Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

audit what pieces of the System Security Plan aren't reflected in the schema #31

Open
afeld opened this issue Aug 19, 2016 · 2 comments

Comments

@afeld
Copy link
Member

afeld commented Aug 19, 2016

I suspect that there are many areas/fields/nuances of the FedRAMP SSP that aren't fields in the OpenControl schema that we need to capture. Someone should work with @brittag to identify them, think through which are the most important for us to capture (presumably which are going to require the most change the in for the SSP), then figure out how to incorporate them.

@afeld afeld added the HighBar label Aug 19, 2016
@brittag brittag removed their assignment Aug 19, 2016
@brittag
Copy link
Member

brittag commented Aug 19, 2016

I'd be excited to work with somebody on this - I figure the best way to go about it would be for a person familiar with the schema to put a meeting on my calendar and talk through it together. For example, right now when I look at that schema description, I don't understand how the component info gets transmogrified into the right parts of the SSP.

I've unassigned this from myself since I figure this should be assigned to that person I talk to. :D

@afeld
Copy link
Member Author

afeld commented Aug 28, 2016

@jcscottiii just found the "Additional FedRAMP Requirements and Guidance" tables in #29 (comment).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

3 participants