use Notification is going
to be verified and provide appropriate periodicity of the check. The
System Use Notification verification and periodicity are approved and
accepted by the JAB/AO.
If performed as part of a Configuration Baseline
check, then the % of items requiring setting that are checked and that
pass (or fail) check can be provided.
If not performed as part of a Configuration Baseline check, then there
must be documented agreement on how to provide results of verification
and the necessary periodicity of the verification by the service
provider. The documented agreement on how to provide verification of the
results are approved and accepted by the JAB/AO.
The text was updated successfully, but these errors were encountered: