Information Types for for Leveraged Authorizations and External, Interconnected, and Unauthorized Systems #942
Open
14 tasks
Labels
enhancement
New feature or request
Constraint Task
As an SSP author, I need to ensure I am using the correct information types when documenting leveraged authorizations external services and interconnections.
Intended Outcome
Enforce the 800-60 allowed value list within components that represent external communication, identical to enforcement within
information-type
.Syntax Type
This is optional core OSCAL syntax.
Allowed Values
FedRAMP allowed values must be defined or verified.
Metapath(s) to Content
Purpose of the OSCAL Content
Aligns any reference of information type to 800-60 and enables the reference of information type impact information relative to the leveraged authorization or external service/interconnected system.
Dependencies
No response
Acceptance Criteria
oscal-cli metaschema metapath eval -e "expression"
.Other information
The allowed values were recently added/revised in PR # 917 in satisfaction of issue #890; however, the allowed values were only applied to
//information-type
. They also need to be applied to//component
as defined by the above xpath.The text was updated successfully, but these errors were encountered: