Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Leveraged Authorizations, External Systems, Interconnections, and Unauthorized Systems #126

Open
brian-ruf opened this issue Nov 25, 2024 · 0 comments
Assignees
Labels
documentation Improvements or additions to documentation

Comments

@brian-ruf
Copy link

As an implementer of tools to create FedRAMP-compliant OSCAL-based SSP content, I need the documentation for leveraged authorizations, interconnections, and Unauthorized Systems to be accurate and up-to-date.

GSA/fedramp-automation#807 and GSA/fedramp-automation#808 provide revised FedRAMP OSCAL content modeling for:

  • Leveraged Authorizations (FedRAMP Rev 5 Word Template table 6.1)
  • External Systems and Services not having a FedRAMP Authorization(FedRAMP Rev 5 Word Template table 7.1)

These issues lay out the following scenarios:

  • Leveraged Authorization
  • Authorized Service of a Leveraged Authorization
  • Non-Authorized Service of a Leveraged Authorization
  • An interconnection between this system and an external system
  • A service from an external system other than the leveraged system
  • A service from this system offered to external systems
  • A CLI that connects to leveraged or external systems

There are many similarities and a few subtle, yet important differences between these scenarios. Each must be represented in the documentation and explained. They are best created/revised collectively.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
documentation Improvements or additions to documentation
Projects
Status: 🏗 In progress
Development

No branches or pull requests

2 participants