Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

EPIC: Better Sharing of Compliance Documentation and SSPs #79

Closed
1 of 5 tasks
afeld opened this issue Aug 20, 2019 · 4 comments
Closed
1 of 5 tasks

EPIC: Better Sharing of Compliance Documentation and SSPs #79

afeld opened this issue Aug 20, 2019 · 4 comments

Comments

@afeld
Copy link
Contributor

afeld commented Aug 20, 2019

In my research for the FISMAtic project, "the lack of access to examples [of System Security Plans (SSPs)] came up...more than any other topic" by people that have been through an Authority to Operate (ATO) process. Lack of access to examples was also a blocker for that project and others like it trying to do analysis across SSPs. We have the power to solve this for TTS SSPs.

Might make sense to split some of those out to separate issues.

cc opencontrol/discuss#68

@afeld
Copy link
Contributor Author

afeld commented Aug 20, 2019

From @brittag:

Suggest reviewing our cloud.gov nonpublic training deck and our policy doc for this to see if they would help - https://docs.google.com/presentation/d/1uB4MlGCu8ZYUxjKVZKwicQ95MvLxaT4Mh93y6w79GPw/edit#slide=id.g1a2cf8d6b3_0_193 + https://github.com/18F/open-source-policy/blob/master/practice.md#protecting-sensitive-information - the good thing is that we have FedRAMP approval for those docs. we just haven’t yet tried applying to the SSP!

@afeld
Copy link
Contributor Author

afeld commented Aug 21, 2019

See also: email thread CUI Classification of GSA's System Security Plans.

@afeld
Copy link
Contributor Author

afeld commented Aug 29, 2019

Great quote from a colleague:

This is also why we want to publish our SSP (time for the circle back to the original question) - we had to invent a whole bunch of solutions to solve problems with mismatches between what the NIST Risk Management Framework expects (large company, traditional data center infrastructure, waterfall processes) and how a realistic cloud-native modern agile team works. So we want to publish those solutions so other people don’t have to reinvent them (reducing the cost of going through [ATO]) and (my dream) so that NIST can learn from them when revising the standards.

@its-a-lisa-at-work its-a-lisa-at-work added this to the Nov IRL milestone Nov 4, 2019
@JJediny JJediny changed the title As someone writing an SSP, I want access to examples EPIC: Better Sharing of Compliance Documentation and SSPs Nov 19, 2019
@its-a-lisa-at-work its-a-lisa-at-work removed this from the Nov IRL milestone Nov 23, 2019
@JJediny
Copy link
Member

JJediny commented Nov 27, 2019

Consolidating into #208

@JJediny JJediny closed this as completed Nov 27, 2019
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants