Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Script to convert FedRAMP controls spreadsheet to opencontrols files #60

Open
rafael5 opened this issue Mar 23, 2019 · 2 comments
Open

Comments

@rafael5
Copy link

rafael5 commented Mar 23, 2019

Only a few (<20) controls are specified in the AWS opencontrols git:
https://github.com/opencontrol/aws-compliance

For FedRAMP-high we need all 421 controls implemented per the FedRAMP spreadsheet:
https://www.fedramp.gov/assets/resources/documents/FedRAMP_Security_Controls_Baseline.xlsx

Is it possible to write a script to auto-populate the AWS opencontrol files with the appropriate controls from the FedRAMP-high spreadsheet?

@rafael5 rafael5 changed the title Convert FedRAMP spreadsheet of all 421 controls to YAML Convert FedRAMP spreadsheet to AWS opencontrols files Mar 23, 2019
@rafael5 rafael5 changed the title Convert FedRAMP spreadsheet to AWS opencontrols files Convert FedRAMP-high spreadsheet to opencontrols files for AWS Mar 23, 2019
@rafael5 rafael5 changed the title Convert FedRAMP-high spreadsheet to opencontrols files for AWS Script to convert FedRAMP controls spreadsheet to opencontrols files Mar 23, 2019
@afeld
Copy link
Member

afeld commented Mar 24, 2019

Hey, thanks for posting! First, a couple of clarifications:

There used to be a repository for the former, but it was recently deleted since it wasn't being maintained. I think it would be relatively straightforward to write a script to create OpenControl Certification YAML files from the spreadsheet you linked above. See also: using them from OSCAL.

Re: AWS control implementations, see opencontrol/aws-compliance#5.

@its-a-lisa
Copy link

Suggest closing once opencontrol/website#46 gets merged

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants