Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

FedRAMP SSP Guide - Section 4.9 and Section 7.3.2 compared (rev 5 compared to Rev 4) #101

Open
Telos-sa opened this issue Sep 12, 2023 · 1 comment
Assignees
Labels
bug Something isn't working documentation Improvements or additions to documentation

Comments

@Telos-sa
Copy link

Describe the bug

Documentation in rev-4, the tag "used-by" in component type "service" was a prop.
image

In Rev 5, in section 4.9 the tag is no part of the link, but in section 7.3.2 it is a prop.
image

Please provide guidance on what this should be. Is it a locally defined prop, as it was in Rev 4, or is it now the link, as defined by NIST?

image

Who is the bug affecting?

Anyone attempting to upgrade their submission package from rev 4 to rev 5, and was using the prop as defined by FedRAMP on rev 4.

What version of OSCAL are you using? (Check our info on supported OSCAL versions)

1.1.0 Attempting to do Rev 5

Expected behavior (i.e. solution)

Please provide guidance on what the expected behavior is, and what the schematron is checking for, since the documentation is inconsistent.

@Telos-sa Telos-sa added the bug Something isn't working label Sep 12, 2023
@volpet2014 volpet2014 added the documentation Improvements or additions to documentation label Sep 15, 2023
@Rene2mt
Copy link
Member

Rene2mt commented Oct 23, 2023

For rev5, FedRAMP has aligned with NIST which states:

When defining a service component where are relationship to other components is known, one or more link entries with rel values of provided-by and used-by can be used to link to the specific component identifier(s) that provide and use the service respectively.

Section 7.3.2 of the rev 5 SSP guide will be updated.

@aj-stein-gsa aj-stein-gsa transferred this issue from GSA/fedramp-automation Oct 25, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working documentation Improvements or additions to documentation
Projects
Status: 📋 Backlog
Development

No branches or pull requests

3 participants