diff --git a/shared/references/oscal/profiles/fedramp_rev5_high/profile.json b/shared/references/oscal/profiles/fedramp_rev5_high/profile.json index 12ce86b93f7..9226dc015ad 100644 --- a/shared/references/oscal/profiles/fedramp_rev5_high/profile.json +++ b/shared/references/oscal/profiles/fedramp_rev5_high/profile.json @@ -1,11 +1,11 @@ { "profile": { - "uuid": "9af0a7d3-252c-4f18-9baf-4f10e82bfac8", + "uuid": "2ef3cdd1-6928-494b-b2ef-593e774fae38", "metadata": { "title": "FedRAMP Rev 5 High Baseline", - "published": "2023-08-31T00:00:00+00:00", - "last-modified": "2023-08-31T00:00:00+00:00", - "version": "fedramp-2.0.0-oscal1.0.4", + "published": "2024-09-24T02:24:00+00:00", + "last-modified": "2024-09-24T02:24:00+00:00", + "version": "fedramp2.1.0-oscal1.0.4", "oscal-version": "1.0.4", "roles": [ { @@ -2027,7 +2027,7 @@ "param-id": "ps-03.03_odp", "constraints": [ { - "description": "personnel screening criteria – as required by specific information" + "description": "personnel screening criteria - as required by specific information" } ] }, @@ -2568,7 +2568,7 @@ ] }, { - "param-id": "si-03_odp.05", + "param-id": "si-03_odp.06", "constraints": [ { "description": "administrator or defined security personnel near-realtime" @@ -2730,1352 +2730,1915 @@ ], "alters": [ { - "control-id": "ac-2.3", + "control-id": "ac-1", "adds": [ { - "position": "ending", - "by-id": "ac-2.3_smt", - "parts": [ + "position": "starting", + "by-id": "ac-1_obj.a-1", + "props": [ { - "id": "ac-2.3_fr", - "name": "item", - "title": "AC-2 (3) Additional FedRAMP Requirements and Guidance", - "parts": [ - { - "id": "ac-2.3_fr_smt.1", - "name": "item", - "props": [ - { - "name": "label", - "value": "Requirement:" - } - ], - "prose": "The service provider defines the time period for non-user accounts (e.g., accounts associated with devices). The time periods are approved and accepted by the JAB/AO. Where user management is a function of the service, reports of activity of consumer users shall be made available." - }, - { - "id": "ac-2.3_fr_smt.2", - "name": "item", - "props": [ - { - "name": "label", - "value": "(d) Requirement:" - } - ], - "prose": "The service provider defines the time period of inactivity for device identifiers." - }, - { - "id": "ac-2.3_fr_gdn.1", - "name": "guidance", - "props": [ - { - "name": "label", - "value": "Guidance:" - } - ], - "prose": "For DoD clouds, see DoD cloud website for specific DoD requirements that go above and beyond FedRAMP https://public.cyber.mil/dccs/." - } - ] + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ac-1_obj.a-2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ac-1_obj.a-3", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ac-1_obj.a-4", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ac-1_obj.a.1.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ac-1_obj.a.1.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ac-1_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ac-1_obj.c.1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ac-1_obj.c.2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ac-1_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point.", + "remarks": "This response must address all control sub-statement requirements." + } + ] + }, + { + "position": "starting", + "by-id": "ac-1_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ac-1_smt.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point.", + "remarks": "This response must address all control sub-statement requirements." } ] } ] }, { - "control-id": "ac-2.5", + "control-id": "ac-10", "adds": [ { - "position": "ending", - "by-id": "ac-2.5_smt", - "parts": [ + "position": "starting", + "by-id": "ac-10_obj", + "props": [ { - "id": "ac-2.5_fr", - "name": "item", - "title": "AC-2 (5) Additional FedRAMP Requirements and Guidance", - "parts": [ - { - "id": "ac-2.5_fr_gdn.1", - "name": "guidance", - "props": [ - { - "name": "label", - "value": "Guidance:" - } - ], - "prose": "Should use a shorter timeframe than AC-12." - } - ] + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ac-10_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." } ] } ] }, { - "control-id": "ac-2.9", + "control-id": "ac-11", "adds": [ { - "position": "ending", - "by-id": "ac-2.9_smt", - "parts": [ + "position": "starting", + "by-id": "ac-11_obj.a", + "props": [ { - "id": "ac-2.9_fr", - "name": "item", - "title": "AC-2 (9) Additional FedRAMP Requirements and Guidance", - "parts": [ - { - "id": "ac-2.9_fr_smt.1", - "name": "item", - "props": [ - { - "name": "label", - "value": "Requirement:" - } - ], - "prose": "Required if shared/group accounts are deployed." - } - ] + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ac-11_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ac-11_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ac-11_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." } ] } ] }, { - "control-id": "ac-2.12", + "control-id": "ac-11.1", "adds": [ { - "position": "ending", - "by-id": "ac-2.12_smt", - "parts": [ + "position": "starting", + "by-id": "ac-11.1_obj", + "props": [ { - "id": "ac-2.12_fr", - "name": "item", - "title": "AC-2 (12) Additional FedRAMP Requirements and Guidance", - "parts": [ - { - "id": "ac-2.12_fr_smt.1", - "name": "item", - "props": [ - { - "name": "label", - "value": "(a) Requirement:" - } - ], - "prose": "Required for privileged accounts." - }, - { - "id": "ac-2.12_fr_smt.2", - "name": "item", - "props": [ - { - "name": "label", - "value": "(b) Requirement:" - } - ], - "prose": "Required for privileged accounts." - } - ] + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ac-11.1_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." } ] } ] }, { - "control-id": "ac-4.4", + "control-id": "ac-12", "adds": [ { - "position": "ending", - "by-id": "ac-4.4_smt", - "parts": [ + "position": "starting", + "by-id": "ac-12_obj", + "props": [ { - "id": "ac-4.4_fr", - "name": "item", - "title": "AC-4 (4) Additional FedRAMP Requirements and Guidance", - "parts": [ - { - "id": "ac-4.4_fr_smt.1", - "name": "item", - "props": [ - { - "name": "label", - "value": "Requirement:" - } - ], - "prose": "The service provider must support Agency requirements to comply with M-21-31 (https://www.whitehouse.gov/wp-content/uploads/2021/08/M-21-31-Improving-the-Federal-Governments-Investigative-and-Remediation-Capabilities-Related-to-Cybersecurity-Incidents.pdf) and M-22-09 (https://www.whitehouse.gov/wp-content/uploads/2022/01/M-22-09.pdf)." - } - ] + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ac-12_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." } ] } ] }, { - "control-id": "ac-5", + "control-id": "ac-14", "adds": [ { - "position": "ending", - "by-id": "ac-5_smt", - "parts": [ + "position": "starting", + "by-id": "ac-14_obj.a", + "props": [ { - "id": "ac-5_fr", - "name": "item", - "title": "AC-5 Additional FedRAMP Requirements and Guidance", - "parts": [ - { - "id": "ac-5_fr_gdn.1", - "name": "guidance", - "props": [ - { - "name": "label", - "value": "Guidance:" - } - ], - "prose": "CSPs have the option to provide a separation of duties matrix as an attachment to the SSP." - } - ] + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" } ] - } - ] - }, - { - "control-id": "ac-6.2", - "adds": [ + }, { - "position": "ending", - "by-id": "ac-6.2_smt", - "parts": [ + "position": "starting", + "by-id": "ac-14_obj.b", + "props": [ { - "id": "ac-6.2_fr", - "name": "item", - "title": "AC-6 (2) Additional FedRAMP Requirements and Guidance", - "parts": [ - { - "id": "ac-6.2_fr_gdn.1", - "name": "guidance", - "props": [ - { - "name": "label", - "value": "Guidance:" - } - ], - "prose": "Examples of security functions include but are not limited to: establishing system accounts, configuring access authorizations (i.e., permissions, privileges), setting events to be audited, and setting intrusion detection parameters, system programming, system and security administration, other privileged functions." - } - ] + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" } ] - } - ] - }, - { - "control-id": "ac-7", - "adds": [ + }, { - "position": "ending", - "by-id": "ac-7_smt", - "parts": [ + "position": "starting", + "by-id": "ac-14_smt.a", + "props": [ { - "id": "ac-7_fr", - "name": "item", - "title": "AC-7 Additional FedRAMP Requirements and Guidance", - "parts": [ - { - "id": "ac-7_fr_smt.1", - "name": "item", - "props": [ - { - "name": "label", - "value": "Requirement:" - } - ], - "prose": "In alignment with NIST SP 800-63B." - } - ] + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." } ] - } - ] - }, - { - "control-id": "ac-8", - "adds": [ + }, { - "position": "ending", - "by-id": "ac-8_smt", - "parts": [ + "position": "starting", + "by-id": "ac-14_smt.b", + "props": [ { - "id": "ac-8_fr", - "name": "item", - "title": "AC-8 Additional FedRAMP Requirements and Guidance", - "parts": [ - { - "id": "ac-8_fr_smt.1", - "name": "item", - "props": [ - { - "name": "label", - "value": "Requirement:" - } - ], - "prose": "The service provider shall determine elements of the cloud environment that require the System Use Notification control. The elements of the cloud environment that require System Use Notification are approved and accepted by the JAB/AO." - }, - { - "id": "ac-8_fr_smt.2", - "name": "item", - "props": [ - { - "name": "label", - "value": "Requirement:" - } - ], - "prose": "The service provider shall determine how System Use Notification is going to be verified and provide appropriate periodicity of the check. The System Use Notification verification and periodicity are approved and accepted by the JAB/AO." - }, - { - "id": "ac-8_fr_smt.3", - "name": "item", - "props": [ - { - "name": "label", - "value": "Requirement:" - } - ], - "prose": "If not performed as part of a Configuration Baseline check, then there must be documented agreement on how to provide results of verification and the necessary periodicity of the verification by the service provider. The documented agreement on how to provide verification of the results are approved and accepted by the JAB/AO." - }, - { - "id": "ac-8_fr_gdn.1", - "name": "guidance", - "props": [ - { - "name": "label", - "value": "Guidance:" - } - ], - "prose": "If performed as part of a Configuration Baseline check, then the % of items requiring setting that are checked and that pass (or fail) check can be provided." - } - ] + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." } ] } ] }, { - "control-id": "ac-20", + "control-id": "ac-17", "adds": [ { - "position": "ending", - "by-id": "ac-20_smt", - "parts": [ + "position": "starting", + "by-id": "ac-17_obj.a", + "props": [ { - "id": "ac-20_fr", - "name": "item", - "title": "AC-20 Additional FedRAMP Requirements and Guidance", - "parts": [ - { - "id": "ac-20_fr_gdn.1", - "name": "guidance", - "props": [ - { - "name": "label", - "value": "Guidance:" - } - ], - "prose": "The interrelated controls of AC-20, CA-3, and SA-9 should be differentiated as follows:\n\nAC-20 describes system access to and from external systems.\n\nCA-3 describes documentation of an agreement between the respective system owners when data is exchanged between the CSO and an external system.\n\nSA-9 describes the responsibilities of external system owners. These responsibilities would typically be captured in the agreement required by CA-3." - } - ] + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ac-17_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ac-17_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ac-17_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." } ] } ] }, { - "control-id": "au-2", + "control-id": "ac-17.1", "adds": [ { - "position": "ending", - "by-id": "au-2_smt", - "parts": [ + "position": "starting", + "by-id": "ac-17.1_obj", + "props": [ { - "id": "au-2_fr", - "name": "item", - "title": "AU-2 Additional FedRAMP Requirements and Guidance", - "parts": [ - { - "id": "au-2_fr_smt.1", - "name": "item", - "props": [ - { - "name": "label", - "value": "Requirement:" - } - ], - "prose": "Coordination between service provider and consumer shall be documented and accepted by the JAB/AO." - }, - { - "id": "au-2_fr_gdn.1", - "name": "guidance", - "props": [ - { - "name": "label", - "value": "(e) Guidance:" - } - ], - "prose": "Annually or whenever changes in the threat environment are communicated to the service provider by the JAB/AO." - } - ] + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ac-17.1_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." } ] } ] }, { - "control-id": "au-3.1", + "control-id": "ac-17.2", "adds": [ { - "position": "ending", - "by-id": "au-3.1_smt", - "parts": [ + "position": "starting", + "by-id": "ac-17.2_obj", + "props": [ { - "id": "au-3.1_fr", - "name": "item", - "title": "AU-3 (1) Additional FedRAMP Requirements and Guidance", - "parts": [ - { - "id": "au-3.1_fr_gdn.1", - "name": "guidance", - "props": [ - { - "name": "label", - "value": "Guidance:" - } - ], - "prose": "For client-server transactions, the number of bytes sent and received gives bidirectional transfer information that can be helpful during an investigation or inquiry." - } - ] + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ac-17.2_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ac-17.2", + "props": [ + { + "name": "CORE", + "ns": "https://fedramp.gov/ns/oscal", + "value": "true" } ] } ] }, { - "control-id": "au-6", + "control-id": "ac-17.3", "adds": [ { - "position": "ending", - "by-id": "au-6_smt", - "parts": [ + "position": "starting", + "by-id": "ac-17.3_obj", + "props": [ { - "id": "au-6_fr", - "name": "item", - "title": "AU-6 Additional FedRAMP Requirements and Guidance", - "parts": [ - { - "id": "au-6_fr_smt.1", - "name": "item", - "props": [ - { - "name": "label", - "value": "Requirement:" - } - ], - "prose": "Coordination between service provider and consumer shall be documented and accepted by the JAB/AO. In multi-tenant environments, capability and means for providing review, analysis, and reporting to consumer for data pertaining to consumer shall be documented." - } - ] + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ac-17.3_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." } ] } ] }, { - "control-id": "au-6.6", + "control-id": "ac-17.4", "adds": [ { - "position": "ending", - "by-id": "au-6.6_smt", - "parts": [ + "position": "starting", + "by-id": "ac-17.4_obj.a-1", + "props": [ { - "id": "au-6.6_fr", - "name": "item", - "title": "AU-6 (6) Additional FedRAMP Requirements and Guidance", - "parts": [ - { - "id": "au-6.6_fr_smt.1", - "name": "item", - "props": [ - { - "name": "label", - "value": "Requirement:" - } - ], - "prose": "Coordination between service provider and consumer shall be documented and accepted by the JAB/AO." - } - ] + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ac-17.4_obj.a-3", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ac-17.4_obj.a-2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ac-17.4_obj.a-4", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ac-17.4_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ac-17.4_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ac-17.4_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." } ] } ] }, { - "control-id": "au-9.3", + "control-id": "ac-18", "adds": [ { - "position": "ending", - "by-id": "au-9.3_smt", - "parts": [ + "position": "starting", + "by-id": "ac-18_obj.a", + "props": [ { - "id": "au-9.3_fr", - "name": "item", - "title": "AU-9 (3) Additional FedRAMP Requirements and Guidance", - "parts": [ - { - "id": "au-9.3_fr_gdn.1", - "name": "guidance", - "props": [ - { - "name": "label", - "value": "Guidance:" - } - ], - "prose": "Note that this enhancement requires the use of cryptography which must be compliant with Federal requirements and utilize FIPS validated or NSA approved cryptography (see SC-13.)" - } - ] + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ac-18_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ac-18_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ac-18_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." } ] } ] }, { - "control-id": "au-11", + "control-id": "ac-18.1", "adds": [ { - "position": "ending", - "by-id": "au-11_smt", - "parts": [ + "position": "starting", + "by-id": "ac-18.1_obj-1", + "props": [ { - "id": "au-11_fr", - "name": "item", - "title": "AU-11 Additional FedRAMP Requirements and Guidance", - "parts": [ - { - "id": "au-11_fr_smt.1", - "name": "item", - "props": [ - { - "name": "label", - "value": "Requirement:" - } - ], - "prose": "The service provider retains audit records on-line for at least ninety days and further preserves audit records off-line for a period that is in accordance with NARA requirements." - }, - { - "id": "au-11_fr_smt.2", - "name": "item", - "props": [ - { - "name": "label", - "value": "Requirement:" - } - ], - "prose": "The service provider must support Agency requirements to comply with M-21-31 (https://www.whitehouse.gov/wp-content/uploads/2021/08/M-21-31-Improving-the-Federal-Governments-Investigative-and-Remediation-Capabilities-Related-to-Cybersecurity-Incidents.pdf)" - }, - { - "id": "au-11_fr_gdn.1", - "name": "guidance", - "props": [ - { - "name": "label", - "value": "Guidance:" - } - ], - "prose": "The service provider is encouraged to align with M-21-31 where possible" - } - ] + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ac-18.1_obj-2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ac-18.1_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." } ] } ] }, { - "control-id": "ca-2", + "control-id": "ac-18.3", "adds": [ { - "position": "ending", - "by-id": "ca-2_smt", - "parts": [ + "position": "starting", + "by-id": "ac-18.3_obj", + "props": [ { - "id": "ca-2_fr", - "name": "item", - "title": "CA-2 Additional FedRAMP Requirements and Guidance", - "parts": [ - { - "id": "ca-2_fr_gdn.1", - "name": "guidance", - "props": [ - { - "name": "label", - "value": "Guidance:" - } - ], - "prose": "Reference FedRAMP Annual Assessment Guidance." - } - ] + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ac-18.3_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." } ] } ] }, { - "control-id": "ca-2.1", + "control-id": "ac-18.4", "adds": [ { - "position": "ending", - "by-id": "ca-2.1_smt", - "parts": [ + "position": "starting", + "by-id": "ac-18.4_obj", + "props": [ { - "id": "ca-2.1_fr", - "name": "item", - "title": "CA-2 (1) Additional FedRAMP Requirements and Guidance", - "parts": [ - { - "id": "ca-2.1_fr_smt.1", - "name": "item", - "props": [ - { - "name": "label", - "value": "Requirement:" - } - ], - "prose": "For JAB Authorization, must use an accredited 3PAO." - } - ] + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ac-18.4_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." } ] } ] }, { - "control-id": "ca-2.2", + "control-id": "ac-18.5", "adds": [ { - "position": "ending", - "by-id": "ca-2.2_smt", - "parts": [ + "position": "starting", + "by-id": "ac-18.5_obj-1", + "props": [ { - "id": "ca-2.2_fr", - "name": "item", - "title": "CA-2 (2) Additional FedRAMP Requirements and Guidance", - "parts": [ - { - "id": "ca-2.2_fr_smt.1", - "name": "item", - "props": [ - { - "name": "label", - "value": "Requirement:" - } - ], - "prose": "To include 'announced', 'vulnerability scanning'" - } - ] + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ac-18.5_obj-2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ac-18.5_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." } ] } ] }, { - "control-id": "ca-5", + "control-id": "ac-19", "adds": [ { - "position": "ending", - "by-id": "ca-5_smt", - "parts": [ + "position": "starting", + "by-id": "ac-19_obj.a", + "props": [ { - "id": "ca-5_fr", - "name": "item", - "title": "CA-5 Additional FedRAMP Requirements and Guidance", - "parts": [ - { - "id": "ca-5_fr_smt.1", - "name": "item", - "props": [ - { - "name": "label", - "value": "Requirement:" - } - ], - "prose": "POA&Ms must be provided at least monthly." - }, - { - "id": "ca-5_fr_gdn.1", - "name": "guidance", - "props": [ - { - "name": "label", - "value": "Guidance:" - } - ], - "prose": "Reference FedRAMP-POAM-Template" - } - ] + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" } ] - } - ] - }, - { - "control-id": "ca-6", - "adds": [ + }, { - "position": "ending", - "by-id": "ca-6_smt", - "parts": [ + "position": "starting", + "by-id": "ac-19_obj.b", + "props": [ { - "id": "ca-6_fr", - "name": "item", - "title": "CA-6 Additional FedRAMP Requirements and Guidance", - "parts": [ - { - "id": "ca-6_fr_gdn.1", - "name": "guidance", - "props": [ - { - "name": "label", - "value": "(e) Guidance:" - } - ], - "prose": "Significant change is defined in NIST Special Publication 800-37 Revision 2, Appendix F and according to FedRAMP Significant Change Policies and Procedures. The service provider describes the types of changes to the information system or the environment of operations that would impact the risk posture. The types of changes are approved and accepted by the JAB/AO." - } - ] + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" } ] - } - ] - }, - { - "control-id": "ca-7", - "adds": [ + }, { - "position": "ending", - "by-id": "ca-7_smt", - "parts": [ + "position": "starting", + "by-id": "ac-19_smt.a", + "props": [ { - "id": "ca-7_fr", - "name": "item", - "title": "CA-7 Additional FedRAMP Requirements and Guidance", - "parts": [ - { - "id": "ca-7_fr_smt.1", - "name": "item", - "props": [ - { - "name": "label", - "value": "Requirement:" - } - ], - "prose": "Operating System, Database, Web Application, Container, and Service Configuration Scans: at least monthly. All scans performed by Independent Assessor: at least annually." - }, - { - "id": "ca-7_fr_smt.2", - "name": "item", - "props": [ - { - "name": "label", - "value": "Requirement:" - } - ], - "prose": "CSOs with more than one agency ATO must implement a collaborative Continuous Monitoring (ConMon) approach described in the FedRAMP Guide for Multi-Agency Continuous Monitoring. This requirement applies to CSOs authorized via the Agency path as each agency customer is responsible for performing ConMon oversight. It does not apply to CSOs authorized via the JAB path because the JAB performs ConMon oversight." - }, - { - "id": "ca-7_fr_gdn.1", - "name": "guidance", - "props": [ - { - "name": "label", - "value": "Guidance:" - } - ], - "prose": "FedRAMP does not provide a template for the Continuous Monitoring Plan. CSPs should reference the FedRAMP Continuous Monitoring Strategy Guide when developing the Continuous Monitoring Plan." - } - ] + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." } ] - } - ] - }, - { - "control-id": "ca-8", - "adds": [ + }, { - "position": "ending", - "by-id": "ca-8_smt", - "parts": [ + "position": "starting", + "by-id": "ac-19_smt.b", + "props": [ { - "id": "ca-8_fr", - "name": "item", - "title": "CA-8 Additional FedRAMP Requirements and Guidance", - "parts": [ - { - "id": "ca-8_fr_gdn.1", - "name": "guidance", - "props": [ - { - "name": "label", - "value": "Guidance:" - } - ], - "prose": "Reference the FedRAMP Penetration Test Guidance." - } - ] + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." } ] } ] }, { - "control-id": "ca-8.2", + "control-id": "ac-19.5", "adds": [ { - "position": "ending", - "by-id": "ca-8.2_smt", - "parts": [ + "position": "starting", + "by-id": "ac-19.5_obj", + "props": [ { - "id": "ca-8.2_fr", - "name": "item", - "title": "CM-2 Additional FedRAMP Requirements and Guidance", - "parts": [ - { - "id": "ca-8.2_fr_gdn.1", - "name": "guidance", - "props": [ - { - "name": "label", - "value": "Guidance:" - } - ], - "prose": "See the FedRAMP Documents page> Penetration Test Guidance\n\nhttps://www.FedRAMP.gov/documents/" - } - ] + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" } ] - } - ] - }, - { - "control-id": "cm-2", - "adds": [ + }, { - "position": "ending", - "by-id": "cm-2_smt", - "parts": [ + "position": "starting", + "by-id": "ac-19.5_smt", + "props": [ { - "id": "cm-2_fr", - "name": "item", - "title": "CM-2 Additional FedRAMP Requirements and Guidance", - "parts": [ - { - "id": "cm-2_fr_gdn.1", - "name": "guidance", - "props": [ - { - "name": "label", - "value": "(b)(1) Guidance:" - } - ], - "prose": "Significant change is defined in NIST Special Publication 800-37 Revision 2, Appendix F." - } - ] + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." } ] } ] }, { - "control-id": "cm-3", + "control-id": "ac-2", "adds": [ { - "position": "ending", - "by-id": "cm-3_smt", - "parts": [ + "position": "starting", + "by-id": "ac-2_obj.a-1", + "props": [ { - "id": "cm-3_fr", - "name": "item", - "title": "CM-3 Additional FedRAMP Requirements and Guidance", - "parts": [ - { - "id": "cm-3_fr_smt.1", - "name": "item", - "props": [ - { - "name": "label", - "value": "Requirement:" - } - ], - "prose": "The service provider establishes a central means of communicating major changes to or developments in the information system or environment of operations that may affect its services to the federal government and associated service consumers (e.g., electronic bulletin board, web status page). The means of communication are approved and accepted by the JAB/AO." - }, - { - "id": "cm-3_fr_gdn.1", - "name": "guidance", - "props": [ - { - "name": "label", - "value": "(e) Guidance:" - } - ], - "prose": "In accordance with record retention policies and procedures." - } - ] + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" } ] - } - ] - }, - { - "control-id": "cm-6", - "adds": [ + }, { - "position": "ending", - "by-id": "cm-6_smt", - "parts": [ + "position": "starting", + "by-id": "ac-2_obj.a-2", + "props": [ { - "id": "cm-6_fr", - "name": "item", - "title": "CM-6 Additional FedRAMP Requirements and Guidance", - "parts": [ - { - "id": "cm-6_fr_smt.1", - "name": "item", - "props": [ - { - "name": "label", - "value": "(a) Requirement 1:" - } - ], - "prose": "The service provider shall use the DoD STIGs to establish configuration settings; Center for Internet Security up to Level 2 (CIS Level 2) guidelines shall be used if STIGs are not available; Custom baselines shall be used if CIS is not available." - }, - { - "id": "cm-6_fr_smt.2", - "name": "item", - "props": [ - { - "name": "label", - "value": "(a) Requirement 2:" - } - ], - "prose": "The service provider shall ensure that checklists for configuration settings are Security Content Automation Protocol (SCAP) validated or SCAP compatible (if validated checklists are not available)." - }, - { - "id": "cm-6_fr_gdn.1", - "name": "guidance", - "props": [ - { - "name": "label", - "value": "Guidance:" - } - ], - "prose": "Compliance checks are used to evaluate configuration settings and provide general insight into the overall effectiveness of configuration management activities. CSPs and 3PAOs typically combine compliance check findings into a single CM-6 finding, which is acceptable. However, for initial assessments, annual assessments, and significant change requests, FedRAMP requires a clear understanding, on a per-control basis, where risks exist. Therefore, 3PAOs must also analyze compliance check findings as part of the controls assessment. Where a direct mapping exists, the 3PAO must document additional findings per control in the corresponding SAR Risk Exposure Table (RET), which are then documented in the CSP’s Plan of Action and Milestones (POA&M). This will likely result in the details of individual control findings overlapping with those in the combined CM-6 finding, which is acceptable.\n\nDuring monthly continuous monitoring, new findings from CSP compliance checks may be combined into a single CM-6 POA&M item. CSPs are not required to map the findings to specific controls because controls are only assessed during initial assessments, annual assessments, and significant change requests." - } - ] + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" } ] - } - ] - }, - { - "control-id": "cm-7", - "adds": [ + }, { - "position": "ending", - "by-id": "cm-7_smt", - "parts": [ + "position": "starting", + "by-id": "ac-2_obj.b", + "props": [ { - "id": "cm-7_fr", - "name": "item", - "title": "CM-7 Additional FedRAMP Requirements and Guidance", - "parts": [ - { - "id": "cm-7_fr_smt.1", - "name": "item", - "props": [ - { - "name": "label", - "value": "(b) Requirement:" - } - ], - "prose": "The service provider shall use Security guidelines (See CM-6) to establish list of prohibited or restricted functions, ports, protocols, and/or services or establishes its own list of prohibited or restricted functions, ports, protocols, and/or services if STIGs or CIS is not available." - } - ] + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" } ] - } - ] - }, - { - "control-id": "cm-7.2", - "adds": [ + }, { - "position": "ending", - "by-id": "cm-7.2_smt", - "parts": [ + "position": "starting", + "by-id": "ac-2_obj.c", + "props": [ { - "id": "cm-7.2_fr", - "name": "item", - "title": "CM-7 (2) Additional FedRAMP Requirements and Guidance", - "parts": [ - { - "id": "cm-7.2_fr_gdn.1", - "name": "guidance", - "props": [ - { - "name": "label", - "value": "Guidance:" - } - ], - "prose": "This control refers to software deployment by CSP personnel into the production environment. The control requires a policy that states conditions for deploying software. This control shall be implemented in a technical manner on the information system to only allow programs to run that adhere to the policy (i.e. allow-listing). This control is not to be based off of strictly written policy on what is allowed or not allowed to run." - } - ] + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" } ] - } - ] - }, - { - "control-id": "cm-8", - "adds": [ + }, { - "position": "ending", - "by-id": "cm-8_smt", - "parts": [ + "position": "starting", + "by-id": "ac-2_obj.d", + "props": [ { - "id": "cm-8_fr", - "name": "item", - "title": "CM-8 Additional FedRAMP Requirements and Guidance", - "parts": [ - { - "id": "cm-8_fr_smt.1", - "name": "item", - "props": [ - { - "name": "label", - "value": "Requirement:" - } - ], - "prose": "must be provided at least monthly or when there is a change." - } - ] + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" } ] - } - ] - }, - { - "control-id": "cm-9", - "adds": [ + }, { - "position": "ending", - "by-id": "cm-9_smt", - "parts": [ + "position": "starting", + "by-id": "ac-2_obj.e", + "props": [ { - "id": "cm-9_fr_gdn.1", - "name": "guidance", - "props": [ - { - "name": "label", - "value": "Guidance:" - } - ], - "prose": "FedRAMP does not provide a template for the Configuration Management Plan. However, NIST SP 800-128, Guide for Security-Focused Configuration Management of Information Systems, provides guidelines for the implementation of CM controls as well as a sample CMP outline in Appendix D of the Guide" + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" } ] - } - ] - }, - { - "control-id": "cm-12", - "adds": [ + }, { - "position": "ending", - "by-id": "cm-12_smt", - "parts": [ + "position": "starting", + "by-id": "ac-2_obj.f", + "props": [ { - "id": "cm-12_fr", - "name": "item", - "title": "CM-12 Additional FedRAMP Requirements and Guidance", - "parts": [ - { - "id": "cm-12_fr_smt.1", - "name": "item", - "props": [ - { - "name": "label", - "value": "Requirement:" - } - ], - "prose": "According to FedRAMP Authorization Boundary Guidance" - } - ] + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" } ] - } - ] - }, - { - "control-id": "cm-12.1", - "adds": [ + }, { - "position": "ending", - "by-id": "cm-12.1_smt", - "parts": [ + "position": "starting", + "by-id": "ac-2_obj.g", + "props": [ { - "id": "cm-12.1_fr", - "name": "item", - "title": "CM-12 (1) Additional FedRAMP Requirements and Guidance", - "parts": [ - { - "id": "cm-12.1_fr_smt.1", - "name": "item", - "props": [ - { - "name": "label", - "value": "Requirement:" - } - ], - "prose": "According to FedRAMP Authorization Boundary Guidance." - } - ] + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" } ] - } - ] - }, - { - "control-id": "cm-14", - "adds": [ + }, { - "position": "ending", - "by-id": "cm-14_smt", - "parts": [ + "position": "starting", + "by-id": "ac-2_obj.h", + "props": [ { - "id": "cm-14_fr_gdn.1", - "name": "guidance", - "props": [ - { - "name": "label", - "value": "Guidance:" - } - ], - "prose": "If digital signatures/certificates are unavailable, alternative cryptographic integrity checks (hashes, self-signed certs, etc.) can be utilized." + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" } ] - } - ] - }, - { - "control-id": "cp-2", - "adds": [ + }, { - "position": "ending", - "by-id": "cp-2_smt", - "parts": [ + "position": "starting", + "by-id": "ac-2_obj.i.1", + "props": [ { - "id": "cp-2_fr", - "name": "item", - "title": "CP-2 Additional FedRAMP Requirements and Guidance", - "parts": [ - { - "id": "cp-2_fr_smt.1", - "name": "item", - "props": [ - { - "name": "label", - "value": "Requirement:" - } - ], - "prose": "For JAB authorizations the contingency lists include designated FedRAMP personnel." - }, - { - "id": "cp-2_fr_smt.2", - "name": "item", - "props": [ - { - "name": "label", - "value": "Requirement:" - } - ], - "prose": "CSPs must use the FedRAMP Information System Contingency Plan (ISCP) Template (available on the fedramp.gov: https://www.fedramp.gov/assets/resources/templates/SSP-A06-FedRAMP-ISCP-Template.docx)." - } - ] + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" } ] - } - ] - }, - { - "control-id": "cp-3", - "adds": [ + }, { - "position": "ending", - "by-id": "cp-3_smt", - "parts": [ + "position": "starting", + "by-id": "ac-2_obj.i.2", + "props": [ { - "id": "cp-3_fr", - "name": "item", - "title": "CP-3 Additional FedRAMP Requirements and Guidance", - "parts": [ - { - "id": "cp-3_fr_smt.1", - "name": "item", - "props": [ - { - "name": "label", - "value": "(a) Requirement:" - } - ], - "prose": "Privileged admins and engineers must take the basic contingency training within 10 days. Consideration must be given for those privileged admins and engineers with critical contingency-related roles, to gain enough system context and situational awareness to understand the full impact of contingency training as it applies to their respective level. Newly hired critical contingency personnel must take this more in-depth training within 60 days of hire date when the training will have more impact." - } - ] + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" } ] - } - ] - }, - { - "control-id": "cp-4", - "adds": [ + }, { - "position": "ending", - "by-id": "cp-4_smt", - "parts": [ + "position": "starting", + "by-id": "ac-2_obj.i.3", + "props": [ { - "id": "cp-4_fr", - "name": "item", - "title": "CP-4 Additional FedRAMP Requirements and Guidance", - "parts": [ - { - "id": "cp-4_fr_smt.1", - "name": "item", - "props": [ - { - "name": "label", - "value": "(a) Requirement:" - } - ], - "prose": "The service provider develops test plans in accordance with NIST Special Publication 800-34 (as amended); plans are approved by the JAB/AO prior to initiating testing." - }, - { - "id": "cp-4_fr_smt.1", - "name": "item", - "props": [ - { - "name": "label", - "value": "(b) Requirement:" - } - ], - "prose": "The service provider must include the Contingency Plan test results with the security package within the Contingency Plan-designated appendix (Appendix G, Contingency Plan Test Report)." - } - ] + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ac-2_obj.j", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ac-2_obj.k-1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ac-2_obj.k-2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ac-2_obj.l", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ac-2_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ac-2_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ac-2_smt.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ac-2_smt.d", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ac-2_smt.e", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ac-2_smt.f", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ac-2_smt.g", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ac-2_smt.h", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ac-2_smt.i", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ac-2_smt.j", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ac-2_smt.k", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ac-2_smt.l", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ac-2", + "props": [ + { + "name": "CORE", + "ns": "https://fedramp.gov/ns/oscal", + "value": "true" } ] } ] }, { - "control-id": "cp-7", + "control-id": "ac-2.1", "adds": [ { - "position": "ending", - "by-id": "cp-7_smt", - "parts": [ + "position": "starting", + "by-id": "ac-2.1_obj", + "props": [ { - "id": "cp-7_fr", - "name": "item", - "title": "CP-7 Additional FedRAMP Requirements and Guidance", - "parts": [ - { - "id": "cp-7_fr_smt.1", - "name": "item", - "props": [ - { - "name": "label", - "value": "(a) Requirement:" - } - ], - "prose": "The service provider defines a time period consistent with the recovery time objectives and business impact analysis." - } - ] + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ac-2.1_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ac-2.1", + "props": [ + { + "name": "CORE", + "ns": "https://fedramp.gov/ns/oscal", + "value": "true" } ] } ] }, { - "control-id": "cp-7.1", + "control-id": "ac-2.11", "adds": [ { - "position": "ending", - "by-id": "cp-7.1_smt", - "parts": [ + "position": "starting", + "by-id": "ac-2.11_obj", + "props": [ { - "id": "cp-7.1_fr", - "name": "item", - "title": "CP-7 (1) Additional FedRAMP Requirements and Guidance", - "parts": [ - { - "id": "cp-7.1_fr_smt.1", - "name": "guidance", - "props": [ - { - "name": "label", - "value": "Guidance:" - } - ], - "prose": "The service provider may determine what is considered a sufficient degree of separation between the primary and alternate processing sites, based on the types of threats that are of concern. For one particular type of threat (i.e., hostile cyber attack), the degree of separation between sites will be less relevant." - } - ] + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ac-2.11_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ac-2.11", + "props": [ + { + "name": "CORE", + "ns": "https://fedramp.gov/ns/oscal", + "value": "true" } ] } ] }, { - "control-id": "cp-8", + "control-id": "ac-2.13", "adds": [ { - "position": "ending", - "by-id": "cp-8_smt", - "parts": [ + "position": "starting", + "by-id": "ac-2.13_obj", + "props": [ { - "id": "cp-8_fr", - "name": "item", - "title": "CP-8 Additional FedRAMP Requirements and Guidance", - "parts": [ - { - "id": "cp-8_fr_gdn.1", - "name": "item", - "props": [ - { - "name": "label", - "value": "Requirement:" - } - ], - "prose": "The service provider defines a time period consistent with the recovery time objectives and business impact analysis." - } - ] + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ac-2.13_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ac-2.13", + "props": [ + { + "name": "CORE", + "ns": "https://fedramp.gov/ns/oscal", + "value": "true" } ] } ] }, { - "control-id": "cp-9", + "control-id": "ac-2.2", + "adds": [ + { + "position": "starting", + "by-id": "ac-2.2_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ac-2.2_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ac-2.2", + "props": [ + { + "name": "CORE", + "ns": "https://fedramp.gov/ns/oscal", + "value": "true" + } + ] + } + ] + }, + { + "control-id": "ac-2.3", "adds": [ { "position": "ending", - "by-id": "cp-9_smt", + "by-id": "ac-2.3_smt", "parts": [ { - "id": "cp-9_fr", + "id": "ac-2.3_fr", "name": "item", - "title": "CP-9 Additional FedRAMP Requirements and Guidance", + "title": "AC-2 (3) Additional FedRAMP Requirements and Guidance", "parts": [ { - "id": "cp-9_fr_smt.1", + "id": "ac-2.3_fr_smt.1", "name": "item", "props": [ { @@ -4083,61 +4646,247 @@ "value": "Requirement:" } ], - "prose": "The service provider shall determine what elements of the cloud environment require the Information System Backup control. The service provider shall determine how Information System Backup is going to be verified and appropriate periodicity of the check." + "prose": "The service provider defines the time period for non-user accounts (e.g., accounts associated with devices). The time periods are approved and accepted by the JAB/AO. Where user management is a function of the service, reports of activity of consumer users shall be made available." }, { - "id": "cp-9_fr_smt.2", + "id": "ac-2.3_fr_smt.2", "name": "item", "props": [ { "name": "label", - "value": "(a) Requirement:" + "value": "(d) Requirement:" } ], - "prose": "The service provider maintains at least three backup copies of user-level information (at least one of which is available online) or provides an equivalent alternative." + "prose": "The service provider defines the time period of inactivity for device identifiers." }, { - "id": "cp-9_fr_smt.3", - "name": "item", + "id": "ac-2.3_fr_gdn.1", + "name": "guidance", "props": [ { "name": "label", - "value": "(b) Requirement:" - } - ], - "prose": "The service provider maintains at least three backup copies of system-level information (at least one of which is available online) or provides an equivalent alternative." - }, - { - "id": "cp-9_fr_smt.4", - "name": "item", - "props": [ - { - "name": "label", - "value": "(c) Requirement:" + "value": "Guidance:" } ], - "prose": "The service provider maintains at least three backup copies of information system documentation including security information (at least one of which is available online) or provides an equivalent alternative." + "prose": "For DoD clouds, see DoD cloud website for specific DoD requirements that go above and beyond FedRAMP https://public.cyber.mil/dccs/." } ] } ] + }, + { + "position": "starting", + "by-id": "ac-2.3_obj.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ac-2.3_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ac-2.3_obj.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ac-2.3_obj.d", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ac-2.3_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ac-2.3_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ac-2.3_smt.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ac-2.3_smt.d", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ac-2.3", + "props": [ + { + "name": "CORE", + "ns": "https://fedramp.gov/ns/oscal", + "value": "true" + } + ] } ] }, { - "control-id": "cp-9.8", + "control-id": "ac-2.4", + "adds": [ + { + "position": "starting", + "by-id": "ac-2.4_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ac-2.4_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ac-2.4", + "props": [ + { + "name": "CORE", + "ns": "https://fedramp.gov/ns/oscal", + "value": "true" + } + ] + } + ] + }, + { + "control-id": "ac-2.5", "adds": [ { "position": "ending", - "by-id": "cp-9.8_smt", + "by-id": "ac-2.5_smt", "parts": [ { - "id": "cp-9.8_fr", + "id": "ac-2.5_fr", "name": "item", - "title": "CP-9 (8) Additional FedRAMP Requirements and Guidance", + "title": "AC-2 (5) Additional FedRAMP Requirements and Guidance", "parts": [ { - "id": "cp-9.8_fr_gdn.1", + "id": "ac-2.5_fr_gdn.1", "name": "guidance", "props": [ { @@ -4145,50 +4894,225 @@ "value": "Guidance:" } ], - "prose": "Note that this enhancement requires the use of cryptography which must be compliant with Federal requirements and utilize FIPS validated or NSA approved cryptography (see SC-13.)" + "prose": "Should use a shorter timeframe than AC-12." } ] } ] + }, + { + "position": "starting", + "by-id": "ac-2.5_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ac-2.5_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ac-2.5", + "props": [ + { + "name": "CORE", + "ns": "https://fedramp.gov/ns/oscal", + "value": "true" + } + ] } ] }, { - "control-id": "ia-2", + "control-id": "ac-2.7", + "adds": [ + { + "position": "starting", + "by-id": "ac-2.7_obj.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ac-2.7_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ac-2.7_obj.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ac-2.7_obj.d", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ac-2.7_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ac-2.7_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ac-2.7_smt.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ac-2.7_smt.d", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ac-2.7", + "props": [ + { + "name": "CORE", + "ns": "https://fedramp.gov/ns/oscal", + "value": "true" + } + ] + } + ] + }, + { + "control-id": "ac-2.9", "adds": [ { "position": "ending", - "by-id": "ia-2_smt", + "by-id": "ac-2.9_smt", "parts": [ { - "id": "ia-2_fr", + "id": "ac-2.9_fr", "name": "item", - "title": "IA-2 Additional FedRAMP Requirements and Guidance", + "title": "AC-2 (9) Additional FedRAMP Requirements and Guidance", "parts": [ { - "id": "ia-2_fr_smt.1", - "name": "item", - "props": [ - { - "name": "label", - "value": "Requirement:" - } - ], - "prose": "For all control enhancements that specify multifactor authentication, the implementation must adhere to the Digital Identity Guidelines specified in NIST Special Publication 800-63B." - }, - { - "id": "ia-2_fr_smt.2", - "name": "item", - "props": [ - { - "name": "label", - "value": "Requirement:" - } - ], - "prose": "Multi-factor authentication must be phishing-resistant." - }, - { - "id": "ia-2_fr_smt.3", + "id": "ac-2.9_fr_smt.1", "name": "item", "props": [ { @@ -4196,250 +5120,646 @@ "value": "Requirement:" } ], - "prose": "All uses of encrypted virtual private networks must meet all applicable Federal requirements and architecture, dataflow, and security and privacy controls must be documented, assessed, and authorized to operate." - }, - { - "id": "ia-2_fr_gdn.1", - "name": "guidance", - "props": [ - { - "name": "label", - "value": "Guidance:" - } - ], - "prose": "\\\"Phishing-resistant\\\" authentication refers to authentication processes designed to detect and prevent disclosure of authentication secrets and outputs to a website or application masquerading as a legitimate system." + "prose": "Required if shared/group accounts are deployed." } ] } ] + }, + { + "position": "starting", + "by-id": "ac-2.9_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ac-2.9_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ac-2.9", + "props": [ + { + "name": "CORE", + "ns": "https://fedramp.gov/ns/oscal", + "value": "true" + } + ] } ] }, { - "control-id": "ia-2.1", + "control-id": "ac-2.12", "adds": [ { "position": "ending", - "by-id": "ia-2.1_smt", + "by-id": "ac-2.12_smt", "parts": [ { - "id": "ia-2.1_fr", + "id": "ac-2.12_fr", "name": "item", - "title": "IA-2 (1) Additional FedRAMP Requirements and Guidance", + "title": "AC-2 (12) Additional FedRAMP Requirements and Guidance", "parts": [ { - "id": "ia-2.1_fr_smt.1", + "id": "ac-2.12_fr_smt.1", "name": "item", "props": [ { "name": "label", - "value": "Requirement:" + "value": "(a) Requirement:" } ], - "prose": "According to SP 800-63-3, SP 800-63A (IAL), SP 800-63B (AAL), and SP 800-63C (FAL)." + "prose": "Required for privileged accounts." }, { - "id": "ia-2.1_fr_smt.2", + "id": "ac-2.12_fr_smt.2", "name": "item", "props": [ { "name": "label", - "value": "Requirement:" + "value": "(b) Requirement:" } ], - "prose": "Multi-factor authentication must be phishing-resistant." - }, - { - "id": "ia-2.1_fr_gdn.1", - "name": "guidance", - "props": [ - { - "name": "label", - "value": "Guidance:" - } - ], - "prose": "Multi-factor authentication to subsequent components in the same user domain is not required." + "prose": "Required for privileged accounts." } ] } ] + }, + { + "position": "starting", + "by-id": "ac-2.12_obj.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ac-2.12_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ac-2.12_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ac-2.12_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ac-2.12", + "props": [ + { + "name": "CORE", + "ns": "https://fedramp.gov/ns/oscal", + "value": "true" + } + ] } ] }, { - "control-id": "ia-2.2", + "control-id": "ac-20.1", "adds": [ { - "position": "ending", - "by-id": "ia-2.2_smt", - "parts": [ + "position": "starting", + "by-id": "ac-20.1_obj.a", + "props": [ { - "id": "ia-2.2_fr", - "name": "item", - "title": "IA-2 (2) Additional FedRAMP Requirements and Guidance", - "parts": [ - { - "id": "ia-2.2_fr_smt.1", - "name": "item", - "props": [ - { - "name": "label", - "value": "Requirement:" - } - ], - "prose": "According to SP 800-63-3, SP 800-63A (IAL), SP 800-63B (AAL), and SP 800-63C (FAL)." - }, - { - "id": "ia-2.2_fr_smt.2", - "name": "item", - "props": [ - { - "name": "label", - "value": "Requirement:" - } - ], - "prose": "Multi-factor authentication must be phishing-resistant." - }, - { - "id": "ia-2.2_fr_gdn.1", - "name": "guidance", - "props": [ - { - "name": "label", - "value": "Guidance:" - } - ], - "prose": "Multi-factor authentication to subsequent components in the same user domain is not required." - } - ] + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ac-20.1_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ac-20.1_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ac-20.1_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." } ] } ] }, { - "control-id": "ia-2.6", + "control-id": "ac-20.2", "adds": [ { - "position": "ending", - "by-id": "ia-2.6_smt", - "parts": [ + "position": "starting", + "by-id": "ac-20.2_obj", + "props": [ { - "id": "ia-2.6_fr", - "name": "item", - "title": "IA-2 (6) Additional FedRAMP Requirements and Guidance", - "parts": [ - { - "id": "ia-2.6_fr_gdn.1", - "name": "guidance", - "props": [ - { - "name": "label", - "value": "Guidance:" - } - ], - "prose": "PIV=separate device. Please refer to NIST SP 800-157 Guidelines for Derived Personal Identity Verification (PIV) Credentials." - }, - { - "id": "ia-2.6_fr_gdn.2", - "name": "guidance", - "props": [ - { - "name": "label", - "value": "Guidance:" - } - ], - "prose": "See SC-13 Guidance for more information on FIPS-validated or NSA-approved cryptography." - } - ] + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ac-20.2_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." } ] } ] }, { - "control-id": "ia-2.12", + "control-id": "ac-21", "adds": [ { - "position": "ending", - "by-id": "ia-2.12_smt", - "parts": [ + "position": "starting", + "by-id": "ac-21_obj.a", + "props": [ { - "id": "ia-2.12_fr", - "name": "item", - "title": "IA-2 (12) Additional FedRAMP Requirements and Guidance", - "parts": [ - { - "id": "ia-2.12_fr_gdn.1", - "name": "guidance", - "props": [ - { - "name": "label", - "value": "Guidance:" - } - ], - "prose": "Include Common Access Card (CAC), i.e., the DoD technical implementation of PIV/FIPS 201/HSPD-12." - } - ] + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ac-21_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ac-21_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ac-21_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." } ] } ] }, { - "control-id": "ia-5", + "control-id": "ac-22", "adds": [ { - "position": "ending", - "by-id": "ia-5_smt", - "parts": [ + "position": "starting", + "by-id": "ac-22_obj.a", + "props": [ { - "id": "ia-5_fr", - "name": "item", - "title": "IA-5 Additional FedRAMP Requirements and Guidance", - "parts": [ - { - "id": "ia-5_fr_smt.1", - "name": "item", - "props": [ - { - "name": "label", - "value": "Requirement:" - } - ], - "prose": "Authenticators must be compliant with NIST SP 800-63-3 Digital Identity Guidelines IAL, AAL, FAL level 3. Link https://pages.nist.gov/800-63-3" - }, - { - "id": "ia-5_fr_gdn.1", - "name": "guidance", - "props": [ - { - "name": "label", - "value": "Guidance:" - } - ], - "prose": "SP 800-63C Section 6.2.3 Encrypted Assertion requires that authentication assertions be encrypted when passed through third parties, such as a browser. For example, a SAML assertion can be encrypted using XML-Encryption, or an OpenID Connect ID Token can be encrypted using JSON Web Encryption (JWE)." - } - ] + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ac-22_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ac-22_obj.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ac-22_obj.d", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ac-22_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ac-22_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ac-22_smt.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ac-22_smt.d", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." } ] } ] }, { - "control-id": "ia-5.1", + "control-id": "ac-3", "adds": [ { - "position": "ending", - "by-id": "ia-5.1_smt", + "position": "starting", + "by-id": "ac-3_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ac-3_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ac-3", + "props": [ + { + "name": "CORE", + "ns": "https://fedramp.gov/ns/oscal", + "value": "true" + } + ] + } + ] + }, + { + "control-id": "ac-4", + "adds": [ + { + "position": "starting", + "by-id": "ac-4_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ac-4_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "ac-4.21", + "adds": [ + { + "position": "starting", + "by-id": "ac-4.21_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ac-4.21_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "ac-4.4", + "adds": [ + { + "position": "ending", + "by-id": "ac-4.4_smt", "parts": [ { - "id": "ia-5.1_fr", + "id": "ac-4.4_fr", "name": "item", - "title": "IA-5 (1) Additional FedRAMP Requirements and Guidance", + "title": "AC-4 (4) Additional FedRAMP Requirements and Guidance", "parts": [ { - "id": "ia-5.1_fr_smt.1", + "id": "ac-4.4_fr_smt.1", "name": "item", "props": [ { @@ -4447,21 +5767,320 @@ "value": "Requirement:" } ], - "prose": "Password policies must be compliant with NIST SP 800-63B for all memorized, lookup, out-of-band, or One-Time-Passwords (OTP). Password policies shall not enforce special character or minimum password rotation requirements for memorized secrets of users." - }, + "prose": "The service provider must support Agency requirements to comply with M-21-31 (https://www.whitehouse.gov/wp-content/uploads/2021/08/M-21-31-Improving-the-Federal-Governments-Investigative-and-Remediation-Capabilities-Related-to-Cybersecurity-Incidents.pdf) and M-22-09 (https://www.whitehouse.gov/wp-content/uploads/2022/01/M-22-09.pdf)." + } + ] + } + ] + }, + { + "position": "starting", + "by-id": "ac-4.4_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ac-4.4_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "ac-5", + "adds": [ + { + "position": "ending", + "by-id": "ac-5_smt", + "parts": [ + { + "id": "ac-5_fr", + "name": "item", + "title": "AC-5 Additional FedRAMP Requirements and Guidance", + "parts": [ { - "id": "ia-5.1_fr_smt.2", - "name": "item", + "id": "ac-5_fr_gdn.1", + "name": "guidance", "props": [ { "name": "label", - "value": "(h) Requirement:" + "value": "Guidance:" } ], - "prose": "For cases where technology doesn’t allow multi-factor authentication, these rules should be enforced: must have a minimum length of 14 characters and must support all printable ASCII characters.\n\nFor emergency use accounts, these rules should be enforced: must have a minimum length of 14 characters, must support all printable ASCII characters, and passwords must be changed if used." - }, + "prose": "CSPs have the option to provide a separation of duties matrix as an attachment to the SSP." + } + ] + } + ] + }, + { + "position": "starting", + "by-id": "ac-5_obj.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ac-5_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ac-5_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ac-5_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "ac-6", + "adds": [ + { + "position": "starting", + "by-id": "ac-6_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ac-6_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ac-6", + "props": [ + { + "name": "CORE", + "ns": "https://fedramp.gov/ns/oscal", + "value": "true" + } + ] + } + ] + }, + { + "control-id": "ac-6.1", + "adds": [ + { + "position": "starting", + "by-id": "ac-6.1_obj.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ac-6.1_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ac-6.1_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ac-6.1_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "ac-6.10", + "adds": [ + { + "position": "starting", + "by-id": "ac-6.10_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ac-6.10_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ac-6.10", + "props": [ + { + "name": "CORE", + "ns": "https://fedramp.gov/ns/oscal", + "value": "true" + } + ] + } + ] + }, + { + "control-id": "ac-6.2", + "adds": [ + { + "position": "ending", + "by-id": "ac-6.2_smt", + "parts": [ + { + "id": "ac-6.2_fr", + "name": "item", + "title": "AC-6 (2) Additional FedRAMP Requirements and Guidance", + "parts": [ { - "id": "ia-5.1_fr_gdn.1", + "id": "ac-6.2_fr_gdn.1", "name": "guidance", "props": [ { @@ -4469,115 +6088,33513 @@ "value": "Guidance:" } ], - "prose": "Note that (c) and (d) require the use of cryptography which must be compliant with Federal requirements and utilize FIPS validated or NSA approved cryptography (see SC-13)." + "prose": "Examples of security functions include but are not limited to: establishing system accounts, configuring access authorizations (i.e., permissions, privileges), setting events to be audited, and setting intrusion detection parameters, system programming, system and security administration, other privileged functions." } ] } ] - } - ] - }, - { - "control-id": "ia-5.7", - "adds": [ + }, + { + "position": "starting", + "by-id": "ac-6.2_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ac-6.2_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ac-6.2", + "props": [ + { + "name": "CORE", + "ns": "https://fedramp.gov/ns/oscal", + "value": "true" + } + ] + } + ] + }, + { + "control-id": "ac-6.3", + "adds": [ + { + "position": "starting", + "by-id": "ac-6.3_obj-1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ac-6.3_obj-2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ac-6.3_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ac-6.3", + "props": [ + { + "name": "CORE", + "ns": "https://fedramp.gov/ns/oscal", + "value": "true" + } + ] + } + ] + }, + { + "control-id": "ac-6.5", + "adds": [ + { + "position": "starting", + "by-id": "ac-6.5_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ac-6.5_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ac-6.5", + "props": [ + { + "name": "CORE", + "ns": "https://fedramp.gov/ns/oscal", + "value": "true" + } + ] + } + ] + }, + { + "control-id": "ac-6.7", + "adds": [ + { + "position": "starting", + "by-id": "ac-6.7_obj.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ac-6.7_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ac-6.7_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ac-6.7_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "ac-6.8", + "adds": [ + { + "position": "starting", + "by-id": "ac-6.8_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ac-6.8_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ac-6.8", + "props": [ + { + "name": "CORE", + "ns": "https://fedramp.gov/ns/oscal", + "value": "true" + } + ] + } + ] + }, + { + "control-id": "ac-6.9", + "adds": [ + { + "position": "starting", + "by-id": "ac-6.9_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ac-6.9_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "ac-7", + "adds": [ + { + "position": "ending", + "by-id": "ac-7_smt", + "parts": [ + { + "id": "ac-7_fr", + "name": "item", + "title": "AC-7 Additional FedRAMP Requirements and Guidance", + "parts": [ + { + "id": "ac-7_fr_smt.1", + "name": "item", + "props": [ + { + "name": "label", + "value": "Requirement:" + } + ], + "prose": "In alignment with NIST SP 800-63B." + } + ] + } + ] + }, + { + "position": "starting", + "by-id": "ac-7_obj.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ac-7_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ac-7_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ac-7_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "ac-8", + "adds": [ + { + "position": "ending", + "by-id": "ac-8_smt", + "parts": [ + { + "id": "ac-8_fr", + "name": "item", + "title": "AC-8 Additional FedRAMP Requirements and Guidance", + "parts": [ + { + "id": "ac-8_fr_smt.1", + "name": "item", + "props": [ + { + "name": "label", + "value": "Requirement:" + } + ], + "prose": "The service provider shall determine elements of the cloud environment that require the System Use Notification control. The elements of the cloud environment that require System Use Notification are approved and accepted by the JAB/AO." + }, + { + "id": "ac-8_fr_smt.2", + "name": "item", + "props": [ + { + "name": "label", + "value": "Requirement:" + } + ], + "prose": "The service provider shall determine how System Use Notification is going to be verified and provide appropriate periodicity of the check. The System Use Notification verification and periodicity are approved and accepted by the JAB/AO." + }, + { + "id": "ac-8_fr_smt.3", + "name": "item", + "props": [ + { + "name": "label", + "value": "Requirement:" + } + ], + "prose": "If not performed as part of a Configuration Baseline check, then there must be documented agreement on how to provide results of verification and the necessary periodicity of the verification by the service provider. The documented agreement on how to provide verification of the results are approved and accepted by the JAB/AO." + }, + { + "id": "ac-8_fr_gdn.1", + "name": "guidance", + "props": [ + { + "name": "label", + "value": "Guidance:" + } + ], + "prose": "If performed as part of a Configuration Baseline check, then the % of items requiring setting that are checked and that pass (or fail) check can be provided." + } + ] + } + ] + }, + { + "position": "starting", + "by-id": "ac-8_obj.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ac-8_obj.a.1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ac-8_obj.a.2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ac-8_obj.a.3", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ac-8_obj.a.4", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ac-8_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ac-8_obj.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ac-8_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ac-8_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ac-8_smt.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "ac-20", + "adds": [ + { + "position": "ending", + "by-id": "ac-20_smt", + "parts": [ + { + "id": "ac-20_fr", + "name": "item", + "title": "AC-20 Additional FedRAMP Requirements and Guidance", + "parts": [ + { + "id": "ac-20_fr_gdn.1", + "name": "guidance", + "props": [ + { + "name": "label", + "value": "Guidance:" + } + ], + "prose": "The interrelated controls of AC-20, CA-3, and SA-9 should be differentiated as follows:\n\nAC-20 describes system access to and from external systems.\n\nCA-3 describes documentation of an agreement between the respective system owners when data is exchanged between the CSO and an external system.\n\nSA-9 describes the responsibilities of external system owners. These responsibilities would typically be captured in the agreement required by CA-3." + } + ] + } + ] + }, + { + "position": "starting", + "by-id": "ac-20_obj.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ac-20_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ac-20_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ac-20_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "at-1", + "adds": [ + { + "position": "starting", + "by-id": "at-1_obj.a-1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "at-1_obj.a-2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "at-1_obj.a-3", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "at-1_obj.a-4", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "at-1_obj.a.1.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "at-1_obj.a.1.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "at-1_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "at-1_obj.c.1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "at-1_obj.c.2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "at-1_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point.", + "remarks": "This response must address all control sub-statement requirements." + } + ] + }, + { + "position": "starting", + "by-id": "at-1_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "at-1_smt.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point.", + "remarks": "This response must address all control sub-statement requirements." + } + ] + } + ] + }, + { + "control-id": "at-2", + "adds": [ + { + "position": "starting", + "by-id": "at-2_obj.a.1-1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "at-2_obj.a.1-3", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "at-2_obj.a.1-2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "at-2_obj.a.1-4", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "at-2_obj.a.2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "at-2_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "at-2_obj.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "at-2_obj.d", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "at-2_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "at-2_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "at-2_smt.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "at-2_smt.d", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "at-2.2", + "adds": [ + { + "position": "starting", + "by-id": "at-2.2_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "at-2.2_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "at-2.3", + "adds": [ + { + "position": "starting", + "by-id": "at-2.3_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "at-2.3_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "at-3", + "adds": [ + { + "position": "starting", + "by-id": "at-3_obj.a.1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "at-3_obj.a.2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "at-3_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "at-3_obj.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "at-3_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "at-3_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "at-3_smt.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "at-4", + "adds": [ + { + "position": "starting", + "by-id": "at-4_obj.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "at-4_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "at-4_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "at-4_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "au-1", + "adds": [ + { + "position": "starting", + "by-id": "au-1_obj.a-1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "au-1_obj.a-2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "au-1_obj.a-3", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "au-1_obj.a-4", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "au-1_obj.a.1.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "au-1_obj.a.1.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "au-1_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "au-1_obj.c.1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "au-1_obj.c.2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "au-1_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point.", + "remarks": "This response must address all control sub-statement requirements." + } + ] + }, + { + "position": "starting", + "by-id": "au-1_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "au-1_smt.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point.", + "remarks": "This response must address all control sub-statement requirements." + } + ] + } + ] + }, + { + "control-id": "au-10", + "adds": [ + { + "position": "starting", + "by-id": "au-10_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "au-10_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "au-10", + "props": [ + { + "name": "CORE", + "ns": "https://fedramp.gov/ns/oscal", + "value": "true" + } + ] + } + ] + }, + { + "control-id": "au-12", + "adds": [ + { + "position": "starting", + "by-id": "au-12_obj.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "au-12_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "au-12_obj.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "au-12_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "au-12_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "au-12_smt.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "au-12", + "props": [ + { + "name": "CORE", + "ns": "https://fedramp.gov/ns/oscal", + "value": "true" + } + ] + } + ] + }, + { + "control-id": "au-12.1", + "adds": [ + { + "position": "starting", + "by-id": "au-12.1_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "au-12.1_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "au-12.1", + "props": [ + { + "name": "CORE", + "ns": "https://fedramp.gov/ns/oscal", + "value": "true" + } + ] + } + ] + }, + { + "control-id": "au-12.3", + "adds": [ + { + "position": "starting", + "by-id": "au-12.3_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "au-12.3_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "au-12.3", + "props": [ + { + "name": "CORE", + "ns": "https://fedramp.gov/ns/oscal", + "value": "true" + } + ] + } + ] + }, + { + "control-id": "au-2", + "adds": [ + { + "position": "ending", + "by-id": "au-2_smt", + "parts": [ + { + "id": "au-2_fr", + "name": "item", + "title": "AU-2 Additional FedRAMP Requirements and Guidance", + "parts": [ + { + "id": "au-2_fr_smt.1", + "name": "item", + "props": [ + { + "name": "label", + "value": "Requirement:" + } + ], + "prose": "Coordination between service provider and consumer shall be documented and accepted by the JAB/AO." + }, + { + "id": "au-2_fr_gdn.1", + "name": "guidance", + "props": [ + { + "name": "label", + "value": "(e) Guidance:" + } + ], + "prose": "Annually or whenever changes in the threat environment are communicated to the service provider by the JAB/AO." + } + ] + } + ] + }, + { + "position": "starting", + "by-id": "au-2_obj.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "au-2_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "au-2_obj.c-1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "au-2_obj.c-2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "au-2_obj.d", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "au-2_obj.e", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "au-2_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "au-2_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "au-2_smt.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "au-2_smt.d", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "au-2_smt.e", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "au-2", + "props": [ + { + "name": "CORE", + "ns": "https://fedramp.gov/ns/oscal", + "value": "true" + } + ] + } + ] + }, + { + "control-id": "au-3", + "adds": [ + { + "position": "starting", + "by-id": "au-3_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "au-3_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "au-3_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "au-3_smt.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "au-3_smt.d", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "au-3_smt.e", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "au-3_smt.f", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "au-3", + "props": [ + { + "name": "CORE", + "ns": "https://fedramp.gov/ns/oscal", + "value": "true" + } + ] + } + ] + }, + { + "control-id": "au-3.1", + "adds": [ + { + "position": "ending", + "by-id": "au-3.1_smt", + "parts": [ + { + "id": "au-3.1_fr", + "name": "item", + "title": "AU-3 (1) Additional FedRAMP Requirements and Guidance", + "parts": [ + { + "id": "au-3.1_fr_gdn.1", + "name": "guidance", + "props": [ + { + "name": "label", + "value": "Guidance:" + } + ], + "prose": "For client-server transactions, the number of bytes sent and received gives bidirectional transfer information that can be helpful during an investigation or inquiry." + } + ] + } + ] + }, + { + "position": "starting", + "by-id": "au-3.1_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "au-3.1_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "au-3.1", + "props": [ + { + "name": "CORE", + "ns": "https://fedramp.gov/ns/oscal", + "value": "true" + } + ] + } + ] + }, + { + "control-id": "au-4", + "adds": [ + { + "position": "starting", + "by-id": "au-4_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "au-4_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "au-4", + "props": [ + { + "name": "CORE", + "ns": "https://fedramp.gov/ns/oscal", + "value": "true" + } + ] + } + ] + }, + { + "control-id": "au-5", + "adds": [ + { + "position": "starting", + "by-id": "au-5_obj.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "au-5_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "au-5_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "au-5_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "au-5", + "props": [ + { + "name": "CORE", + "ns": "https://fedramp.gov/ns/oscal", + "value": "true" + } + ] + } + ] + }, + { + "control-id": "au-5.1", + "adds": [ + { + "position": "starting", + "by-id": "au-5.1_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "au-5.1_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "au-5.1", + "props": [ + { + "name": "CORE", + "ns": "https://fedramp.gov/ns/oscal", + "value": "true" + } + ] + } + ] + }, + { + "control-id": "au-5.2", + "adds": [ + { + "position": "starting", + "by-id": "au-5.2_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "au-5.2_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "au-5.2", + "props": [ + { + "name": "CORE", + "ns": "https://fedramp.gov/ns/oscal", + "value": "true" + } + ] + } + ] + }, + { + "control-id": "au-6", + "adds": [ + { + "position": "ending", + "by-id": "au-6_smt", + "parts": [ + { + "id": "au-6_fr", + "name": "item", + "title": "AU-6 Additional FedRAMP Requirements and Guidance", + "parts": [ + { + "id": "au-6_fr_smt.1", + "name": "item", + "props": [ + { + "name": "label", + "value": "Requirement:" + } + ], + "prose": "Coordination between service provider and consumer shall be documented and accepted by the JAB/AO. In multi-tenant environments, capability and means for providing review, analysis, and reporting to consumer for data pertaining to consumer shall be documented." + } + ] + } + ] + }, + { + "position": "starting", + "by-id": "au-6_obj.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "au-6_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "au-6_obj.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "au-6_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "au-6_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "au-6_smt.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "au-6", + "props": [ + { + "name": "CORE", + "ns": "https://fedramp.gov/ns/oscal", + "value": "true" + } + ] + } + ] + }, + { + "control-id": "au-6.1", + "adds": [ + { + "position": "starting", + "by-id": "au-6.1_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "au-6.1_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "au-6.1", + "props": [ + { + "name": "CORE", + "ns": "https://fedramp.gov/ns/oscal", + "value": "true" + } + ] + } + ] + }, + { + "control-id": "au-6.3", + "adds": [ + { + "position": "starting", + "by-id": "au-6.3_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "au-6.3_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "au-6.3", + "props": [ + { + "name": "CORE", + "ns": "https://fedramp.gov/ns/oscal", + "value": "true" + } + ] + } + ] + }, + { + "control-id": "au-6.4", + "adds": [ + { + "position": "starting", + "by-id": "au-6.4_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "au-6.4_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "au-6.4", + "props": [ + { + "name": "CORE", + "ns": "https://fedramp.gov/ns/oscal", + "value": "true" + } + ] + } + ] + }, + { + "control-id": "au-6.5", + "adds": [ + { + "position": "starting", + "by-id": "au-6.5_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "au-6.5_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "au-6.5", + "props": [ + { + "name": "CORE", + "ns": "https://fedramp.gov/ns/oscal", + "value": "true" + } + ] + } + ] + }, + { + "control-id": "au-6.6", + "adds": [ + { + "position": "ending", + "by-id": "au-6.6_smt", + "parts": [ + { + "id": "au-6.6_fr", + "name": "item", + "title": "AU-6 (6) Additional FedRAMP Requirements and Guidance", + "parts": [ + { + "id": "au-6.6_fr_smt.1", + "name": "item", + "props": [ + { + "name": "label", + "value": "Requirement:" + } + ], + "prose": "Coordination between service provider and consumer shall be documented and accepted by the JAB/AO." + } + ] + } + ] + }, + { + "position": "starting", + "by-id": "au-6.6_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "au-6.6_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "au-6.6", + "props": [ + { + "name": "CORE", + "ns": "https://fedramp.gov/ns/oscal", + "value": "true" + } + ] + } + ] + }, + { + "control-id": "au-6.7", + "adds": [ + { + "position": "starting", + "by-id": "au-6.7_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "au-6.7_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "au-6.7", + "props": [ + { + "name": "CORE", + "ns": "https://fedramp.gov/ns/oscal", + "value": "true" + } + ] + } + ] + }, + { + "control-id": "au-7", + "adds": [ + { + "position": "starting", + "by-id": "au-7_obj.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "au-7_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "au-7_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "au-7_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "au-7.1", + "adds": [ + { + "position": "starting", + "by-id": "au-7.1_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "au-7.1_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "au-8", + "adds": [ + { + "position": "starting", + "by-id": "au-8_obj.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "au-8_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "au-8_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "au-8_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "au-8", + "props": [ + { + "name": "CORE", + "ns": "https://fedramp.gov/ns/oscal", + "value": "true" + } + ] + } + ] + }, + { + "control-id": "au-9", + "adds": [ + { + "position": "starting", + "by-id": "au-9_obj.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "au-9_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "au-9_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "au-9_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "au-9.2", + "adds": [ + { + "position": "starting", + "by-id": "au-9.2_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "au-9.2_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "au-9.3", + "adds": [ + { + "position": "ending", + "by-id": "au-9.3_smt", + "parts": [ + { + "id": "au-9.3_fr", + "name": "item", + "title": "AU-9 (3) Additional FedRAMP Requirements and Guidance", + "parts": [ + { + "id": "au-9.3_fr_gdn.1", + "name": "guidance", + "props": [ + { + "name": "label", + "value": "Guidance:" + } + ], + "prose": "Note that this enhancement requires the use of cryptography which must be compliant with Federal requirements and utilize FIPS validated or NSA approved cryptography (see SC-13.)" + } + ] + } + ] + }, + { + "position": "starting", + "by-id": "au-9.3_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "au-9.3_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "au-11", + "adds": [ + { + "position": "ending", + "by-id": "au-11_smt", + "parts": [ + { + "id": "au-11_fr", + "name": "item", + "title": "AU-11 Additional FedRAMP Requirements and Guidance", + "parts": [ + { + "id": "au-11_fr_smt.1", + "name": "item", + "props": [ + { + "name": "label", + "value": "Requirement:" + } + ], + "prose": "The service provider retains audit records on-line for at least ninety days and further preserves audit records off-line for a period that is in accordance with NARA requirements." + }, + { + "id": "au-11_fr_smt.2", + "name": "item", + "props": [ + { + "name": "label", + "value": "Requirement:" + } + ], + "prose": "The service provider must support Agency requirements to comply with M-21-31 (https://www.whitehouse.gov/wp-content/uploads/2021/08/M-21-31-Improving-the-Federal-Governments-Investigative-and-Remediation-Capabilities-Related-to-Cybersecurity-Incidents.pdf)" + }, + { + "id": "au-11_fr_gdn.1", + "name": "guidance", + "props": [ + { + "name": "label", + "value": "Guidance:" + } + ], + "prose": "The service provider is encouraged to align with M-21-31 where possible" + } + ] + } + ] + }, + { + "position": "starting", + "by-id": "au-11_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "au-11_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "au-11", + "props": [ + { + "name": "CORE", + "ns": "https://fedramp.gov/ns/oscal", + "value": "true" + } + ] + } + ] + }, + { + "control-id": "au-9.4", + "adds": [ + { + "position": "starting", + "by-id": "au-9.4_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "au-9.4_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "ca-1", + "adds": [ + { + "position": "starting", + "by-id": "ca-1_obj.a-1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ca-1_obj.a-2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ca-1_obj.a-3", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ca-1_obj.a-4", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ca-1_obj.a.1.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ca-1_obj.a.1.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ca-1_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ca-1_obj.c.1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ca-1_obj.c.2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ca-1_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point.", + "remarks": "This response must address all control sub-statement requirements." + } + ] + }, + { + "position": "starting", + "by-id": "ca-1_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ca-1_smt.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point.", + "remarks": "This response must address all control sub-statement requirements." + } + ] + } + ] + }, + { + "control-id": "ca-2", + "adds": [ + { + "position": "ending", + "by-id": "ca-2_smt", + "parts": [ + { + "id": "ca-2_fr", + "name": "item", + "title": "CA-2 Additional FedRAMP Requirements and Guidance", + "parts": [ + { + "id": "ca-2_fr_gdn.1", + "name": "guidance", + "props": [ + { + "name": "label", + "value": "Guidance:" + } + ], + "prose": "Reference FedRAMP Annual Assessment Guidance." + } + ] + } + ] + }, + { + "position": "starting", + "by-id": "ca-2_obj.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ca-2_obj.b.1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ca-2_obj.b.2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ca-2_obj.b.3", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ca-2_obj.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ca-2_obj.d", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ca-2_obj.e", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ca-2_obj.f", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ca-2_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ca-2_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ca-2_smt.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ca-2_smt.d", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ca-2_smt.e", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ca-2_smt.f", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "ca-2.1", + "adds": [ + { + "position": "ending", + "by-id": "ca-2.1_smt", + "parts": [ + { + "id": "ca-2.1_fr", + "name": "item", + "title": "CA-2 (1) Additional FedRAMP Requirements and Guidance", + "parts": [ + { + "id": "ca-2.1_fr_smt.1", + "name": "item", + "props": [ + { + "name": "label", + "value": "Requirement:" + } + ], + "prose": "For JAB Authorization, must use an accredited 3PAO." + } + ] + } + ] + }, + { + "position": "starting", + "by-id": "ca-2.1_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ca-2.1_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "ca-2.2", + "adds": [ + { + "position": "ending", + "by-id": "ca-2.2_smt", + "parts": [ + { + "id": "ca-2.2_fr", + "name": "item", + "title": "CA-2 (2) Additional FedRAMP Requirements and Guidance", + "parts": [ + { + "id": "ca-2.2_fr_smt.1", + "name": "item", + "props": [ + { + "name": "label", + "value": "Requirement:" + } + ], + "prose": "To include 'announced', 'vulnerability scanning'" + } + ] + } + ] + }, + { + "position": "starting", + "by-id": "ca-2.2_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ca-2.2_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "ca-2.3", + "adds": [ + { + "position": "starting", + "by-id": "ca-2.3_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ca-2.3_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "ca-3", + "adds": [ + { + "position": "starting", + "by-id": "ca-3_obj.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ca-3_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ca-3_obj.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ca-3_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ca-3_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ca-3_smt.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "ca-3.6", + "adds": [ + { + "position": "starting", + "by-id": "ca-3.6_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ca-3.6_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "ca-5", + "adds": [ + { + "position": "ending", + "by-id": "ca-5_smt", + "parts": [ + { + "id": "ca-5_fr", + "name": "item", + "title": "CA-5 Additional FedRAMP Requirements and Guidance", + "parts": [ + { + "id": "ca-5_fr_smt.1", + "name": "item", + "props": [ + { + "name": "label", + "value": "Requirement:" + } + ], + "prose": "POA&Ms must be provided at least monthly." + }, + { + "id": "ca-5_fr_gdn.1", + "name": "guidance", + "props": [ + { + "name": "label", + "value": "Guidance:" + } + ], + "prose": "Reference FedRAMP-POAM-Template" + } + ] + } + ] + }, + { + "position": "starting", + "by-id": "ca-5_obj.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ca-5_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ca-5_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ca-5_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "ca-6", + "adds": [ + { + "position": "ending", + "by-id": "ca-6_smt", + "parts": [ + { + "id": "ca-6_fr", + "name": "item", + "title": "CA-6 Additional FedRAMP Requirements and Guidance", + "parts": [ + { + "id": "ca-6_fr_gdn.1", + "name": "guidance", + "props": [ + { + "name": "label", + "value": "(e) Guidance:" + } + ], + "prose": "Significant change is defined in NIST Special Publication 800-37 Revision 2, Appendix F and according to FedRAMP Significant Change Policies and Procedures. The service provider describes the types of changes to the information system or the environment of operations that would impact the risk posture. The types of changes are approved and accepted by the JAB/AO." + } + ] + } + ] + }, + { + "position": "starting", + "by-id": "ca-6_obj.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ca-6_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ca-6_obj.c.1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ca-6_obj.c.2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ca-6_obj.d", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ca-6_obj.e", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ca-6_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ca-6_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ca-6_smt.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ca-6_smt.d", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ca-6_smt.e", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "ca-7", + "adds": [ + { + "position": "ending", + "by-id": "ca-7_smt", + "parts": [ + { + "id": "ca-7_fr", + "name": "item", + "title": "CA-7 Additional FedRAMP Requirements and Guidance", + "parts": [ + { + "id": "ca-7_fr_smt.1", + "name": "item", + "props": [ + { + "name": "label", + "value": "Requirement:" + } + ], + "prose": "Operating System, Database, Web Application, Container, and Service Configuration Scans: at least monthly. All scans performed by Independent Assessor: at least annually." + }, + { + "id": "ca-7_fr_smt.2", + "name": "item", + "props": [ + { + "name": "label", + "value": "Requirement:" + } + ], + "prose": "CSOs with more than one agency ATO must implement a collaborative Continuous Monitoring (ConMon) approach described in the FedRAMP Guide for Multi-Agency Continuous Monitoring. This requirement applies to CSOs authorized via the Agency path as each agency customer is responsible for performing ConMon oversight. It does not apply to CSOs authorized via the JAB path because the JAB performs ConMon oversight." + }, + { + "id": "ca-7_fr_gdn.1", + "name": "guidance", + "props": [ + { + "name": "label", + "value": "Guidance:" + } + ], + "prose": "FedRAMP does not provide a template for the Continuous Monitoring Plan. CSPs should reference the FedRAMP Continuous Monitoring Strategy Guide when developing the Continuous Monitoring Plan." + } + ] + } + ] + }, + { + "position": "starting", + "by-id": "ca-7_obj-1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ca-7_obj-2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ca-7_obj.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ca-7_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ca-7_obj.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ca-7_obj.d", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ca-7_obj.e", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ca-7_obj.f", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ca-7_obj.g", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ca-7_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ca-7_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ca-7_smt.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ca-7_smt.d", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ca-7_smt.e", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ca-7_smt.f", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ca-7_smt.g", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "ca-7.1", + "adds": [ + { + "position": "starting", + "by-id": "ca-7.1_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ca-7.1_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "ca-7.4", + "adds": [ + { + "position": "starting", + "by-id": "ca-7.4_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ca-7.4_obj.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ca-7.4_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ca-7.4_obj.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ca-7.4_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ca-7.4_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ca-7.4_smt.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "ca-8", + "adds": [ + { + "position": "ending", + "by-id": "ca-8_smt", + "parts": [ + { + "id": "ca-8_fr", + "name": "item", + "title": "CA-8 Additional FedRAMP Requirements and Guidance", + "parts": [ + { + "id": "ca-8_fr_gdn.1", + "name": "guidance", + "props": [ + { + "name": "label", + "value": "Guidance:" + } + ], + "prose": "Reference the FedRAMP Penetration Test Guidance." + } + ] + } + ] + }, + { + "position": "starting", + "by-id": "ca-8_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ca-8_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "ca-8.1", + "adds": [ + { + "position": "starting", + "by-id": "ca-8.1_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ca-8.1_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "ca-8.2", + "adds": [ + { + "position": "ending", + "by-id": "ca-8.2_smt", + "parts": [ + { + "id": "ca-8.2_fr", + "name": "item", + "title": "CA-8(2) Additional FedRAMP Requirements and Guidance", + "parts": [ + { + "id": "ca-8.2_fr_gdn.1", + "name": "guidance", + "props": [ + { + "name": "label", + "value": "Guidance:" + } + ], + "prose": "See the FedRAMP Documents page> Penetration Test Guidance\n\nhttps://www.FedRAMP.gov/documents/" + } + ] + } + ] + }, + { + "position": "starting", + "by-id": "ca-8.2_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ca-8.2_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ca-8.2", + "props": [ + { + "name": "CORE", + "ns": "https://fedramp.gov/ns/oscal", + "value": "true" + } + ] + } + ] + }, + { + "control-id": "ca-9", + "adds": [ + { + "position": "starting", + "by-id": "ca-9_obj.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ca-9_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ca-9_obj.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ca-9_obj.d", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ca-9_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ca-9_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ca-9_smt.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ca-9_smt.d", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "cm-1", + "adds": [ + { + "position": "starting", + "by-id": "cm-1_obj.a-1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cm-1_obj.a-2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cm-1_obj.a-3", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cm-1_obj.a-4", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cm-1_obj.a.1.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cm-1_obj.a.1.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cm-1_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cm-1_obj.c.1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cm-1_obj.c.2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cm-1_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point.", + "remarks": "This response must address all control sub-statement requirements." + } + ] + }, + { + "position": "starting", + "by-id": "cm-1_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "cm-1_smt.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point.", + "remarks": "This response must address all control sub-statement requirements." + } + ] + } + ] + }, + { + "control-id": "cm-10", + "adds": [ + { + "position": "starting", + "by-id": "cm-10_obj.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cm-10_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cm-10_obj.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cm-10_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "cm-10_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "cm-10_smt.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "cm-11", + "adds": [ + { + "position": "starting", + "by-id": "cm-11_obj.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cm-11_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cm-11_obj.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cm-11_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "cm-11_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "cm-11_smt.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "cm-2", + "adds": [ + { + "position": "ending", + "by-id": "cm-2_smt", + "parts": [ + { + "id": "cm-2_fr", + "name": "item", + "title": "CM-2 Additional FedRAMP Requirements and Guidance", + "parts": [ + { + "id": "cm-2_fr_gdn.1", + "name": "guidance", + "props": [ + { + "name": "label", + "value": "(b)(1) Guidance:" + } + ], + "prose": "Significant change is defined in NIST Special Publication 800-37 Revision 2, Appendix F." + } + ] + } + ] + }, + { + "position": "starting", + "by-id": "cm-2_obj.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cm-2_obj.b.1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cm-2_obj.b.2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cm-2_obj.b.3", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cm-2_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "cm-2_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "cm-2.2", + "adds": [ + { + "position": "starting", + "by-id": "cm-2.2_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cm-2.2_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "cm-2.3", + "adds": [ + { + "position": "starting", + "by-id": "cm-2.3_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cm-2.3_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "cm-2.7", + "adds": [ + { + "position": "starting", + "by-id": "cm-2.7_obj.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cm-2.7_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cm-2.7_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "cm-2.7_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "cm-3", + "adds": [ + { + "position": "ending", + "by-id": "cm-3_smt", + "parts": [ + { + "id": "cm-3_fr", + "name": "item", + "title": "CM-3 Additional FedRAMP Requirements and Guidance", + "parts": [ + { + "id": "cm-3_fr_smt.1", + "name": "item", + "props": [ + { + "name": "label", + "value": "Requirement:" + } + ], + "prose": "The service provider establishes a central means of communicating major changes to or developments in the information system or environment of operations that may affect its services to the federal government and associated service consumers (e.g., electronic bulletin board, web status page). The means of communication are approved and accepted by the JAB/AO." + }, + { + "id": "cm-3_fr_gdn.1", + "name": "guidance", + "props": [ + { + "name": "label", + "value": "(e) Guidance:" + } + ], + "prose": "In accordance with record retention policies and procedures." + } + ] + } + ] + }, + { + "position": "starting", + "by-id": "cm-3_obj.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cm-3_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cm-3_obj.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cm-3_obj.d", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cm-3_obj.e", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cm-3_obj.f", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cm-3_obj.g-1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cm-3_obj.g-2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cm-3_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "cm-3_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "cm-3_smt.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "cm-3_smt.d", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "cm-3_smt.e", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "cm-3_smt.f", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "cm-3_smt.g", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "cm-3.1", + "adds": [ + { + "position": "starting", + "by-id": "cm-3.1_obj.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cm-3.1_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cm-3.1_obj.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cm-3.1_obj.d", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cm-3.1_obj.e", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cm-3.1_obj.f", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cm-3.1_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "cm-3.1_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "cm-3.1_smt.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "cm-3.1_smt.d", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "cm-3.1_smt.e", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "cm-3.1_smt.f", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "cm-3.2", + "adds": [ + { + "position": "starting", + "by-id": "cm-3.2_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cm-3.2_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "cm-3.4", + "adds": [ + { + "position": "starting", + "by-id": "cm-3.4_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cm-3.4_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "cm-3.6", + "adds": [ + { + "position": "starting", + "by-id": "cm-3.6_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cm-3.6_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "cm-4", + "adds": [ + { + "position": "starting", + "by-id": "cm-4_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cm-4_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "cm-4.1", + "adds": [ + { + "position": "starting", + "by-id": "cm-4.1_obj-1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cm-4.1_obj-2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cm-4.1_obj-3", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cm-4.1_obj-4", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cm-4.1_obj-5", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cm-4.1_obj-6", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cm-4.1_obj-7", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cm-4.1_obj-8", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cm-4.1_obj-9", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cm-4.1_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "cm-4.2", + "adds": [ + { + "position": "starting", + "by-id": "cm-4.2_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cm-4.2_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "cm-5", + "adds": [ + { + "position": "starting", + "by-id": "cm-5_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cm-5_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "cm-5", + "props": [ + { + "name": "CORE", + "ns": "https://fedramp.gov/ns/oscal", + "value": "true" + } + ] + } + ] + }, + { + "control-id": "cm-5.1", + "adds": [ + { + "position": "starting", + "by-id": "cm-5.1_obj.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cm-5.1_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cm-5.1_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "cm-5.1_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "cm-5.5", + "adds": [ + { + "position": "starting", + "by-id": "cm-5.5_obj.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cm-5.5_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cm-5.5_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "cm-5.5_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "cm-6", + "adds": [ + { + "position": "ending", + "by-id": "cm-6_smt", + "parts": [ + { + "id": "cm-6_fr", + "name": "item", + "title": "CM-6 Additional FedRAMP Requirements and Guidance", + "parts": [ + { + "id": "cm-6_fr_smt.1", + "name": "item", + "props": [ + { + "name": "label", + "value": "(a) Requirement 1:" + } + ], + "prose": "The service provider shall use the DoD STIGs to establish configuration settings; Center for Internet Security up to Level 2 (CIS Level 2) guidelines shall be used if STIGs are not available; Custom baselines shall be used if CIS is not available." + }, + { + "id": "cm-6_fr_smt.2", + "name": "item", + "props": [ + { + "name": "label", + "value": "(a) Requirement 2:" + } + ], + "prose": "The service provider shall ensure that checklists for configuration settings are Security Content Automation Protocol (SCAP) validated or SCAP compatible (if validated checklists are not available)." + }, + { + "id": "cm-6_fr_gdn.1", + "name": "guidance", + "props": [ + { + "name": "label", + "value": "Guidance:" + } + ], + "prose": "Compliance checks are used to evaluate configuration settings and provide general insight into the overall effectiveness of configuration management activities. CSPs and 3PAOs typically combine compliance check findings into a single CM-6 finding, which is acceptable. However, for initial assessments, annual assessments, and significant change requests, FedRAMP requires a clear understanding, on a per-control basis, where risks exist. Therefore, 3PAOs must also analyze compliance check findings as part of the controls assessment. Where a direct mapping exists, the 3PAO must document additional findings per control in the corresponding SAR Risk Exposure Table (RET), which are then documented in the CSP's Plan of Action and Milestones (POA&M). This will likely result in the details of individual control findings overlapping with those in the combined CM-6 finding, which is acceptable.\n\nDuring monthly continuous monitoring, new findings from CSP compliance checks may be combined into a single CM-6 POA&M item. CSPs are not required to map the findings to specific controls because controls are only assessed during initial assessments, annual assessments, and significant change requests." + } + ] + } + ] + }, + { + "position": "starting", + "by-id": "cm-6_obj.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cm-6_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cm-6_obj.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cm-6_obj.d", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cm-6_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "cm-6_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "cm-6_smt.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "cm-6_smt.d", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "cm-6", + "props": [ + { + "name": "CORE", + "ns": "https://fedramp.gov/ns/oscal", + "value": "true" + } + ] + } + ] + }, + { + "control-id": "cm-6.1", + "adds": [ + { + "position": "starting", + "by-id": "cm-6.1_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cm-6.1_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "cm-6.1", + "props": [ + { + "name": "CORE", + "ns": "https://fedramp.gov/ns/oscal", + "value": "true" + } + ] + } + ] + }, + { + "control-id": "cm-6.2", + "adds": [ + { + "position": "starting", + "by-id": "cm-6.2_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cm-6.2_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "cm-6.2", + "props": [ + { + "name": "CORE", + "ns": "https://fedramp.gov/ns/oscal", + "value": "true" + } + ] + } + ] + }, + { + "control-id": "cm-7", + "adds": [ + { + "position": "ending", + "by-id": "cm-7_smt", + "parts": [ + { + "id": "cm-7_fr", + "name": "item", + "title": "CM-7 Additional FedRAMP Requirements and Guidance", + "parts": [ + { + "id": "cm-7_fr_smt.1", + "name": "item", + "props": [ + { + "name": "label", + "value": "(b) Requirement:" + } + ], + "prose": "The service provider shall use Security guidelines (See CM-6) to establish list of prohibited or restricted functions, ports, protocols, and/or services or establishes its own list of prohibited or restricted functions, ports, protocols, and/or services if STIGs or CIS is not available." + } + ] + } + ] + }, + { + "position": "starting", + "by-id": "cm-7_obj.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cm-7_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cm-7_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "cm-7_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "cm-7", + "props": [ + { + "name": "CORE", + "ns": "https://fedramp.gov/ns/oscal", + "value": "true" + } + ] + } + ] + }, + { + "control-id": "cm-7.1", + "adds": [ + { + "position": "starting", + "by-id": "cm-7.1_obj.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cm-7.1_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cm-7.1_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "cm-7.1_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "cm-7.1", + "props": [ + { + "name": "CORE", + "ns": "https://fedramp.gov/ns/oscal", + "value": "true" + } + ] + } + ] + }, + { + "control-id": "cm-7.2", + "adds": [ + { + "position": "ending", + "by-id": "cm-7.2_smt", + "parts": [ + { + "id": "cm-7.2_fr", + "name": "item", + "title": "CM-7 (2) Additional FedRAMP Requirements and Guidance", + "parts": [ + { + "id": "cm-7.2_fr_gdn.1", + "name": "guidance", + "props": [ + { + "name": "label", + "value": "Guidance:" + } + ], + "prose": "This control refers to software deployment by CSP personnel into the production environment. The control requires a policy that states conditions for deploying software. This control shall be implemented in a technical manner on the information system to only allow programs to run that adhere to the policy (i.e. allow-listing). This control is not to be based off of strictly written policy on what is allowed or not allowed to run." + } + ] + } + ] + }, + { + "position": "starting", + "by-id": "cm-7.2_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cm-7.2_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "cm-7.2", + "props": [ + { + "name": "CORE", + "ns": "https://fedramp.gov/ns/oscal", + "value": "true" + } + ] + } + ] + }, + { + "control-id": "cm-7.5", + "adds": [ + { + "position": "starting", + "by-id": "cm-7.5_obj.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cm-7.5_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cm-7.5_obj.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cm-7.5_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "cm-7.5_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "cm-7.5_smt.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "cm-7.5", + "props": [ + { + "name": "CORE", + "ns": "https://fedramp.gov/ns/oscal", + "value": "true" + } + ] + } + ] + }, + { + "control-id": "cm-8", + "adds": [ + { + "position": "ending", + "by-id": "cm-8_smt", + "parts": [ + { + "id": "cm-8_fr", + "name": "item", + "title": "CM-8 Additional FedRAMP Requirements and Guidance", + "parts": [ + { + "id": "cm-8_fr_smt.1", + "name": "item", + "props": [ + { + "name": "label", + "value": "Requirement:" + } + ], + "prose": "must be provided at least monthly or when there is a change." + } + ] + } + ] + }, + { + "position": "starting", + "by-id": "cm-8_obj.a.1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cm-8_obj.a.2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cm-8_obj.a.3", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cm-8_obj.a.4", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cm-8_obj.a.5", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cm-8_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cm-8_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "cm-8_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "cm-8", + "props": [ + { + "name": "CORE", + "ns": "https://fedramp.gov/ns/oscal", + "value": "true" + } + ] + } + ] + }, + { + "control-id": "cm-8.1", + "adds": [ + { + "position": "starting", + "by-id": "cm-8.1_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cm-8.1_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "cm-8.2", + "adds": [ + { + "position": "starting", + "by-id": "cm-8.2_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cm-8.2_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "cm-8.3", + "adds": [ + { + "position": "starting", + "by-id": "cm-8.3_obj.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cm-8.3_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cm-8.3_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "cm-8.3_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "cm-8.4", + "adds": [ + { + "position": "starting", + "by-id": "cm-8.4_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cm-8.4_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "cm-9", + "adds": [ + { + "position": "ending", + "by-id": "cm-9_smt", + "parts": [ + { + "id": "cm-9_fr_gdn.1", + "name": "guidance", + "props": [ + { + "name": "label", + "value": "Guidance:" + } + ], + "prose": "FedRAMP does not provide a template for the Configuration Management Plan. However, NIST SP 800-128, Guide for Security-Focused Configuration Management of Information Systems, provides guidelines for the implementation of CM controls as well as a sample CMP outline in Appendix D of the Guide" + } + ] + }, + { + "position": "starting", + "by-id": "cm-9_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cm-9_obj.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cm-9_obj.b-1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cm-9_obj.b-2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cm-9_obj.c-1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cm-9_obj.c-2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cm-9_obj.d", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cm-9_obj.e", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cm-9_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "cm-9_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "cm-9_smt.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "cm-9_smt.d", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "cm-9_smt.e", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "cm-12", + "adds": [ + { + "position": "ending", + "by-id": "cm-12_smt", + "parts": [ + { + "id": "cm-12_fr", + "name": "item", + "title": "CM-12 Additional FedRAMP Requirements and Guidance", + "parts": [ + { + "id": "cm-12_fr_smt.1", + "name": "item", + "props": [ + { + "name": "label", + "value": "Requirement:" + } + ], + "prose": "According to FedRAMP Authorization Boundary Guidance" + } + ] + } + ] + }, + { + "position": "starting", + "by-id": "cm-12_obj.a-1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cm-12_obj.a-2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cm-12_obj.a-3", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cm-12_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cm-12_obj.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cm-12_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "cm-12_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "cm-12_smt.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "cm-12.1", + "adds": [ + { + "position": "ending", + "by-id": "cm-12.1_smt", + "parts": [ + { + "id": "cm-12.1_fr", + "name": "item", + "title": "CM-12 (1) Additional FedRAMP Requirements and Guidance", + "parts": [ + { + "id": "cm-12.1_fr_smt.1", + "name": "item", + "props": [ + { + "name": "label", + "value": "Requirement:" + } + ], + "prose": "According to FedRAMP Authorization Boundary Guidance." + } + ] + } + ] + }, + { + "position": "starting", + "by-id": "cm-12.1_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cm-12.1_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "cm-14", + "adds": [ + { + "position": "ending", + "by-id": "cm-14_smt", + "parts": [ + { + "id": "cm-14_fr_gdn.1", + "name": "guidance", + "props": [ + { + "name": "label", + "value": "Guidance:" + } + ], + "prose": "If digital signatures/certificates are unavailable, alternative cryptographic integrity checks (hashes, self-signed certs, etc.) can be utilized." + } + ] + }, + { + "position": "starting", + "by-id": "cm-14_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cm-14_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "cp-1", + "adds": [ + { + "position": "starting", + "by-id": "cp-1_obj.a-1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cp-1_obj.a-2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cp-1_obj.a-3", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cp-1_obj.a-4", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cp-1_obj.a.1.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cp-1_obj.a.1.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cp-1_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cp-1_obj.c.1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cp-1_obj.c.2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cp-1_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point.", + "remarks": "This response must address all control sub-statement requirements." + } + ] + }, + { + "position": "starting", + "by-id": "cp-1_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "cp-1_smt.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point.", + "remarks": "This response must address all control sub-statement requirements." + } + ] + } + ] + }, + { + "control-id": "cp-10", + "adds": [ + { + "position": "starting", + "by-id": "cp-10_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cp-10_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "cp-10.2", + "adds": [ + { + "position": "starting", + "by-id": "cp-10.2_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cp-10.2_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "cp-10.4", + "adds": [ + { + "position": "starting", + "by-id": "cp-10.4_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cp-10.4_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "cp-2", + "adds": [ + { + "position": "ending", + "by-id": "cp-2_smt", + "parts": [ + { + "id": "cp-2_fr", + "name": "item", + "title": "CP-2 Additional FedRAMP Requirements and Guidance", + "parts": [ + { + "id": "cp-2_fr_smt.1", + "name": "item", + "props": [ + { + "name": "label", + "value": "Requirement:" + } + ], + "prose": "For JAB authorizations the contingency lists include designated FedRAMP personnel." + }, + { + "id": "cp-2_fr_smt.2", + "name": "item", + "props": [ + { + "name": "label", + "value": "Requirement:" + } + ], + "prose": "CSPs must use the FedRAMP Information System Contingency Plan (ISCP) Template (available on the fedramp.gov: https://www.fedramp.gov/assets/resources/templates/SSP-A06-FedRAMP-ISCP-Template.docx)." + } + ] + } + ] + }, + { + "position": "starting", + "by-id": "cp-2_obj.a.1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cp-2_obj.a.2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cp-2_obj.a.3", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cp-2_obj.a.4", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cp-2_obj.a.5", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cp-2_obj.a.6", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cp-2_obj.a.7", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cp-2_obj.b-1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cp-2_obj.b-2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cp-2_obj.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cp-2_obj.d", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cp-2_obj.e-1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cp-2_obj.e-2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cp-2_obj.f", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cp-2_obj.g", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cp-2_obj.h", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cp-2_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "cp-2_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "cp-2_smt.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "cp-2_smt.d", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "cp-2_smt.e", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "cp-2_smt.f", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "cp-2_smt.g", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "cp-2_smt.h", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "cp-2.1", + "adds": [ + { + "position": "starting", + "by-id": "cp-2.1_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cp-2.1_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "cp-2.2", + "adds": [ + { + "position": "starting", + "by-id": "cp-2.2_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cp-2.2_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "cp-2.3", + "adds": [ + { + "position": "starting", + "by-id": "cp-2.3_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cp-2.3_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "cp-2.5", + "adds": [ + { + "position": "starting", + "by-id": "cp-2.5_obj-1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cp-2.5_obj-2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cp-2.5_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "cp-2.8", + "adds": [ + { + "position": "starting", + "by-id": "cp-2.8_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cp-2.8_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "cp-3", + "adds": [ + { + "position": "ending", + "by-id": "cp-3_smt", + "parts": [ + { + "id": "cp-3_fr", + "name": "item", + "title": "CP-3 Additional FedRAMP Requirements and Guidance", + "parts": [ + { + "id": "cp-3_fr_smt.1", + "name": "item", + "props": [ + { + "name": "label", + "value": "(a) Requirement:" + } + ], + "prose": "Privileged admins and engineers must take the basic contingency training within 10 days. Consideration must be given for those privileged admins and engineers with critical contingency-related roles, to gain enough system context and situational awareness to understand the full impact of contingency training as it applies to their respective level. Newly hired critical contingency personnel must take this more in-depth training within 60 days of hire date when the training will have more impact." + } + ] + } + ] + }, + { + "position": "starting", + "by-id": "cp-3_obj.a.1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cp-3_obj.a.2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cp-3_obj.a.3", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cp-3_obj.b-1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cp-3_obj.b-2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cp-3_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "cp-3_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "cp-3.1", + "adds": [ + { + "position": "starting", + "by-id": "cp-3.1_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cp-3.1_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "cp-4", + "adds": [ + { + "position": "ending", + "by-id": "cp-4_smt", + "parts": [ + { + "id": "cp-4_fr", + "name": "item", + "title": "CP-4 Additional FedRAMP Requirements and Guidance", + "parts": [ + { + "id": "cp-4_fr_smt.1", + "name": "item", + "props": [ + { + "name": "label", + "value": "(a) Requirement:" + } + ], + "prose": "The service provider develops test plans in accordance with NIST Special Publication 800-34 (as amended); plans are approved by the JAB/AO prior to initiating testing." + }, + { + "id": "cp-4_fr_smt.1", + "name": "item", + "props": [ + { + "name": "label", + "value": "(b) Requirement:" + } + ], + "prose": "The service provider must include the Contingency Plan test results with the security package within the Contingency Plan-designated appendix (Appendix G, Contingency Plan Test Report)." + } + ] + } + ] + }, + { + "position": "starting", + "by-id": "cp-4_obj.a-1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cp-4_obj.a-2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cp-4_obj.a-3", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cp-4_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cp-4_obj.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cp-4_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "cp-4_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "cp-4_smt.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "cp-4", + "props": [ + { + "name": "CORE", + "ns": "https://fedramp.gov/ns/oscal", + "value": "true" + } + ] + } + ] + }, + { + "control-id": "cp-4.1", + "adds": [ + { + "position": "starting", + "by-id": "cp-4.1_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cp-4.1_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "cp-4.2", + "adds": [ + { + "position": "starting", + "by-id": "cp-4.2_obj.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cp-4.2_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cp-4.2_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "cp-4.2_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "cp-6", + "adds": [ + { + "position": "starting", + "by-id": "cp-6_obj.a-1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cp-6_obj.a-2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cp-6_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cp-6_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "cp-6_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "cp-6.1", + "adds": [ + { + "position": "starting", + "by-id": "cp-6.1_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cp-6.1_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "cp-6.2", + "adds": [ + { + "position": "starting", + "by-id": "cp-6.2_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cp-6.2_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "cp-6.3", + "adds": [ + { + "position": "starting", + "by-id": "cp-6.3_obj-1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cp-6.3_obj-2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cp-6.3_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "cp-7", + "adds": [ + { + "position": "ending", + "by-id": "cp-7_smt", + "parts": [ + { + "id": "cp-7_fr", + "name": "item", + "title": "CP-7 Additional FedRAMP Requirements and Guidance", + "parts": [ + { + "id": "cp-7_fr_smt.1", + "name": "item", + "props": [ + { + "name": "label", + "value": "(a) Requirement:" + } + ], + "prose": "The service provider defines a time period consistent with the recovery time objectives and business impact analysis." + } + ] + } + ] + }, + { + "position": "starting", + "by-id": "cp-7_obj.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cp-7_obj.b-1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cp-7_obj.b-2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cp-7_obj.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cp-7_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "cp-7_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "cp-7_smt.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "cp-7.1", + "adds": [ + { + "position": "ending", + "by-id": "cp-7.1_smt", + "parts": [ + { + "id": "cp-7.1_fr", + "name": "item", + "title": "CP-7 (1) Additional FedRAMP Requirements and Guidance", + "parts": [ + { + "id": "cp-7.1_fr_smt.1", + "name": "guidance", + "props": [ + { + "name": "label", + "value": "Guidance:" + } + ], + "prose": "The service provider may determine what is considered a sufficient degree of separation between the primary and alternate processing sites, based on the types of threats that are of concern. For one particular type of threat (i.e., hostile cyber attack), the degree of separation between sites will be less relevant." + } + ] + } + ] + }, + { + "position": "starting", + "by-id": "cp-7.1_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cp-7.1_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "cp-7.2", + "adds": [ + { + "position": "starting", + "by-id": "cp-7.2_obj-1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cp-7.2_obj-2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cp-7.2_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "cp-7.3", + "adds": [ + { + "position": "starting", + "by-id": "cp-7.3_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cp-7.3_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "cp-7.4", + "adds": [ + { + "position": "starting", + "by-id": "cp-7.4_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cp-7.4_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "cp-8", + "adds": [ + { + "position": "ending", + "by-id": "cp-8_smt", + "parts": [ + { + "id": "cp-8_fr", + "name": "item", + "title": "CP-8 Additional FedRAMP Requirements and Guidance", + "parts": [ + { + "id": "cp-8_fr_gdn.1", + "name": "item", + "props": [ + { + "name": "label", + "value": "Requirement:" + } + ], + "prose": "The service provider defines a time period consistent with the recovery time objectives and business impact analysis." + } + ] + } + ] + }, + { + "position": "starting", + "by-id": "cp-8_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cp-8_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "cp-8.1", + "adds": [ + { + "position": "starting", + "by-id": "cp-8.1_obj.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cp-8.1_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cp-8.1_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "cp-8.1_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "cp-8.2", + "adds": [ + { + "position": "starting", + "by-id": "cp-8.2_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cp-8.2_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "cp-8.3", + "adds": [ + { + "position": "starting", + "by-id": "cp-8.3_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cp-8.3_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "cp-8.4", + "adds": [ + { + "position": "starting", + "by-id": "cp-8.4_obj.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cp-8.4_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cp-8.4_obj.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cp-8.4_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "cp-8.4_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "cp-8.4_smt.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "cp-9", + "adds": [ + { + "position": "ending", + "by-id": "cp-9_smt", + "parts": [ + { + "id": "cp-9_fr", + "name": "item", + "title": "CP-9 Additional FedRAMP Requirements and Guidance", + "parts": [ + { + "id": "cp-9_fr_smt.1", + "name": "item", + "props": [ + { + "name": "label", + "value": "Requirement:" + } + ], + "prose": "The service provider shall determine what elements of the cloud environment require the Information System Backup control. The service provider shall determine how Information System Backup is going to be verified and appropriate periodicity of the check." + }, + { + "id": "cp-9_fr_smt.2", + "name": "item", + "props": [ + { + "name": "label", + "value": "(a) Requirement:" + } + ], + "prose": "The service provider maintains at least three backup copies of user-level information (at least one of which is available online) or provides an equivalent alternative." + }, + { + "id": "cp-9_fr_smt.3", + "name": "item", + "props": [ + { + "name": "label", + "value": "(b) Requirement:" + } + ], + "prose": "The service provider maintains at least three backup copies of system-level information (at least one of which is available online) or provides an equivalent alternative." + }, + { + "id": "cp-9_fr_smt.4", + "name": "item", + "props": [ + { + "name": "label", + "value": "(c) Requirement:" + } + ], + "prose": "The service provider maintains at least three backup copies of information system documentation including security information (at least one of which is available online) or provides an equivalent alternative." + } + ] + } + ] + }, + { + "position": "starting", + "by-id": "cp-9_obj.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cp-9_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cp-9_obj.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cp-9_obj.d", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cp-9_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "cp-9_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "cp-9_smt.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "cp-9_smt.d", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "cp-9.1", + "adds": [ + { + "position": "starting", + "by-id": "cp-9.1_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cp-9.1_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "cp-9.2", + "adds": [ + { + "position": "starting", + "by-id": "cp-9.2_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cp-9.2_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "cp-9.3", + "adds": [ + { + "position": "starting", + "by-id": "cp-9.3_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cp-9.3_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "cp-9.5", + "adds": [ + { + "position": "starting", + "by-id": "cp-9.5_obj-1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cp-9.5_obj-2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cp-9.5_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "cp-9.8", + "adds": [ + { + "position": "ending", + "by-id": "cp-9.8_smt", + "parts": [ + { + "id": "cp-9.8_fr", + "name": "item", + "title": "CP-9 (8) Additional FedRAMP Requirements and Guidance", + "parts": [ + { + "id": "cp-9.8_fr_gdn.1", + "name": "guidance", + "props": [ + { + "name": "label", + "value": "Guidance:" + } + ], + "prose": "Note that this enhancement requires the use of cryptography which must be compliant with Federal requirements and utilize FIPS validated or NSA approved cryptography (see SC-13.)" + } + ] + } + ] + }, + { + "position": "starting", + "by-id": "cp-9.8_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "cp-9.8_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "ia-1", + "adds": [ + { + "position": "starting", + "by-id": "ia-1_obj.a-1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ia-1_obj.a-2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ia-1_obj.a-3", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ia-1_obj.a-4", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ia-1_obj.a.1.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ia-1_obj.a.1.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ia-1_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ia-1_obj.c.1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ia-1_obj.c.2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ia-1_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point.", + "remarks": "This response must address all control sub-statement requirements." + } + ] + }, + { + "position": "starting", + "by-id": "ia-1_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ia-1_smt.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point.", + "remarks": "This response must address all control sub-statement requirements." + } + ] + } + ] + }, + { + "control-id": "ia-12.2", + "adds": [ + { + "position": "starting", + "by-id": "ia-12.2_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ia-12.2_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "ia-12.3", + "adds": [ + { + "position": "starting", + "by-id": "ia-12.3_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ia-12.3_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "ia-12.4", + "adds": [ + { + "position": "starting", + "by-id": "ia-12.4_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ia-12.4_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "ia-2", + "adds": [ + { + "position": "ending", + "by-id": "ia-2_smt", + "parts": [ + { + "id": "ia-2_fr", + "name": "item", + "title": "IA-2 Additional FedRAMP Requirements and Guidance", + "parts": [ + { + "id": "ia-2_fr_smt.1", + "name": "item", + "props": [ + { + "name": "label", + "value": "Requirement:" + } + ], + "prose": "For all control enhancements that specify multifactor authentication, the implementation must adhere to the Digital Identity Guidelines specified in NIST Special Publication 800-63B." + }, + { + "id": "ia-2_fr_smt.2", + "name": "item", + "props": [ + { + "name": "label", + "value": "Requirement:" + } + ], + "prose": "Multi-factor authentication must be phishing-resistant." + }, + { + "id": "ia-2_fr_smt.3", + "name": "item", + "props": [ + { + "name": "label", + "value": "Requirement:" + } + ], + "prose": "All uses of encrypted virtual private networks must meet all applicable Federal requirements and architecture, dataflow, and security and privacy controls must be documented, assessed, and authorized to operate." + }, + { + "id": "ia-2_fr_gdn.1", + "name": "guidance", + "props": [ + { + "name": "label", + "value": "Guidance:" + } + ], + "prose": "\\\"Phishing-resistant\\\" authentication refers to authentication processes designed to detect and prevent disclosure of authentication secrets and outputs to a website or application masquerading as a legitimate system." + } + ] + } + ] + }, + { + "position": "starting", + "by-id": "ia-2_obj-1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ia-2_obj-2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ia-2_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ia-2", + "props": [ + { + "name": "CORE", + "ns": "https://fedramp.gov/ns/oscal", + "value": "true" + } + ] + } + ] + }, + { + "control-id": "ia-2.1", + "adds": [ + { + "position": "ending", + "by-id": "ia-2.1_smt", + "parts": [ + { + "id": "ia-2.1_fr", + "name": "item", + "title": "IA-2 (1) Additional FedRAMP Requirements and Guidance", + "parts": [ + { + "id": "ia-2.1_fr_smt.1", + "name": "item", + "props": [ + { + "name": "label", + "value": "Requirement:" + } + ], + "prose": "According to SP 800-63-3, SP 800-63A (IAL), SP 800-63B (AAL), and SP 800-63C (FAL)." + }, + { + "id": "ia-2.1_fr_smt.2", + "name": "item", + "props": [ + { + "name": "label", + "value": "Requirement:" + } + ], + "prose": "Multi-factor authentication must be phishing-resistant." + }, + { + "id": "ia-2.1_fr_gdn.1", + "name": "guidance", + "props": [ + { + "name": "label", + "value": "Guidance:" + } + ], + "prose": "Multi-factor authentication to subsequent components in the same user domain is not required." + } + ] + } + ] + }, + { + "position": "starting", + "by-id": "ia-2.1_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ia-2.1_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ia-2.1", + "props": [ + { + "name": "CORE", + "ns": "https://fedramp.gov/ns/oscal", + "value": "true" + } + ] + } + ] + }, + { + "control-id": "ia-2.2", + "adds": [ + { + "position": "ending", + "by-id": "ia-2.2_smt", + "parts": [ + { + "id": "ia-2.2_fr", + "name": "item", + "title": "IA-2 (2) Additional FedRAMP Requirements and Guidance", + "parts": [ + { + "id": "ia-2.2_fr_smt.1", + "name": "item", + "props": [ + { + "name": "label", + "value": "Requirement:" + } + ], + "prose": "According to SP 800-63-3, SP 800-63A (IAL), SP 800-63B (AAL), and SP 800-63C (FAL)." + }, + { + "id": "ia-2.2_fr_smt.2", + "name": "item", + "props": [ + { + "name": "label", + "value": "Requirement:" + } + ], + "prose": "Multi-factor authentication must be phishing-resistant." + }, + { + "id": "ia-2.2_fr_gdn.1", + "name": "guidance", + "props": [ + { + "name": "label", + "value": "Guidance:" + } + ], + "prose": "Multi-factor authentication to subsequent components in the same user domain is not required." + } + ] + } + ] + }, + { + "position": "starting", + "by-id": "ia-2.2_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ia-2.2_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ia-2.2", + "props": [ + { + "name": "CORE", + "ns": "https://fedramp.gov/ns/oscal", + "value": "true" + } + ] + } + ] + }, + { + "control-id": "ia-2.5", + "adds": [ + { + "position": "starting", + "by-id": "ia-2.5_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ia-2.5_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ia-2.5", + "props": [ + { + "name": "CORE", + "ns": "https://fedramp.gov/ns/oscal", + "value": "true" + } + ] + } + ] + }, + { + "control-id": "ia-2.6", + "adds": [ + { + "position": "ending", + "by-id": "ia-2.6_smt", + "parts": [ + { + "id": "ia-2.6_fr", + "name": "item", + "title": "IA-2 (6) Additional FedRAMP Requirements and Guidance", + "parts": [ + { + "id": "ia-2.6_fr_gdn.1", + "name": "guidance", + "props": [ + { + "name": "label", + "value": "Guidance:" + } + ], + "prose": "PIV=separate device. Please refer to NIST SP 800-157 Guidelines for Derived Personal Identity Verification (PIV) Credentials." + }, + { + "id": "ia-2.6_fr_gdn.2", + "name": "guidance", + "props": [ + { + "name": "label", + "value": "Guidance:" + } + ], + "prose": "See SC-13 Guidance for more information on FIPS-validated or NSA-approved cryptography." + } + ] + } + ] + }, + { + "position": "starting", + "by-id": "ia-2.6_obj.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ia-2.6_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ia-2.6_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ia-2.6_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ia-2.6", + "props": [ + { + "name": "CORE", + "ns": "https://fedramp.gov/ns/oscal", + "value": "true" + } + ] + } + ] + }, + { + "control-id": "ia-2.12", + "adds": [ + { + "position": "ending", + "by-id": "ia-2.12_smt", + "parts": [ + { + "id": "ia-2.12_fr", + "name": "item", + "title": "IA-2 (12) Additional FedRAMP Requirements and Guidance", + "parts": [ + { + "id": "ia-2.12_fr_gdn.1", + "name": "guidance", + "props": [ + { + "name": "label", + "value": "Guidance:" + } + ], + "prose": "Include Common Access Card (CAC), i.e., the DoD technical implementation of PIV/FIPS 201/HSPD-12." + } + ] + } + ] + }, + { + "position": "starting", + "by-id": "ia-2.12_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ia-2.12_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ia-2.12", + "props": [ + { + "name": "CORE", + "ns": "https://fedramp.gov/ns/oscal", + "value": "true" + } + ] + } + ] + }, + { + "control-id": "ia-2.8", + "adds": [ + { + "position": "starting", + "by-id": "ia-2.8_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ia-2.8_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ia-2.8", + "props": [ + { + "name": "CORE", + "ns": "https://fedramp.gov/ns/oscal", + "value": "true" + } + ] + } + ] + }, + { + "control-id": "ia-3", + "adds": [ + { + "position": "starting", + "by-id": "ia-3_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ia-3_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "ia-4", + "adds": [ + { + "position": "starting", + "by-id": "ia-4_obj.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ia-4_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ia-4_obj.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ia-4_obj.d", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ia-4_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ia-4_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ia-4_smt.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ia-4_smt.d", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ia-4", + "props": [ + { + "name": "CORE", + "ns": "https://fedramp.gov/ns/oscal", + "value": "true" + } + ] + } + ] + }, + { + "control-id": "ia-4.4", + "adds": [ + { + "position": "starting", + "by-id": "ia-4.4_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ia-4.4_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "ia-5", + "adds": [ + { + "position": "ending", + "by-id": "ia-5_smt", + "parts": [ + { + "id": "ia-5_fr", + "name": "item", + "title": "IA-5 Additional FedRAMP Requirements and Guidance", + "parts": [ + { + "id": "ia-5_fr_smt.1", + "name": "item", + "props": [ + { + "name": "label", + "value": "Requirement:" + } + ], + "prose": "Authenticators must be compliant with NIST SP 800-63-3 Digital Identity Guidelines IAL, AAL, FAL level 3. Link https://pages.nist.gov/800-63-3" + }, + { + "id": "ia-5_fr_gdn.1", + "name": "guidance", + "props": [ + { + "name": "label", + "value": "Guidance:" + } + ], + "prose": "SP 800-63C Section 6.2.3 Encrypted Assertion requires that authentication assertions be encrypted when passed through third parties, such as a browser. For example, a SAML assertion can be encrypted using XML-Encryption, or an OpenID Connect ID Token can be encrypted using JSON Web Encryption (JWE)." + } + ] + } + ] + }, + { + "position": "starting", + "by-id": "ia-5_obj.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ia-5_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ia-5_obj.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ia-5_obj.d", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ia-5_obj.e", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ia-5_obj.f", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ia-5_obj.g", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ia-5_obj.h-1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ia-5_obj.h-2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ia-5_obj.i", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ia-5_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ia-5_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ia-5_smt.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ia-5_smt.d", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ia-5_smt.e", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ia-5_smt.f", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ia-5_smt.g", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ia-5_smt.h", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ia-5_smt.i", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ia-5", + "props": [ + { + "name": "CORE", + "ns": "https://fedramp.gov/ns/oscal", + "value": "true" + } + ] + } + ] + }, + { + "control-id": "ia-5.1", + "adds": [ + { + "position": "ending", + "by-id": "ia-5.1_smt", + "parts": [ + { + "id": "ia-5.1_fr", + "name": "item", + "title": "IA-5 (1) Additional FedRAMP Requirements and Guidance", + "parts": [ + { + "id": "ia-5.1_fr_smt.1", + "name": "item", + "props": [ + { + "name": "label", + "value": "Requirement:" + } + ], + "prose": "Password policies must be compliant with NIST SP 800-63B for all memorized, lookup, out-of-band, or One-Time-Passwords (OTP). Password policies shall not enforce special character or minimum password rotation requirements for memorized secrets of users." + }, + { + "id": "ia-5.1_fr_smt.2", + "name": "item", + "props": [ + { + "name": "label", + "value": "(h) Requirement:" + } + ], + "prose": "For cases where technology doesn't allow multi-factor authentication, these rules should be enforced: must have a minimum length of 14 characters and must support all printable ASCII characters.\n\nFor emergency use accounts, these rules should be enforced: must have a minimum length of 14 characters, must support all printable ASCII characters, and passwords must be changed if used." + }, + { + "id": "ia-5.1_fr_gdn.1", + "name": "guidance", + "props": [ + { + "name": "label", + "value": "Guidance:" + } + ], + "prose": "Note that (c) and (d) require the use of cryptography which must be compliant with Federal requirements and utilize FIPS validated or NSA approved cryptography (see SC-13)." + } + ] + } + ] + }, + { + "position": "starting", + "by-id": "ia-5.1_obj.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ia-5.1_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ia-5.1_obj.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ia-5.1_obj.d", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ia-5.1_obj.e", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ia-5.1_obj.f", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ia-5.1_obj.g", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ia-5.1_obj.h", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ia-5.1_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ia-5.1_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ia-5.1_smt.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ia-5.1_smt.d", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ia-5.1_smt.e", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ia-5.1_smt.f", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ia-5.1_smt.g", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ia-5.1_smt.h", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "ia-5.2", + "adds": [ + { + "position": "starting", + "by-id": "ia-5.2_obj.a.1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ia-5.2_obj.a.2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ia-5.2_obj.b.1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ia-5.2_obj.b.2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ia-5.2_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ia-5.2_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "ia-5.6", + "adds": [ + { + "position": "starting", + "by-id": "ia-5.6_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ia-5.6_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "ia-5.7", + "adds": [ + { + "position": "ending", + "by-id": "ia-5.7_smt", + "parts": [ + { + "id": "ia-5.7_fr", + "name": "item", + "title": "IA-5 (7) Additional FedRAMP Requirements and Guidance", + "parts": [ + { + "id": "ia-5.7_fr_gdn.1", + "name": "guidance", + "props": [ + { + "name": "label", + "value": "Guidance:" + } + ], + "prose": "In this context, prohibited static storage refers to any storage where unencrypted authenticators, such as passwords, persist beyond the time required to complete the access process." + } + ] + } + ] + }, + { + "position": "starting", + "by-id": "ia-5.7_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ia-5.7_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "ia-5.8", + "adds": [ + { + "position": "ending", + "by-id": "ia-5.8_smt", + "parts": [ + { + "id": "ia-5.8_fr", + "name": "item", + "title": "IA-5 (8) Additional FedRAMP Requirements and Guidance", + "parts": [ + { + "id": "ia-5.8_fr_gdn.x", + "name": "guidance", + "props": [ + { + "name": "label", + "value": "Guidance:" + } + ], + "prose": "If a single user authentication domain is used to access multiple systems, such as in single-sign-on, then only a single authenticator is required." + } + ] + } + ] + }, + { + "position": "starting", + "by-id": "ia-5.8_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ia-5.8_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "ia-5.13", + "adds": [ + { + "position": "ending", + "by-id": "ia-5.13_smt", + "parts": [ + { + "id": "ia-5.13_fr", + "name": "item", + "title": "IA-5 (13) Additional FedRAMP Requirements and Guidance", + "parts": [ + { + "id": "ia-5.13_fr_gdn.1", + "name": "guidance", + "props": [ + { + "name": "label", + "value": "Guidance:" + } + ], + "prose": "For components subject to configuration baseline(s) (such as STIG or CIS,) the time period should conform to the baseline standard." + } + ] + } + ] + }, + { + "position": "starting", + "by-id": "ia-5.13_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ia-5.13_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "ia-11", + "adds": [ + { + "position": "ending", + "by-id": "ia-11_smt", + "parts": [ + { + "id": "ia-11_fr", + "name": "item", + "title": "IA-11 Additional FedRAMP Requirements and Guidance", + "parts": [ + { + "id": "ia-11_fr_gdn.1", + "name": "guidance", + "props": [ + { + "name": "label", + "value": "Guidance:" + } + ], + "prose": "The fixed time period cannot exceed the limits set in SP 800-63. At this writing they are:\n\n* AAL3 (high baseline) * 12 hours or * 15 minutes of inactivity \n" + } + ] + } + ] + }, + { + "position": "starting", + "by-id": "ia-11_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ia-11_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "ia-12", + "adds": [ + { + "position": "ending", + "by-id": "ia-12_smt", + "parts": [ + { + "id": "ia-12_fr", + "name": "item", + "title": "IA-12 Additional FedRAMP Requirements and Guidance", + "parts": [ + { + "id": "ia-12_fr_gdn.1", + "name": "guidance", + "props": [ + { + "name": "label", + "value": "Guidance:" + } + ], + "prose": "In accordance with NIST SP 800-63A Enrollment and Identity Proofing" + } + ] + } + ] + }, + { + "position": "starting", + "by-id": "ia-12_obj.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ia-12_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ia-12_obj.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ia-12_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ia-12_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ia-12_smt.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "ia-12.5", + "adds": [ + { + "position": "ending", + "by-id": "ia-12.5_smt", + "parts": [ + { + "id": "ia-12.5_fr", + "name": "item", + "title": "IA-12 (5) Additional FedRAMP Requirements and Guidance", + "parts": [ + { + "id": "ia-12.5_fr_gdn.1", + "name": "guidance", + "props": [ + { + "name": "label", + "value": "Guidance:" + } + ], + "prose": "In accordance with NIST SP 800-63A Enrollment and Identity Proofing" + } + ] + } + ] + }, + { + "position": "starting", + "by-id": "ia-12.5_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ia-12.5_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "ia-6", + "adds": [ + { + "position": "starting", + "by-id": "ia-6_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ia-6_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "ia-7", + "adds": [ + { + "position": "starting", + "by-id": "ia-7_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ia-7_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "ia-8", + "adds": [ + { + "position": "starting", + "by-id": "ia-8_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ia-8_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "ia-8.1", + "adds": [ + { + "position": "starting", + "by-id": "ia-8.1_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ia-8.1_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "ia-8.2", + "adds": [ + { + "position": "starting", + "by-id": "ia-8.2_obj.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ia-8.2_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ia-8.2_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ia-8.2_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "ia-8.4", + "adds": [ + { + "position": "starting", + "by-id": "ia-8.4_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ia-8.4_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "ir-1", + "adds": [ + { + "position": "starting", + "by-id": "ir-1_obj.a-1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ir-1_obj.a-2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ir-1_obj.a-3", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ir-1_obj.a-4", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ir-1_obj.a.1.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ir-1_obj.a.1.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ir-1_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ir-1_obj.c.1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ir-1_obj.c.2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ir-1_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point.", + "remarks": "This response must address all control sub-statement requirements." + } + ] + }, + { + "position": "starting", + "by-id": "ir-1_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ir-1_smt.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point.", + "remarks": "This response must address all control sub-statement requirements." + } + ] + } + ] + }, + { + "control-id": "ir-2", + "adds": [ + { + "position": "starting", + "by-id": "ir-2_obj.a.1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ir-2_obj.a.2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ir-2_obj.a.3", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ir-2_obj.b-1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ir-2_obj.b-2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ir-2_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ir-2_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "ir-2.1", + "adds": [ + { + "position": "starting", + "by-id": "ir-2.1_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ir-2.1_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "ir-2.2", + "adds": [ + { + "position": "starting", + "by-id": "ir-2.2_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ir-2.2_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "ir-3", + "adds": [ + { + "position": "ending", + "by-id": "ir-3_smt", + "parts": [ + { + "id": "ir-3_fr", + "name": "item", + "title": "IR-3-2 Additional FedRAMP Requirements and Guidance", + "parts": [ + { + "id": "ir-3_fr_smt.1", + "name": "item", + "props": [ + { + "name": "label", + "value": "Requirement:" + } + ], + "prose": "The service provider defines tests and/or exercises in accordance with NIST Special Publication 800-61 (as amended). Functional testing must occur prior to testing for initial authorization. Annual functional testing may be concurrent with required penetration tests (see CA-8). The service provider provides test plans to the JAB/AO annually. Test plans are approved and accepted by the JAB/AO prior to test commencing." + } + ] + } + ] + }, + { + "position": "starting", + "by-id": "ir-3_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ir-3_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ir-3", + "props": [ + { + "name": "CORE", + "ns": "https://fedramp.gov/ns/oscal", + "value": "true" + } + ] + } + ] + }, + { + "control-id": "ir-3.2", + "adds": [ + { + "position": "starting", + "by-id": "ir-3.2_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ir-3.2_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "ir-4", + "adds": [ + { + "position": "ending", + "by-id": "ir-4_smt", + "parts": [ + { + "id": "ir-4_fr", + "name": "item", + "title": "IR-4 Additional FedRAMP Requirements and Guidance", + "parts": [ + { + "id": "ir-4_fr_smt.1", + "name": "item", + "props": [ + { + "name": "label", + "value": "Requirement:" + } + ], + "prose": "The FISMA definition of \\\"incident\\\" shall be used: \\\"An occurrence that actually or imminently jeopardizes, without lawful authority, the confidentiality, integrity, or availability of information or an information system; or constitutes a violation or imminent threat of violation of law, security policies, security procedures, or acceptable use policies.\\\"" + }, + { + "id": "ir-4_fr_smt.2", + "name": "item", + "props": [ + { + "name": "label", + "value": "Requirement:" + } + ], + "prose": "The service provider ensures that individuals conducting incident handling meet personnel security requirements commensurate with the criticality/sensitivity of the information being processed, stored, and transmitted by the information system." + } + ] + } + ] + }, + { + "position": "starting", + "by-id": "ir-4_obj.a-1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ir-4_obj.a-2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ir-4_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ir-4_obj.c-1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ir-4_obj.c-2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ir-4_obj.d", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ir-4_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ir-4_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ir-4_smt.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ir-4_smt.d", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ir-4", + "props": [ + { + "name": "CORE", + "ns": "https://fedramp.gov/ns/oscal", + "value": "true" + } + ] + } + ] + }, + { + "control-id": "ir-4.1", + "adds": [ + { + "position": "starting", + "by-id": "ir-4.1_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ir-4.1_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ir-4.1", + "props": [ + { + "name": "CORE", + "ns": "https://fedramp.gov/ns/oscal", + "value": "true" + } + ] + } + ] + }, + { + "control-id": "ir-4.11", + "adds": [ + { + "position": "starting", + "by-id": "ir-4.11_obj-1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ir-4.11_obj-2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ir-4.11_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "ir-4.2", + "adds": [ + { + "position": "starting", + "by-id": "ir-4.2_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ir-4.2_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ir-4.2", + "props": [ + { + "name": "CORE", + "ns": "https://fedramp.gov/ns/oscal", + "value": "true" + } + ] + } + ] + }, + { + "control-id": "ir-4.4", + "adds": [ + { + "position": "starting", + "by-id": "ir-4.4_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ir-4.4_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ir-4.4", + "props": [ + { + "name": "CORE", + "ns": "https://fedramp.gov/ns/oscal", + "value": "true" + } + ] + } + ] + }, + { + "control-id": "ir-4.6", + "adds": [ + { + "position": "starting", + "by-id": "ir-4.6_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ir-4.6_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ir-4.6", + "props": [ + { + "name": "CORE", + "ns": "https://fedramp.gov/ns/oscal", + "value": "true" + } + ] + } + ] + }, + { + "control-id": "ir-5", + "adds": [ + { + "position": "starting", + "by-id": "ir-5_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ir-5_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "ir-5.1", + "adds": [ + { + "position": "starting", + "by-id": "ir-5.1_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ir-5.1_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "ir-6", + "adds": [ + { + "position": "ending", + "by-id": "ir-6_smt", + "parts": [ + { + "id": "ir-6_fr", + "name": "item", + "title": "IR-6 Additional FedRAMP Requirements and Guidance", + "parts": [ + { + "id": "ir-6_fr_smt.1", + "name": "item", + "props": [ + { + "name": "label", + "value": "Requirement:" + } + ], + "prose": "Reports security incident information according to FedRAMP Incident Communications Procedure." + } + ] + } + ] + }, + { + "position": "starting", + "by-id": "ir-6_obj.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ir-6_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ir-6_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ir-6_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "ir-6.1", + "adds": [ + { + "position": "starting", + "by-id": "ir-6.1_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ir-6.1_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "ir-6.3", + "adds": [ + { + "position": "starting", + "by-id": "ir-6.3_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ir-6.3_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "ir-7", + "adds": [ + { + "position": "starting", + "by-id": "ir-7_obj-1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ir-7_obj-2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ir-7_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "ir-7.1", + "adds": [ + { + "position": "starting", + "by-id": "ir-7.1_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ir-7.1_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "ir-8", + "adds": [ + { + "position": "ending", + "by-id": "ir-8_smt", + "parts": [ + { + "id": "ir-8_fr", + "name": "item", + "title": "IR-8 Additional FedRAMP Requirements and Guidance", + "parts": [ + { + "id": "ir-8_fr_smt.1", + "name": "item", + "props": [ + { + "name": "label", + "value": "(b) Requirement:" + } + ], + "prose": "The service provider defines a list of incident response personnel (identified by name and/or by role) and organizational elements. The incident response list includes designated FedRAMP personnel." + }, + { + "id": "ir-8_fr_smt.2", + "name": "item", + "props": [ + { + "name": "label", + "value": "(d) Requirement:" + } + ], + "prose": "The service provider defines a list of incident response personnel (identified by name and/or by role) and organizational elements. The incident response list includes designated FedRAMP personnel." + } + ] + } + ] + }, + { + "position": "starting", + "by-id": "ir-8_obj.a.1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ir-8_obj.a.2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ir-8_obj.a.3", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ir-8_obj.a.4", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ir-8_obj.a.5", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ir-8_obj.a.6", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ir-8_obj.a.7", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ir-8_obj.a.8", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ir-8_obj.a.9", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ir-8_obj.a.10", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ir-8_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ir-8_obj.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ir-8_obj.d", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ir-8_obj.e", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ir-8_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ir-8_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ir-8_smt.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ir-8_smt.d", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ir-8_smt.e", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "ir-9", + "adds": [ + { + "position": "starting", + "by-id": "ir-9_obj.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ir-9_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ir-9_obj.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ir-9_obj.d", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ir-9_obj.e", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ir-9_obj.f", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ir-9_obj.g", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ir-9_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ir-9_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ir-9_smt.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ir-9_smt.d", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ir-9_smt.e", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ir-9_smt.f", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ir-9_smt.g", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "ir-9.2", + "adds": [ + { + "position": "starting", + "by-id": "ir-9.2_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ir-9.2_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "ir-9.3", + "adds": [ + { + "position": "starting", + "by-id": "ir-9.3_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ir-9.3_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "ir-9.4", + "adds": [ + { + "position": "starting", + "by-id": "ir-9.4_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ir-9.4_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "ma-1", + "adds": [ + { + "position": "starting", + "by-id": "ma-1_obj.a-1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ma-1_obj.a-2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ma-1_obj.a-3", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ma-1_obj.a-4", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ma-1_obj.a.1.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ma-1_obj.a.1.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ma-1_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ma-1_obj.c.1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ma-1_obj.c.2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ma-1_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point.", + "remarks": "This response must address all control sub-statement requirements." + } + ] + }, + { + "position": "starting", + "by-id": "ma-1_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ma-1_smt.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point.", + "remarks": "This response must address all control sub-statement requirements." + } + ] + } + ] + }, + { + "control-id": "ma-2", + "adds": [ + { + "position": "starting", + "by-id": "ma-2_obj.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ma-2_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ma-2_obj.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ma-2_obj.d", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ma-2_obj.e", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ma-2_obj.f", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ma-2_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ma-2_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ma-2_smt.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ma-2_smt.d", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ma-2_smt.e", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ma-2_smt.f", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "ma-2.2", + "adds": [ + { + "position": "starting", + "by-id": "ma-2.2_obj.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ma-2.2_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ma-2.2_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ma-2.2_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "ma-3", + "adds": [ + { + "position": "starting", + "by-id": "ma-3_obj.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ma-3_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ma-3_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ma-3_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "ma-3.1", + "adds": [ + { + "position": "starting", + "by-id": "ma-3.1_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ma-3.1_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "ma-3.2", + "adds": [ + { + "position": "starting", + "by-id": "ma-3.2_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ma-3.2_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ma-3.2", + "props": [ + { + "name": "CORE", + "ns": "https://fedramp.gov/ns/oscal", + "value": "true" + } + ] + } + ] + }, + { + "control-id": "ma-3.3", + "adds": [ + { + "position": "starting", + "by-id": "ma-3.3_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ma-3.3_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ma-3.3_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ma-3.3_smt.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ma-3.3_smt.d", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "ma-4", + "adds": [ + { + "position": "starting", + "by-id": "ma-4_obj.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ma-4_obj.b-1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ma-4_obj.b-2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ma-4_obj.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ma-4_obj.d", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ma-4_obj.e", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ma-4_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ma-4_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ma-4_smt.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ma-4_smt.d", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ma-4_smt.e", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "ma-4.3", + "adds": [ + { + "position": "starting", + "by-id": "ma-4.3_obj.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ma-4.3_obj.b-1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ma-4.3_obj.b-2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ma-4.3_obj.b-3", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ma-4.3_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ma-4.3_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "ma-5", + "adds": [ + { + "position": "starting", + "by-id": "ma-5_obj.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ma-5_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ma-5_obj.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ma-5_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ma-5_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ma-5_smt.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "ma-5.1", + "adds": [ + { + "position": "starting", + "by-id": "ma-5.1_obj.a.1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ma-5.1_obj.a.2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ma-5.1_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ma-5.1_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ma-5.1_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "ma-6", + "adds": [ + { + "position": "starting", + "by-id": "ma-6_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ma-6_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "mp-1", + "adds": [ + { + "position": "starting", + "by-id": "mp-1_obj.a-1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "mp-1_obj.a-2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "mp-1_obj.a-3", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "mp-1_obj.a-4", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "mp-1_obj.a.1.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "mp-1_obj.a.1.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "mp-1_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "mp-1_obj.c.1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "mp-1_obj.c.2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "mp-1_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point.", + "remarks": "This response must address all control sub-statement requirements." + } + ] + }, + { + "position": "starting", + "by-id": "mp-1_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "mp-1_smt.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point.", + "remarks": "This response must address all control sub-statement requirements." + } + ] + } + ] + }, + { + "control-id": "mp-2", + "adds": [ + { + "position": "starting", + "by-id": "mp-2_obj-1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "mp-2_obj-2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "mp-2_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "mp-3", + "adds": [ + { + "position": "ending", + "by-id": "mp-3_smt", + "parts": [ + { + "id": "mp-3_fr", + "name": "item", + "title": "MP-3 Additional FedRAMP Requirements and Guidance", + "parts": [ + { + "id": "mp-3_fr_gdn.1", + "name": "guidance", + "props": [ + { + "name": "label", + "value": "(b) Guidance:" + } + ], + "prose": "Second parameter not-applicable" + } + ] + } + ] + }, + { + "position": "starting", + "by-id": "mp-3_obj.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "mp-3_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "mp-3_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "mp-3_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "mp-4", + "adds": [ + { + "position": "ending", + "by-id": "mp-4_smt", + "parts": [ + { + "id": "mp-4_fr", + "name": "item", + "title": "MP-4 Additional FedRAMP Requirements and Guidance", + "parts": [ + { + "id": "mp-4_fr_smt.1", + "name": "item", + "props": [ + { + "name": "label", + "value": "(a) Requirement:" + } + ], + "prose": "The service provider defines controlled areas within facilities where the information and information system reside." + } + ] + } + ] + }, + { + "position": "starting", + "by-id": "mp-4_obj.a-1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "mp-4_obj.a-2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "mp-4_obj.a-3", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "mp-4_obj.a-4", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "mp-4_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "mp-4_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "mp-4_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "mp-5", + "adds": [ + { + "position": "ending", + "by-id": "mp-5_smt", + "parts": [ + { + "id": "mp-5_fr", + "name": "item", + "title": "MP-5 Additional FedRAMP Requirements and Guidance", + "parts": [ + { + "id": "mp-5_fr_smt.1", + "name": "item", + "props": [ + { + "name": "label", + "value": "(a) Requirement:" + } + ], + "prose": "The service provider defines security measures to protect digital and non-digital media in transport. The security measures are approved and accepted by the JAB/AO." + } + ] + } + ] + }, + { + "position": "starting", + "by-id": "mp-5_obj.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "mp-5_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "mp-5_obj.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "mp-5_obj.d-1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "mp-5_obj.d-2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "mp-5_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "mp-5_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "mp-5_smt.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "mp-5_smt.d", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "mp-6", + "adds": [ + { + "position": "starting", + "by-id": "mp-6_obj.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "mp-6_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "mp-6_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "mp-6_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "mp-6.1", + "adds": [ + { + "position": "ending", + "by-id": "mp-6.1_smt", + "parts": [ + { + "id": "mp-6.1_fr", + "name": "item", + "title": "MP-6 (1) Additional FedRAMP Requirements and Guidance", + "parts": [ + { + "id": "mp-6.1_fr_smt.1", + "name": "item", + "props": [ + { + "name": "label", + "value": "Requirement:" + } + ], + "prose": "Must comply with NIST SP 800-88" + } + ] + } + ] + }, + { + "position": "starting", + "by-id": "mp-6.1_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "mp-6.1_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "mp-6.2", + "adds": [ + { + "position": "ending", + "by-id": "mp-6.2_smt", + "parts": [ + { + "id": "mp-6.2_fr", + "name": "item", + "title": "MP-6 (2) Additional FedRAMP Requirements and Guidance", + "parts": [ + { + "id": "mp-6.2_fr_smt.1", + "name": "guidance", + "props": [ + { + "name": "label", + "value": "Guidance:" + } + ], + "prose": "Equipment and procedures may be tested or validated for effectiveness" + } + ] + } + ] + }, + { + "position": "starting", + "by-id": "mp-6.2_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "mp-6.2_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "mp-6.3", + "adds": [ + { + "position": "ending", + "by-id": "mp-6.3_smt", + "parts": [ + { + "id": "mp-6.3_fr", + "name": "item", + "title": "MP-6 (3) Additional FedRAMP Requirements and Guidance", + "parts": [ + { + "id": "mp-6.3_fr_smt.1", + "name": "item", + "props": [ + { + "name": "label", + "value": "Requirement:" + } + ], + "prose": "Must comply with NIST SP 800-88" + } + ] + } + ] + }, + { + "position": "starting", + "by-id": "mp-6.3_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "mp-6.3_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "mp-7", + "adds": [ + { + "position": "starting", + "by-id": "mp-7_obj.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "mp-7_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "mp-7_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "mp-7_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "pe-1", + "adds": [ + { + "position": "starting", + "by-id": "pe-1_obj.a-1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pe-1_obj.a-2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pe-1_obj.a-3", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pe-1_obj.a-4", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pe-1_obj.a.1.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pe-1_obj.a.1.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pe-1_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pe-1_obj.c.1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pe-1_obj.c.2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pe-1_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point.", + "remarks": "This response must address all control sub-statement requirements." + } + ] + }, + { + "position": "starting", + "by-id": "pe-1_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "pe-1_smt.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point.", + "remarks": "This response must address all control sub-statement requirements." + } + ] + } + ] + }, + { + "control-id": "pe-10", + "adds": [ + { + "position": "starting", + "by-id": "pe-10_obj.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pe-10_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pe-10_obj.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pe-10_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "pe-10_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "pe-10_smt.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "pe-11", + "adds": [ + { + "position": "starting", + "by-id": "pe-11_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pe-11_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "pe-11.1", + "adds": [ + { + "position": "starting", + "by-id": "pe-11.1_obj-1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pe-11.1_obj-2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pe-11.1_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "pe-12", + "adds": [ + { + "position": "starting", + "by-id": "pe-12_obj-1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pe-12_obj-2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pe-12_obj-3", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pe-12_obj-4", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pe-12_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "pe-13", + "adds": [ + { + "position": "starting", + "by-id": "pe-13_obj-1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pe-13_obj-2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pe-13_obj-3", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pe-13_obj-4", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pe-13_obj-5", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pe-13_obj-6", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pe-13_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "pe-13.1", + "adds": [ + { + "position": "starting", + "by-id": "pe-13.1_obj-1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pe-13.1_obj-2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pe-13.1_obj-3", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pe-13.1_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "pe-13.2", + "adds": [ + { + "position": "starting", + "by-id": "pe-13.2_obj.a-1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pe-13.2_obj.a-2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pe-13.2_obj.a-3", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pe-13.2_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pe-13.2_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "pe-13.2_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "pe-14", + "adds": [ + { + "position": "ending", + "by-id": "pe-14_smt", + "parts": [ + { + "id": "pe-14_fr", + "name": "item", + "title": "PE-14 Additional FedRAMP Requirements and Guidance", + "parts": [ + { + "id": "pe-14_fr_smt.1", + "name": "item", + "props": [ + { + "name": "label", + "value": "(a) Requirement:" + } + ], + "prose": "The service provider measures temperature at server inlets and humidity levels by dew point." + } + ] + } + ] + }, + { + "position": "starting", + "by-id": "pe-14_obj.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pe-14_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pe-14_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "pe-14_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "pe-14.2", + "adds": [ + { + "position": "starting", + "by-id": "pe-14.2_obj-1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pe-14.2_obj-2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pe-14.2_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "pe-15", + "adds": [ + { + "position": "starting", + "by-id": "pe-15_obj-1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pe-15_obj-2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pe-15_obj-3", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pe-15_obj-4", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pe-15_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "pe-15.1", + "adds": [ + { + "position": "starting", + "by-id": "pe-15.1_obj-1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pe-15.1_obj-2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pe-15.1_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "pe-16", + "adds": [ + { + "position": "starting", + "by-id": "pe-16_obj.a-1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pe-16_obj.a-2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pe-16_obj.a-3", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pe-16_obj.a-4", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pe-16_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pe-16_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "pe-16_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "pe-17", + "adds": [ + { + "position": "starting", + "by-id": "pe-17_obj.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pe-17_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pe-17_obj.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pe-17_obj.d", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pe-17_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "pe-17_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "pe-17_smt.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "pe-17_smt.d", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "pe-18", + "adds": [ + { + "position": "starting", + "by-id": "pe-18_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pe-18_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "pe-2", + "adds": [ + { + "position": "starting", + "by-id": "pe-2_obj.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pe-2_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pe-2_obj.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pe-2_obj.d", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pe-2_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "pe-2_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "pe-2_smt.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "pe-2_smt.d", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "pe-3", + "adds": [ + { + "position": "starting", + "by-id": "pe-3_obj.a.1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pe-3_obj.a.2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pe-3_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pe-3_obj.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pe-3_obj.d-1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pe-3_obj.d-2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pe-3_obj.e", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pe-3_obj.f", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pe-3_obj.g-1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pe-3_obj.g-2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pe-3_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "pe-3_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "pe-3_smt.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "pe-3_smt.d", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "pe-3_smt.e", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "pe-3_smt.f", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "pe-3_smt.g", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "pe-3", + "props": [ + { + "name": "CORE", + "ns": "https://fedramp.gov/ns/oscal", + "value": "true" + } + ] + } + ] + }, + { + "control-id": "pe-3.1", + "adds": [ + { + "position": "starting", + "by-id": "pe-3.1_obj-1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pe-3.1_obj.2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pe-3.1_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "pe-4", + "adds": [ + { + "position": "starting", + "by-id": "pe-4_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pe-4_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "pe-5", + "adds": [ + { + "position": "starting", + "by-id": "pe-5_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pe-5_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "pe-6", + "adds": [ + { + "position": "starting", + "by-id": "pe-6_obj.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pe-6_obj.b-1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pe-6_obj.b-2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pe-6_obj.c-1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pe-6_obj.c-2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pe-6_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "pe-6_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "pe-6_smt.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "pe-6.1", + "adds": [ + { + "position": "starting", + "by-id": "pe-6.1_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pe-6.1_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "pe-6.4", + "adds": [ + { + "position": "starting", + "by-id": "pe-6.4_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pe-6.4_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "pe-8", + "adds": [ + { + "position": "starting", + "by-id": "pe-8_obj.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pe-8_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pe-8_obj.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pe-8_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "pe-8_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "pe-8_smt.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "pe-8.1", + "adds": [ + { + "position": "starting", + "by-id": "pe-8.1_obj-1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pe-8.1_obj-2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pe-8.1_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "pe-9", + "adds": [ + { + "position": "starting", + "by-id": "pe-9_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pe-9_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "pl-1", + "adds": [ + { + "position": "starting", + "by-id": "pl-1_obj.a-1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pl-1_obj.a-2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pl-1_obj.a-3", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pl-1_obj.a-4", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pl-1_obj.a.1.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pl-1_obj.a.1.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pl-1_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pl-1_obj.c.1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pl-1_obj.c.2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pl-1_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point.", + "remarks": "This response must address all control sub-statement requirements." + } + ] + }, + { + "position": "starting", + "by-id": "pl-1_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "pl-1_smt.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point.", + "remarks": "This response must address all control sub-statement requirements." + } + ] + } + ] + }, + { + "control-id": "pl-11", + "adds": [ + { + "position": "starting", + "by-id": "pl-11_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pl-11_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "pl-2", + "adds": [ + { + "position": "starting", + "by-id": "pl-2_obj.a.1-1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pl-2_obj.a.1-1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pl-2_obj.a.1-1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pl-2_obj.a.1-2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pl-2_obj.a.1-2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pl-2_obj.a.1-2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pl-2_obj.a.4-1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pl-2_obj.a.4-2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pl-2_obj.a.5", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pl-2_obj.a.6", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pl-2_obj.a.7", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pl-2_obj.a.8", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pl-2_obj.a.9", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pl-2_obj.a.10-1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pl-2_obj.a.10-2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pl-2_obj.a.11", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pl-2_obj.a.12-1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pl-2_obj.a.12-2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pl-2_obj.a.13-1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pl-2_obj.a.13-2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pl-2_obj.a.14-1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pl-2_obj.a.14-2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pl-2_obj.a.15-1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pl-2_obj.a.15-2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pl-2_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pl-2_obj.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pl-2_obj.d", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pl-2_obj.e", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pl-2_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "pl-2_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "pl-2_smt.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "pl-2_smt.d", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "pl-2_smt.e", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "pl-4", + "adds": [ + { + "position": "starting", + "by-id": "pl-4_obj.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pl-4_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pl-4_obj.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pl-4_obj.d", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pl-4_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "pl-4_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "pl-4_smt.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "pl-4_smt.d", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "pl-4.1", + "adds": [ + { + "position": "starting", + "by-id": "pl-4.1_obj.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pl-4.1_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pl-4.1_obj.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pl-4.1_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "pl-4.1_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "pl-4.1_smt.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "pl-8", + "adds": [ + { + "position": "ending", + "by-id": "pl-8_smt", + "parts": [ + { + "id": "pl-8_fr", + "name": "item", + "title": "PL-8 Additional FedRAMP Requirements and Guidance", + "parts": [ + { + "id": "pl-8_fr_gdn.1", + "name": "guidance", + "props": [ + { + "name": "label", + "value": "(b) Guidance:" + } + ], + "prose": "Significant change is defined in NIST Special Publication 800-37 Revision 2, Appendix F." + } + ] + } + ] + }, + { + "position": "starting", + "by-id": "pl-8_obj.a.1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pl-8_obj.a.2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pl-8_obj.a.3", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pl-8_obj.a.4", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pl-8_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pl-8_obj.c-1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pl-8_obj.c-2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pl-8_obj.c-3", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pl-8_obj.c-4", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pl-8_obj.c-5", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pl-8_obj.c-6", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pl-8_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "pl-8_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "pl-8_smt.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "pl-10", + "adds": [ + { + "position": "ending", + "by-id": "pl-10_smt", + "parts": [ + { + "id": "pl-10_fr", + "name": "item", + "title": "PL-10 Additional FedRAMP Requirements and Guidance", + "parts": [ + { + "id": "pl-10_fr_smt.1", + "name": "item", + "props": [ + { + "name": "label", + "value": "Requirement:" + } + ], + "prose": "Select the appropriate FedRAMP Baseline" + } + ] + } + ] + }, + { + "position": "starting", + "by-id": "pl-10_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "pl-10_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "ps-1", + "adds": [ + { + "position": "starting", + "by-id": "ps-1_obj.a-1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ps-1_obj.a-2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ps-1_obj.a-3", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ps-1_obj.a-4", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ps-1_obj.a.1.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ps-1_obj.a.1.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ps-1_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ps-1_obj.c.1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ps-1_obj.c.2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ps-1_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point.", + "remarks": "This response must address all control sub-statement requirements." + } + ] + }, + { + "position": "starting", + "by-id": "ps-1_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ps-1_smt.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point.", + "remarks": "This response must address all control sub-statement requirements." + } + ] + } + ] + }, + { + "control-id": "ps-2", + "adds": [ + { + "position": "starting", + "by-id": "ps-2_obj.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ps-2_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ps-2_obj.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ps-2_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ps-2_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ps-2_smt.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "ps-3", + "adds": [ + { + "position": "starting", + "by-id": "ps-3_obj.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ps-3_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ps-3_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ps-3_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "ps-3.3", + "adds": [ + { + "position": "starting", + "by-id": "ps-3.3_obj.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ps-3.3_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ps-3.3_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ps-3.3_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "ps-4", + "adds": [ + { + "position": "starting", + "by-id": "ps-4_obj.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ps-4_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ps-4_obj.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ps-4_obj.d", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ps-4_obj.e", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ps-4_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ps-4_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ps-4_smt.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ps-4_smt.d", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ps-4_smt.e", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "ps-4.2", + "adds": [ + { + "position": "starting", + "by-id": "ps-4.2_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ps-4.2_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "ps-5", + "adds": [ + { + "position": "starting", + "by-id": "ps-5_obj.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ps-5_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ps-5_obj.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ps-5_obj.d", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ps-5_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ps-5_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ps-5_smt.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ps-5_smt.d", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "ps-6", + "adds": [ + { + "position": "starting", + "by-id": "ps-6_obj.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ps-6_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ps-6_obj.c.1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ps-6_obj.c.2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ps-6_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ps-6_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ps-6_smt.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "ps-7", + "adds": [ + { + "position": "starting", + "by-id": "ps-7_obj.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ps-7_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ps-7_obj.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ps-7_obj.d", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ps-7_obj.e", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ps-7_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ps-7_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ps-7_smt.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ps-7_smt.d", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ps-7_smt.e", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "ps-8", + "adds": [ + { + "position": "starting", + "by-id": "ps-8_obj.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ps-8_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ps-8_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ps-8_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "ps-9", + "adds": [ + { + "position": "starting", + "by-id": "ps-9_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ps-9_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "ra-1", + "adds": [ + { + "position": "starting", + "by-id": "ra-1_obj.a-1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ra-1_obj.a-2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ra-1_obj.a-3", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ra-1_obj.a-4", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ra-1_obj.a.1.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ra-1_obj.a.1.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ra-1_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ra-1_obj.c.1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ra-1_obj.c.2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ra-1_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point.", + "remarks": "This response must address all control sub-statement requirements." + } + ] + }, + { + "position": "starting", + "by-id": "ra-1_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ra-1_smt.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point.", + "remarks": "This response must address all control sub-statement requirements." + } + ] + } + ] + }, + { + "control-id": "ra-2", + "adds": [ + { + "position": "starting", + "by-id": "ra-2_obj.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ra-2_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ra-2_obj.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ra-2_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ra-2_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ra-2_smt.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "ra-3", + "adds": [ + { + "position": "ending", + "by-id": "ra-3_smt", + "parts": [ + { + "id": "ra-3_fr", + "name": "item", + "title": "RA-3 Additional FedRAMP Requirements and Guidance", + "parts": [ + { + "id": "ra-3_fr_gdn.1", + "name": "guidance", + "props": [ + { + "name": "label", + "value": "Guidance:" + } + ], + "prose": "Significant change is defined in NIST Special Publication 800-37 Revision 2, Appendix F." + }, + { + "id": "ra-3_fr_smt.1", + "name": "item", + "props": [ + { + "name": "label", + "value": "(e) Requirement:" + } + ], + "prose": "Include all Authorizing Officials; for JAB authorizations to include FedRAMP." + } + ] + } + ] + }, + { + "position": "starting", + "by-id": "ra-3_obj.a.1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ra-3_obj.a.2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ra-3_obj.a.3", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ra-3_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ra-3_obj.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ra-3_obj.d", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ra-3_obj.e", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ra-3_obj.f", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ra-3_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ra-3_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ra-3_smt.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ra-3_smt.d", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ra-3_smt.e", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ra-3_smt.f", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "ra-3.1", + "adds": [ + { + "position": "starting", + "by-id": "ra-3.1_obj.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ra-3.1_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ra-3.1_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ra-3.1_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "ra-5", + "adds": [ + { + "position": "ending", + "by-id": "ra-5_smt", + "parts": [ + { + "id": "ra-5_fr", + "name": "item", + "title": "RA-5 Additional FedRAMP Requirements and Guidance", + "parts": [ + { + "id": "ra-5_fr_gdn.1", + "name": "guidance", + "props": [ + { + "name": "label", + "value": "Guidance:" + } + ], + "prose": "See the FedRAMP Documents page> Vulnerability Scanning Requirements https://www.FedRAMP.gov/documents/" + }, + { + "id": "ra-5_fr_smt.1", + "name": "item", + "props": [ + { + "name": "label", + "value": "(a) Requirement:" + } + ], + "prose": "an accredited independent assessor scans operating systems/infrastructure, web applications, and databases once annually." + }, + { + "id": "ra-5_fr_smt.2", + "name": "item", + "props": [ + { + "name": "label", + "value": "(d) Requirement:" + } + ], + "prose": "If a vulnerability is listed among the CISA Known Exploited Vulnerability (KEV) Catalog (https://www.cisa.gov/known-exploited-vulnerabilities-catalog) the KEV remediation date supersedes the FedRAMP parameter requirement." + }, + { + "id": "ra-5_fr_smt.3", + "name": "item", + "props": [ + { + "name": "label", + "value": "(e) Requirement:" + } + ], + "prose": "to include all Authorizing Officials; for JAB authorizations to include FedRAMP" + }, + { + "id": "ra-5_fr_gdn.2", + "name": "guidance", + "props": [ + { + "name": "label", + "value": "Guidance:" + } + ], + "prose": "Informational findings from a scanner are detailed as a returned result that holds no vulnerability risk or severity and for FedRAMP does not require an entry onto the POA&M or entry onto the RET during any assessment phase.\n\nWarning findings, on the other hand, are given a risk rating (low, moderate, high or critical) by the scanning solution and should be treated like any other finding with a risk or severity rating for tracking purposes onto either the POA&M or RET depending on when the findings originated (during assessments or during monthly continuous monitoring). If a warning is received during scanning, but further validation turns up no actual issue then this item should be categorized as a false positive. If this situation presents itself during an assessment phase (initial assessment, annual assessment or any SCR), follow guidance on how to report false positives in the Security Assessment Report (SAR). If this situation happens during monthly continuous monitoring, a deviation request will need to be submitted per the FedRAMP Vulnerability Deviation Request Form.\n\nWarnings are commonly associated with scanning solutions that also perform compliance scans, and if the scanner reports a \\\"warning\\\" as part of the compliance scanning of a CSO, follow guidance surrounding the tracking of compliance findings during either the assessment phases (initial assessment, annual assessment or any SCR) or monthly continuous monitoring as it applies. Guidance on compliance scan findings can be found by searching on \\\"Tracking of Compliance Scans\\\" in FAQs." + } + ] + } + ] + }, + { + "position": "starting", + "by-id": "ra-5_obj.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ra-5_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ra-5_obj.b.1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ra-5_obj.b.2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ra-5_obj.b.3", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ra-5_obj.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ra-5_obj.d", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ra-5_obj.e", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ra-5_obj.f", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ra-5_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ra-5_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ra-5_smt.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ra-5_smt.d", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ra-5_smt.e", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ra-5_smt.f", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ra-5", + "props": [ + { + "name": "CORE", + "ns": "https://fedramp.gov/ns/oscal", + "value": "true" + } + ] + } + ] + }, + { + "control-id": "ra-5.11", + "adds": [ + { + "position": "starting", + "by-id": "ra-5.11_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ra-5.11_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "ra-5.2", + "adds": [ + { + "position": "starting", + "by-id": "ra-5.2_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ra-5.2_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ra-5.2", + "props": [ + { + "name": "CORE", + "ns": "https://fedramp.gov/ns/oscal", + "value": "true" + } + ] + } + ] + }, + { + "control-id": "ra-5.3", + "adds": [ + { + "position": "starting", + "by-id": "ra-5.3_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ra-5.3_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "ra-5.3", + "props": [ + { + "name": "CORE", + "ns": "https://fedramp.gov/ns/oscal", + "value": "true" + } + ] + } + ] + }, + { + "control-id": "ra-5.4", + "adds": [ + { + "position": "starting", + "by-id": "ra-5.4_obj-1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ra-5.4_obj-2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ra-5.4_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "ra-5.5", + "adds": [ + { + "position": "starting", + "by-id": "ra-5.5_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ra-5.5_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "ra-5.8", + "adds": [ + { + "position": "ending", + "by-id": "ra-5.8_smt", + "parts": [ + { + "id": "ra-5.8_fr", + "name": "item", + "title": "RA-5(8) Additional FedRAMP Requirement", + "parts": [ + { + "id": "ra-5.8_fr_smt.1", + "name": "item", + "props": [ + { + "name": "label", + "value": "Requirement:" + } + ], + "prose": "This enhancement is required for all high (or critical) vulnerability scan findings." + } + ] + } + ] + }, + { + "position": "starting", + "by-id": "ra-5.8_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ra-5.8_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "ra-7", + "adds": [ + { + "position": "starting", + "by-id": "ra-7_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ra-7_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "ra-9", + "adds": [ + { + "position": "starting", + "by-id": "ra-9_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "ra-9_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "sa-1", + "adds": [ + { + "position": "starting", + "by-id": "sa-1_obj.a-1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sa-1_obj.a-2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sa-1_obj.a-3", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sa-1_obj.a-4", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sa-1_obj.a.1.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sa-1_obj.a.1.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sa-1_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sa-1_obj.c.1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sa-1_obj.c.2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sa-1_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point.", + "remarks": "This response must address all control sub-statement requirements." + } + ] + }, + { + "position": "starting", + "by-id": "sa-1_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "sa-1_smt.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point.", + "remarks": "This response must address all control sub-statement requirements." + } + ] + } + ] + }, + { + "control-id": "sa-11", + "adds": [ + { + "position": "starting", + "by-id": "sa-11_obj.a-1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sa-11_obj.a-2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sa-11_obj.a-3", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sa-11_obj.a-4", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sa-11_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sa-11_obj.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sa-11_obj.d", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sa-11_obj.e", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sa-11_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "sa-11_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "sa-11_smt.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "sa-11_smt.d", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "sa-11_smt.e", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "sa-11.2", + "adds": [ + { + "position": "starting", + "by-id": "sa-11.2_obj.a-1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sa-11.2_obj.a-2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sa-11.2_obj.a-3", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sa-11.2_obj.a-4", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sa-11.2_obj.b-1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sa-11.2_obj.b-2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sa-11.2_obj.b-3", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sa-11.2_obj.b-4", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sa-11.2_obj.c-1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sa-11.2_obj.c-2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sa-11.2_obj.d-1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sa-11.2_obj.d-2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sa-11.2_obj.d-3", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sa-11.2_obj.d-4", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sa-11.2_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "sa-11.2_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "sa-11.2_smt.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "sa-11.2_smt.d", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "sa-15", + "adds": [ + { + "position": "starting", + "by-id": "sa-15_obj.a.1-1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sa-15_obj.a.1-2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sa-15_obj.a.2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sa-15_obj.a.3", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sa-15_obj.a.4", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sa-15_obj.b-1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sa-15_obj.b-2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sa-15_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "sa-15_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "sa-15.3", + "adds": [ + { + "position": "starting", + "by-id": "sa-15.3_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sa-15.3_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "sa-15.3_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "sa-16", + "adds": [ + { + "position": "starting", + "by-id": "sa-16_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sa-16_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "sa-17", + "adds": [ + { + "position": "starting", + "by-id": "sa-17_obj.a-1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sa-17_obj.a-2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sa-17_obj.b-1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sa-17_obj.b-2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sa-17_obj.c-1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sa-17_obj.c-2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sa-17_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "sa-17_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "sa-17_smt.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "sa-2", + "adds": [ + { + "position": "starting", + "by-id": "sa-2_obj.a-1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sa-2_obj.a-2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sa-2_obj.b-1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sa-2_obj.b-2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sa-2_obj.c-1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sa-2_obj.c-2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sa-2_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "sa-2_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "sa-2_smt.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "sa-21", + "adds": [ + { + "position": "starting", + "by-id": "sa-21_obj.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sa-21_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sa-21_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "sa-21_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "sa-22", + "adds": [ + { + "position": "starting", + "by-id": "sa-22_obj.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sa-22_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sa-22_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "sa-22_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "sa-3", + "adds": [ + { + "position": "starting", + "by-id": "sa-3_obj.a-1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sa-3_obj.a-2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sa-3_obj.b-1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sa-3_obj.b-2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sa-3_obj.c-1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sa-3_obj.c-2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sa-3_obj.d-1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sa-3_obj.d-2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sa-3_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "sa-3_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "sa-3_smt.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "sa-3_smt.d", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "sa-4", + "adds": [ + { + "position": "ending", + "by-id": "sa-4_smt", + "parts": [ + { + "id": "sa-4_fr", + "name": "item", + "title": "SA-4 Additional FedRAMP Requirements and Guidance", + "parts": [ + { + "id": "sa-4_fr_smt.1", + "name": "item", + "props": [ + { + "name": "label", + "value": "Requirement:" + } + ], + "prose": "The service provider must comply with Federal Acquisition Regulation (FAR) Subpart 7.103, and Section 889 of the John S. McCain National Defense Authorization Act (NDAA) for Fiscal Year 2019 (Pub. L. 115-232), and FAR Subpart 4.21, which implements Section 889 (as well as any added updates related to FISMA to address security concerns in the system acquisitions process)." + }, + { + "id": "sa-4_fr_gdn.1", + "name": "guidance", + "props": [ + { + "name": "label", + "value": "Guidance:" + } + ], + "prose": "The use of Common Criteria (ISO/IEC 15408) evaluated products is strongly preferred.\n\nSee https://www.niap-ccevs.org/Product/index.cfm or https://www.commoncriteriaportal.org/products/." + } + ] + } + ] + }, + { + "position": "starting", + "by-id": "sa-4_obj.a-1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sa-4_obj.a-1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sa-4_obj.a-1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sa-4_obj.a-2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sa-4_obj.a-2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sa-4_obj.a-2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sa-4_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sa-4_obj.e", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sa-4_obj.f", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sa-4_obj.g", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sa-4_obj.h", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sa-4_obj.i", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sa-4_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "sa-4_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "sa-4_smt.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "sa-4_smt.d", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "sa-4_smt.e", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "sa-4_smt.f", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "sa-4_smt.g", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "sa-4_smt.h", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "sa-4_smt.i", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "sa-10", + "adds": [ + { + "position": "ending", + "by-id": "sa-10_smt", + "parts": [ + { + "id": "sa-10_fr", + "name": "item", + "title": "SA-10 Additional FedRAMP Requirements and Guidance", + "parts": [ + { + "id": "sa-10_fr_smt.1", + "name": "item", + "props": [ + { + "name": "label", + "value": "(e) Requirement:" + } + ], + "prose": "track security flaws and flaw resolution within the system, component, or service and report findings to organization-defined personnel, to include FedRAMP." + } + ] + } + ] + }, + { + "position": "starting", + "by-id": "sa-10_obj.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sa-10_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sa-10_obj.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sa-10_obj.d", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sa-10_obj.e", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sa-10_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "sa-10_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "sa-10_smt.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "sa-10_smt.d", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "sa-10_smt.e", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "sa-11.1", + "adds": [ + { + "position": "ending", + "by-id": "sa-11.1_smt", + "parts": [ + { + "id": "sa-11.1_fr", + "name": "item", + "title": "SA-11(1) Additional FedRAMP Requirements", + "parts": [ + { + "id": "sa-11.1_fr_smt.1", + "name": "item", + "props": [ + { + "name": "label", + "value": "Requirement:" + } + ], + "prose": "The service provider must document its methodology for reviewing newly developed code for the Service in its Continuous Monitoring Plan.\n\nIf Static code analysis cannot be performed (for example, when the source code is not available), then dynamic code analysis must be performed (see SA-11 (8))" + } + ] + } + ] + }, + { + "position": "starting", + "by-id": "sa-11.1_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sa-11.1_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "sa-11.1", + "props": [ + { + "name": "CORE", + "ns": "https://fedramp.gov/ns/oscal", + "value": "true" + } + ] + } + ] + }, + { + "control-id": "sa-4.1", + "adds": [ + { + "position": "starting", + "by-id": "sa-4.1_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sa-4.1_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "sa-4.10", + "adds": [ + { + "position": "starting", + "by-id": "sa-4.10_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sa-4.10_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "sa-4.2", + "adds": [ + { + "position": "starting", + "by-id": "sa-4.2_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sa-4.2_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "sa-4.5", + "adds": [ + { + "position": "starting", + "by-id": "sa-4.5_obj.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sa-4.5_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sa-4.5_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "sa-4.5_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "sa-4.9", + "adds": [ + { + "position": "starting", + "by-id": "sa-4.9_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sa-4.9_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "sa-5", + "adds": [ + { + "position": "starting", + "by-id": "sa-5_obj.a.1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sa-5_obj.a.2-1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sa-5_obj.a.2-2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sa-5_obj.a.2-3", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sa-5_obj.a.2-4", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sa-5_obj.a.3", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sa-5_obj.b.1-1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sa-5_obj.b.1-2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sa-5_obj.b.1-3", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sa-5_obj.b.1-4", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sa-5_obj.b.2-1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sa-5_obj.b.2-2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sa-5_obj.b.3-1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sa-5_obj.b.3-2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sa-5_obj.c-1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sa-5_obj.c-2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sa-5_obj.d", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sa-5_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "sa-5_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "sa-5_smt.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "sa-5_smt.d", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "sa-8", + "adds": [ + { + "position": "starting", + "by-id": "sa-8_obj-1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sa-8_obj-2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sa-8_obj-3", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sa-8_obj-4", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sa-8_obj-5", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sa-8_obj-6", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sa-8_obj-7", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sa-8_obj-8", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sa-8_obj-9", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sa-8_obj-10", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sa-8_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "sa-9", + "adds": [ + { + "position": "starting", + "by-id": "sa-9_obj.a-1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sa-9_obj.a-2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sa-9_obj.a-3", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sa-9_obj.b-1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sa-9_obj.b-2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sa-9_obj.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sa-9_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "sa-9_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "sa-9_smt.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "sa-9", + "props": [ + { + "name": "CORE", + "ns": "https://fedramp.gov/ns/oscal", + "value": "true" + } + ] + } + ] + }, + { + "control-id": "sa-9.1", + "adds": [ + { + "position": "starting", + "by-id": "sa-9.1_obj.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sa-9.1_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sa-9.1_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "sa-9.1_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "sa-9.2", + "adds": [ + { + "position": "starting", + "by-id": "sa-9.2_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sa-9.2_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "sa-9.5", + "adds": [ + { + "position": "starting", + "by-id": "sa-9.5_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sa-9.5_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "sc-1", + "adds": [ + { + "position": "starting", + "by-id": "sc-1_obj.a-1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sc-1_obj.a-2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sc-1_obj.a-3", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sc-1_obj.a-4", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sc-1_obj.a.1.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sc-1_obj.a.1.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sc-1_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sc-1_obj.c.1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sc-1_obj.c.2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sc-1_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point.", + "remarks": "This response must address all control sub-statement requirements." + } + ] + }, + { + "position": "starting", + "by-id": "sc-1_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "sc-1_smt.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point.", + "remarks": "This response must address all control sub-statement requirements." + } + ] + } + ] + }, + { + "control-id": "sc-10", + "adds": [ + { + "position": "starting", + "by-id": "sc-10_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sc-10_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "sc-12.1", + "adds": [ + { + "position": "starting", + "by-id": "sc-12.1_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sc-12.1_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "sc-17", + "adds": [ + { + "position": "starting", + "by-id": "sc-17_obj.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sc-17_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sc-17_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "sc-17_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "sc-18", + "adds": [ + { + "position": "starting", + "by-id": "sc-18_obj.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sc-18_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sc-18_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "sc-18_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "sc-2", + "adds": [ + { + "position": "starting", + "by-id": "sc-2_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sc-2_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "sc-22", + "adds": [ + { + "position": "starting", + "by-id": "sc-22_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sc-22_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "sc-23", + "adds": [ + { + "position": "starting", + "by-id": "sc-23_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sc-23_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "sc-24", + "adds": [ + { + "position": "starting", + "by-id": "sc-24_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sc-24_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "sc-3", + "adds": [ + { + "position": "starting", + "by-id": "sc-3_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sc-3_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "sc-39", + "adds": [ + { + "position": "starting", + "by-id": "sc-39_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sc-39_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "sc-4", + "adds": [ + { + "position": "starting", + "by-id": "sc-4_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sc-4_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "sc-45", + "adds": [ + { + "position": "starting", + "by-id": "sc-45_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sc-45_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "sc-5", + "adds": [ + { + "position": "starting", + "by-id": "sc-5_obj.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sc-5_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sc-5_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "sc-5_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "sc-7", + "adds": [ + { + "position": "ending", + "by-id": "sc-7_smt", + "parts": [ + { + "id": "sc-7_fr", + "name": "item", + "title": "SC-7 Additional FedRAMP Requirements and Guidance", + "parts": [ + { + "id": "sc-7_fr_gdn.1", + "name": "guidance", + "props": [ + { + "name": "label", + "value": "(b) Guidance:" + } + ], + "prose": "SC-7 (b) should be met by subnet isolation. A subnetwork (subnet) is a physically or logically segmented section of a larger network defined at TCP/IP Layer 3, to both minimize traffic and, important for a FedRAMP Authorization, add a crucial layer of network isolation. Subnets are distinct from VLANs (Layer 2), security groups, and VPCs and are specifically required to satisfy SC-7 part b and other controls. See the FedRAMP Subnets White Paper (https://www.fedramp.gov/assets/resources/documents/FedRAMP_subnets_white_paper.pdf) for additional information." + } + ] + } + ] + }, + { + "position": "starting", + "by-id": "sc-7_obj.a-1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sc-7_obj.a-2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sc-7_obj.a-3", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sc-7_obj.a-4", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sc-7_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sc-7_obj.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sc-7_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "sc-7_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "sc-7_smt.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "sc-7", + "props": [ + { + "name": "CORE", + "ns": "https://fedramp.gov/ns/oscal", + "value": "true" + } + ] + } + ] + }, + { + "control-id": "sc-7.10", + "adds": [ + { + "position": "starting", + "by-id": "sc-7.10_obj.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sc-7.10_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sc-7.10_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "sc-7.10_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "sc-7.12", + "adds": [ + { + "position": "starting", + "by-id": "sc-7.12_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sc-7.12_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "sc-7.12", + "props": [ + { + "name": "CORE", + "ns": "https://fedramp.gov/ns/oscal", + "value": "true" + } + ] + } + ] + }, + { + "control-id": "sc-7.18", + "adds": [ + { + "position": "starting", + "by-id": "sc-7.18_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sc-7.18_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "sc-7.18", + "props": [ + { + "name": "CORE", + "ns": "https://fedramp.gov/ns/oscal", + "value": "true" + } + ] + } + ] + }, + { + "control-id": "sc-7.20", + "adds": [ + { + "position": "starting", + "by-id": "sc-7.20_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sc-7.20_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "sc-7.20", + "props": [ + { + "name": "CORE", + "ns": "https://fedramp.gov/ns/oscal", + "value": "true" + } + ] + } + ] + }, + { + "control-id": "sc-7.21", + "adds": [ + { + "position": "starting", + "by-id": "sc-7.21_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sc-7.21_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "sc-7.21", + "props": [ + { + "name": "CORE", + "ns": "https://fedramp.gov/ns/oscal", + "value": "true" + } + ] + } + ] + }, + { + "control-id": "sc-7.3", + "adds": [ + { + "position": "starting", + "by-id": "sc-7.3_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sc-7.3_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "sc-7.3", + "props": [ + { + "name": "CORE", + "ns": "https://fedramp.gov/ns/oscal", + "value": "true" + } + ] + } + ] + }, + { + "control-id": "sc-7.4", + "adds": [ + { + "position": "starting", + "by-id": "sc-7.4_obj.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sc-7.4_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sc-7.4_obj.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sc-7.4_obj.d", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sc-7.4_obj.e", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sc-7.4_obj.f", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sc-7.4_obj.g", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sc-7.4_obj.h", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sc-7.4_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "sc-7.4_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "sc-7.4_smt.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "sc-7.4_smt.d", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "sc-7.4_smt.e", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "sc-7.4_smt.f", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "sc-7.4_smt.g", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "sc-7.4_smt.h", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "sc-7.4", + "props": [ + { + "name": "CORE", + "ns": "https://fedramp.gov/ns/oscal", + "value": "true" + } + ] + } + ] + }, + { + "control-id": "sc-7.5", + "adds": [ + { + "position": "ending", + "by-id": "sc-7.5_smt", + "parts": [ + { + "id": "sc-7.5_fr", + "name": "item", + "title": "SC-7 (5) Additional FedRAMP Requirements and Guidance", + "parts": [ + { + "id": "sc-7.5_fr_gdn.1", + "name": "guidance", + "props": [ + { + "name": "label", + "value": "Guidance:" + } + ], + "prose": "For JAB Authorization, CSPs shall include details of this control in their Architecture Briefing" + } + ] + } + ] + }, + { + "position": "starting", + "by-id": "sc-7.5_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sc-7.5_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "sc-7.5", + "props": [ + { + "name": "CORE", + "ns": "https://fedramp.gov/ns/oscal", + "value": "true" + } + ] + } + ] + }, + { + "control-id": "sc-7.7", + "adds": [ + { + "position": "starting", + "by-id": "sc-7.7_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sc-7.7_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "sc-7.7", + "props": [ + { + "name": "CORE", + "ns": "https://fedramp.gov/ns/oscal", + "value": "true" + } + ] + } + ] + }, + { + "control-id": "sc-7.8", + "adds": [ + { + "position": "starting", + "by-id": "sc-7.8_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sc-7.8_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "sc-7.8", + "props": [ + { + "name": "CORE", + "ns": "https://fedramp.gov/ns/oscal", + "value": "true" + } + ] + } + ] + }, + { + "control-id": "sc-8", + "adds": [ + { + "position": "ending", + "by-id": "sc-8_smt", + "parts": [ + { + "id": "sc-8_fr", + "name": "item", + "title": "SC-8 Additional FedRAMP Requirements and Guidance", + "parts": [ + { + "id": "sc-8_fr_gdn.1", + "name": "guidance", + "props": [ + { + "name": "label", + "value": "Guidance:" + } + ], + "prose": "For each instance of data in transit, confidentiality AND integrity should be through cryptography as specified in SC-8 (1), physical means as specified in SC-8 (5), or in combination.\n\n\n\nFor clarity, this control applies to all data in transit. Examples include the following data flows:\n\n* Crossing the system boundary\n* Between compute instances - including containers\n* From a compute instance to storage\n* Replication between availability zones\n* Transmission of backups to storage\n* From a load balancer to a compute instance\n* Flows from management tools required for their work - e.g. log collection, scanning, etc.\n\n\n\n\nThe following applies only when choosing SC-8 (5) in lieu of SC-8 (1).\n\nFedRAMP-Defined Assignment / Selection Parameters\n\nSC-8 (5)-1 [a hardened or alarmed carrier Protective Distribution System (PDS) when outside of Controlled Access Area (CAA)]\n\nSC-8 (5)-2 [prevent unauthorized disclosure of information AND detect changes to information]" + }, + { + "id": "sc-8_fr_gdn.2", + "name": "guidance", + "props": [ + { + "name": "label", + "value": "Guidance:" + } + ], + "prose": "SC-8 (5) applies when physical protection has been selected as the method to protect confidentiality and integrity. For physical protection, data in transit must be in either a Controlled Access Area (CAA), or a Hardened or alarmed PDS.\n\n\n\nHardened or alarmed PDS: Shall be as defined in SECTION X - CATEGORY 2 PDS INSTALLATION GUIDANCE of CNSSI No.7003, titled PROTECTED DISTRIBUTION SYSTEMS (PDS). Per the CNSSI No. 7003 Section VIII, PDS must originate and terminate in a Controlled Access Area (CAA).\n\n\n\nControlled Access Area (CAA): Data will be considered physically protected, and in a CAA if it meets Section 2.3 of the DHS's Recommended Practice: Improving Industrial Control System Cybersecurity with Defense-in-Depth Strategies. CSPs can meet Section 2.3 of the DHS' recommended practice by satisfactory implementation of the following controls PE-2 (1), PE-2 (2), PE-2 (3), PE-3 (2), PE-3 (3), PE-6 (2), and PE-6 (3).\n\n\n\nNote: When selecting SC-8 (5), the above SC-8(5), and the above referenced PE controls must be added to the SSP.\n\n\n\nCNSSI No.7003 can be accessed here:\n\nhttps://www.dcsa.mil/Portals/91/documents/ctp/nao/CNSSI_7003_PDS_September_2015.pdf\n\n\n\nDHS Recommended Practice: Improving Industrial Control System Cybersecurity with Defense-in-Depth Strategies can be accessed here:\n\nhttps://us-cert.cisa.gov/sites/default/files/FactSheets/NCCIC%20ICS_FactSheet_Defense_in_Depth_Strategies_S508C.pdf" + } + ] + } + ] + }, + { + "position": "starting", + "by-id": "sc-8_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sc-8_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "sc-8", + "props": [ + { + "name": "CORE", + "ns": "https://fedramp.gov/ns/oscal", + "value": "true" + } + ] + } + ] + }, + { + "control-id": "sc-8.1", + "adds": [ + { + "position": "ending", + "by-id": "sc-8.1_smt", + "parts": [ + { + "id": "sc-8.1_fr", + "name": "item", + "title": "SC-8 (1) Additional FedRAMP Requirements and Guidance", + "parts": [ + { + "id": "sc-8.1_fr_smt.1", + "name": "item", + "props": [ + { + "name": "label", + "value": "Requirement:" + } + ], + "prose": "Please ensure SSP Section 10.3 Cryptographic Modules Implemented for Data At Rest (DAR) and Data In Transit (DIT) is fully populated for reference in this control." + }, + { + "id": "sc-8.1_fr_gdn.1", + "name": "guidance", + "props": [ + { + "name": "label", + "value": "Guidance:" + } + ], + "prose": "See M-22-09, including \\\"Agencies encrypt all DNS requests and HTTP traffic within their environment\\\"\n\nSC-8 (1) applies when encryption has been selected as the method to protect confidentiality and integrity. Otherwise refer to SC-8 (5). SC-8 (1) is strongly encouraged." + }, + { + "id": "sc-8.1_fr_gdn.2", + "name": "guidance", + "props": [ + { + "name": "label", + "value": "Guidance:" + } + ], + "prose": "Note that this enhancement requires the use of cryptography which must be compliant with Federal requirements and utilize FIPS validated or NSA approved cryptography (see SC-13.)" + }, + { + "id": "sc-8.1_fr_gdn.3", + "name": "guidance", + "props": [ + { + "name": "label", + "value": "Guidance:" + } + ], + "prose": "When leveraging encryption from the underlying IaaS/PaaS: While some IaaS/PaaS services provide encryption by default, many require encryption to be configured, and enabled by the customer. The CSP has the responsibility to verify encryption is properly configured." + } + ] + } + ] + }, + { + "position": "starting", + "by-id": "sc-8.1_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sc-8.1_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "sc-12", + "adds": [ + { + "position": "ending", + "by-id": "sc-12_smt", + "parts": [ + { + "id": "sc-12_fr", + "name": "item", + "title": "SC-12 Additional FedRAMP Requirements and Guidance", + "parts": [ + { + "id": "sc-12_fr_gdn.1", + "name": "guidance", + "props": [ + { + "name": "label", + "value": "Guidance:" + } + ], + "prose": "See references in NIST 800-53 documentation." + }, + { + "id": "sc-12_fr_gdn.2", + "name": "guidance", + "props": [ + { + "name": "label", + "value": "Guidance:" + } + ], + "prose": "Must meet applicable Federal Cryptographic Requirements. See References Section of control." + }, + { + "id": "sc-12_fr_gdn.3", + "name": "guidance", + "props": [ + { + "name": "label", + "value": "Guidance:" + } + ], + "prose": "Wildcard certificates may be used internally within the system, but are not permitted for external customer access to the system." + } + ] + } + ] + }, + { + "position": "starting", + "by-id": "sc-12_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sc-12_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "sc-12", + "props": [ + { + "name": "CORE", + "ns": "https://fedramp.gov/ns/oscal", + "value": "true" + } + ] + } + ] + }, + { + "control-id": "sc-13", + "adds": [ + { + "position": "ending", + "by-id": "sc-13_smt", + "parts": [ + { + "id": "sc-13_fr", + "name": "item", + "title": "SC-13 Additional FedRAMP Requirements and Guidance", + "parts": [ + { + "id": "sc-13_fr_gdn.1", + "name": "guidance", + "props": [ + { + "name": "label", + "value": "Guidance:" + } + ], + "prose": "This control applies to all use of cryptography. In addition to encryption, this includes functions such as hashing, random number generation, and key generation. Examples include the following:\n\n* Encryption of data\n* Decryption of data\n* Generation of one time passwords (OTPs) for MFA\n* Protocols such as TLS, SSH, and HTTPS\n\n\n\n\nThe requirement for FIPS 140 validation, as well as timelines for acceptance of FIPS 140-2, and 140-3 can be found at the NIST Cryptographic Module Validation Program (CMVP).\n\nhttps://csrc.nist.gov/projects/cryptographic-module-validation-program" + }, + { + "id": "sc-13_fr_gdn.2", + "name": "guidance", + "props": [ + { + "name": "label", + "value": "Guidance:" + } + ], + "prose": "For NSA-approved cryptography, the National Information Assurance Partnership (NIAP) oversees a national program to evaluate Commercial IT Products for Use in National Security Systems. The NIAP Product Compliant List can be found at the following location:\n\nhttps://www.niap-ccevs.org/Product/index.cfm" + }, + { + "id": "sc-13_fr_gdn.3", + "name": "guidance", + "props": [ + { + "name": "label", + "value": "Guidance:" + } + ], + "prose": "When leveraging encryption from underlying IaaS/PaaS: While some IaaS/PaaS provide encryption by default, many require encryption to be configured, and enabled by the customer. The CSP has the responsibility to verify encryption is properly configured." + }, + { + "id": "sc-13_fr_gdn.4", + "name": "guidance", + "props": [ + { + "name": "label", + "value": "Guidance:" + } + ], + "prose": "Moving to non-FIPS CM or product is acceptable when:\n\n* FIPS validated version has a known vulnerability\n* Feature with vulnerability is in use\n* Non-FIPS version fixes the vulnerability\n* Non-FIPS version is submitted to NIST for FIPS validation\n* POA&M is added to track approval, and deployment when ready\n" + }, + { + "id": "sc-13_fr_gdn.5", + "name": "guidance", + "props": [ + { + "name": "label", + "value": "Guidance:" + } + ], + "prose": "At a minimum, this control applies to cryptography in use for the following controls: AU-9(3), CP-9(8), IA-2(6), IA-5(1), MP-5, SC-8(1), and SC-28(1)." + } + ] + } + ] + }, + { + "position": "starting", + "by-id": "sc-13_obj.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sc-13_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sc-13_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "sc-13_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "sc-13", + "props": [ + { + "name": "CORE", + "ns": "https://fedramp.gov/ns/oscal", + "value": "true" + } + ] + } + ] + }, + { + "control-id": "sc-15", + "adds": [ + { + "position": "ending", + "by-id": "sc-15_smt", + "parts": [ + { + "id": "sc-15_fr", + "name": "item", + "title": "SC-15 Additional FedRAMP Requirements and Guidance", + "parts": [ + { + "id": "sc-15_fr_smt.1", + "name": "item", + "props": [ + { + "name": "label", + "value": "Requirement:" + } + ], + "prose": "The information system provides disablement (instead of physical disconnect) of collaborative computing devices in a manner that supports ease of use." + } + ] + } + ] + }, + { + "position": "starting", + "by-id": "sc-15_obj.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sc-15_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sc-15_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "sc-15_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "sc-20", + "adds": [ + { + "position": "ending", + "by-id": "sc-20_smt", + "parts": [ + { + "id": "sc-20_fr", + "name": "item", + "title": "SC-20 Additional FedRAMP Requirements and Guidance", + "parts": [ + { + "id": "sc-20_fr_smt.1", + "name": "item", + "props": [ + { + "name": "label", + "value": "Requirement:" + } + ], + "prose": "Control Description should include how DNSSEC is implemented on authoritative DNS servers to supply valid responses to external DNSSEC requests." + }, + { + "id": "sc-20_fr_smt.2", + "name": "item", + "props": [ + { + "name": "label", + "value": "Requirement:" + } + ], + "prose": "Authoritative DNS servers must be geolocated in accordance with SA-9 (5)." + }, + { + "id": "sc-20_fr_gdn.1", + "name": "guidance", + "props": [ + { + "name": "label", + "value": "Guidance:" + } + ], + "prose": "SC-20 applies to use of external authoritative DNS to access a CSO from outside the boundary." + }, + { + "id": "sc-20_fr_gdn.2", + "name": "guidance", + "props": [ + { + "name": "label", + "value": "Guidance:" + } + ], + "prose": "External authoritative DNS servers may be located outside an authorized environment. Positioning these servers inside an authorized boundary is encouraged." + }, + { + "id": "sc-20_fr_gdn.3", + "name": "guidance", + "props": [ + { + "name": "label", + "value": "Guidance:" + } + ], + "prose": "CSPs are recommended to self-check DNSSEC configuration through one of many available analyzers such as Sandia National Labs (https://dnsviz.net)" + } + ] + } + ] + }, + { + "position": "starting", + "by-id": "sc-20_obj.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sc-20_obj.b-1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sc-20_obj.b-2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sc-20_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "sc-20_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "sc-21", + "adds": [ + { + "position": "ending", + "by-id": "sc-21_smt", + "parts": [ + { + "id": "sc-21_fr", + "name": "item", + "title": "SC-21 Additional FedRAMP Requirements and Guidance", + "parts": [ + { + "id": "sc-21_fr_smt.1", + "name": "item", + "props": [ + { + "name": "label", + "value": "Requirement:" + } + ], + "prose": "Control description should include how DNSSEC is implemented on recursive DNS servers to make DNSSEC requests when resolving DNS requests from internal components to domains external to the CSO boundary.\n\n* If the reply is signed, and fails DNSSEC, do not use the reply\n* If the reply is unsigned: * CSP chooses the policy to apply \n" + }, + { + "id": "sc-21_fr_smt.2", + "name": "item", + "props": [ + { + "name": "label", + "value": "Requirement:" + } + ], + "prose": "Internal recursive DNS servers must be located inside an authorized environment. It is typically within the boundary, or leveraged from an underlying IaaS/PaaS." + }, + { + "id": "sc-21_fr_gdn.1", + "name": "guidance", + "props": [ + { + "name": "label", + "value": "Guidance:" + } + ], + "prose": "Accepting an unsigned reply is acceptable" + }, + { + "id": "sc-21_fr_gdn.2", + "name": "guidance", + "props": [ + { + "name": "label", + "value": "Guidance:" + } + ], + "prose": "SC-21 applies to use of internal recursive DNS to access a domain outside the boundary by a component inside the boundary.\n\n- DNSSEC resolution to access a component inside the boundary is excluded." + } + ] + } + ] + }, + { + "position": "starting", + "by-id": "sc-21_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sc-21_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "sc-21", + "props": [ + { + "name": "CORE", + "ns": "https://fedramp.gov/ns/oscal", + "value": "true" + } + ] + } + ] + }, + { + "control-id": "sc-28", + "adds": [ + { + "position": "ending", + "by-id": "sc-28_smt", + "parts": [ + { + "id": "sc-28_fr", + "name": "item", + "title": "SC-28 Additional FedRAMP Requirements and Guidance", + "parts": [ + { + "id": "sc-28_fr_gdn.1", + "name": "guidance", + "props": [ + { + "name": "label", + "value": "Guidance:" + } + ], + "prose": "The organization supports the capability to use cryptographic mechanisms to protect information at rest." + }, + { + "id": "sc-28_fr_gdn.2", + "name": "guidance", + "props": [ + { + "name": "label", + "value": "Guidance:" + } + ], + "prose": "When leveraging encryption from underlying IaaS/PaaS: While some IaaS/PaaS services provide encryption by default, many require encryption to be configured, and enabled by the customer. The CSP has the responsibility to verify encryption is properly configured." + }, + { + "id": "sc-28_fr_gdn.3", + "name": "guidance", + "props": [ + { + "name": "label", + "value": "Guidance:" + } + ], + "prose": "Note that this enhancement requires the use of cryptography in accordance with SC-13." + } + ] + } + ] + }, + { + "position": "starting", + "by-id": "sc-28_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sc-28_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "sc-28", + "props": [ + { + "name": "CORE", + "ns": "https://fedramp.gov/ns/oscal", + "value": "true" + } + ] + } + ] + }, + { + "control-id": "sc-28.1", + "adds": [ + { + "position": "ending", + "by-id": "sc-28.1_smt", + "parts": [ + { + "id": "sc-28.1_fr", + "name": "item", + "title": "SC-28 (1) Additional FedRAMP Requirements and Guidance", + "parts": [ + { + "id": "sc-28.1_fr_gdn.1", + "name": "guidance", + "props": [ + { + "name": "label", + "value": "Guidance:" + } + ], + "prose": "Organizations should select a mode of protection that is targeted towards the relevant threat scenarios.\n\nExamples:\n\nA. Organizations may apply full disk encryption (FDE) to a mobile device where the primary threat is loss of the device while storage is locked.\n\nB. For a database application housing data for a single customer, encryption at the file system level would often provide more protection than FDE against the more likely threat of an intruder on the operating system accessing the storage.\n\nC. For a database application housing data for multiple customers, encryption with unique keys for each customer at the database record level may be more appropriate." + } + ] + } + ] + }, + { + "position": "starting", + "by-id": "sc-28.1_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sc-28.1_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "sc-45.1", + "adds": [ + { + "position": "ending", + "by-id": "sc-45.1_smt", + "parts": [ + { + "id": "sc-45.1_fr", + "name": "item", + "title": "SC-45(1) Additional FedRAMP Requirements and Guidance", + "parts": [ + { + "id": "sc-45.1_fr_smt.1", + "name": "item", + "props": [ + { + "name": "label", + "value": "Requirement:" + } + ], + "prose": "The service provider selects primary and secondary time servers used by the NIST Internet time service. The secondary server is selected from a different geographic region than the primary server." + }, + { + "id": "sc-45.1_fr_smt.2", + "name": "item", + "props": [ + { + "name": "label", + "value": "Requirement:" + } + ], + "prose": "The service provider synchronizes the system clocks of network computers that run operating systems other than Windows to the Windows Server Domain Controller emulator or to the same time source for that server." + }, + { + "id": "sc-45.1_fr_gdn.1", + "name": "guidance", + "props": [ + { + "name": "label", + "value": "Guidance:" + } + ], + "prose": "Synchronization of system clocks improves the accuracy of log analysis." + } + ] + } + ] + }, + { + "position": "starting", + "by-id": "sc-45.1_obj.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sc-45.1_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sc-45.1_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "sc-45.1_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "sc-45.1", + "props": [ + { + "name": "CORE", + "ns": "https://fedramp.gov/ns/oscal", + "value": "true" + } + ] + } + ] + }, + { + "control-id": "si-1", + "adds": [ + { + "position": "starting", + "by-id": "si-1_obj.a-1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "si-1_obj.a-2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "si-1_obj.a-3", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "si-1_obj.a-4", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "si-1_obj.a.1.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "si-1_obj.a.1.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "si-1_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "si-1_obj.c.1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "si-1_obj.c.2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "si-1_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point.", + "remarks": "This response must address all control sub-statement requirements." + } + ] + }, + { + "position": "starting", + "by-id": "si-1_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "si-1_smt.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point.", + "remarks": "This response must address all control sub-statement requirements." + } + ] + } + ] + }, + { + "control-id": "si-11", + "adds": [ + { + "position": "starting", + "by-id": "si-11_obj.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "si-11_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "si-11_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "si-11_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "si-12", + "adds": [ + { + "position": "starting", + "by-id": "si-12_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "si-12_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "si-16", + "adds": [ + { + "position": "starting", + "by-id": "si-16_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "si-16_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "si-2", + "adds": [ + { + "position": "starting", + "by-id": "si-2_obj.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "si-2_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "si-2_obj.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "si-2_obj.d", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "si-2_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "si-2_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "si-2_smt.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "si-2_smt.d", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "si-2.2", + "adds": [ + { + "position": "starting", + "by-id": "si-2.2_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "si-2.2_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "si-2.3", + "adds": [ + { + "position": "starting", + "by-id": "si-2.3_obj.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "si-2.3_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "si-2.3_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "si-2.3_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "si-3", + "adds": [ + { + "position": "starting", + "by-id": "si-3_obj.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "si-3_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "si-3_obj.c.1-1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "si-3_obj.c.1-2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "si-3_obj.c.2-1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "si-3_obj.c.2-2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "si-3_obj.d", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "si-3_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "si-3_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, { - "position": "ending", - "by-id": "ia-5.7_smt", - "parts": [ + "position": "starting", + "by-id": "si-3_smt.c", + "props": [ { - "id": "ia-5.7_fr", - "name": "item", - "title": "IA-5 (7) Additional FedRAMP Requirements and Guidance", - "parts": [ - { - "id": "ia-5.7_fr_gdn.1", - "name": "guidance", - "props": [ - { - "name": "label", - "value": "Guidance:" - } - ], - "prose": "In this context, prohibited static storage refers to any storage where unencrypted authenticators, such as passwords, persist beyond the time required to complete the access process." - } - ] + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." } ] - } - ] - }, - { - "control-id": "ia-5.8", - "adds": [ + }, { - "position": "ending", - "by-id": "ia-5.8_smt", - "parts": [ + "position": "starting", + "by-id": "si-3_smt.d", + "props": [ { - "id": "ia-5.8_fr", - "name": "item", - "title": "IA-5 (8) Additional FedRAMP Requirements and Guidance", - "parts": [ - { - "id": "ia-5.8_fr_gdn.x", - "name": "guidance", - "props": [ - { - "name": "label", - "value": "Guidance:" - } - ], - "prose": "If a single user authentication domain is used to access multiple systems, such as in single-sign-on, then only a single authenticator is required." - } - ] + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." } ] - } - ] - }, - { - "control-id": "ia-5.13", - "adds": [ + }, { - "position": "ending", - "by-id": "ia-5.13_smt", - "parts": [ + "position": "starting", + "by-id": "si-3", + "props": [ { - "id": "ia-5.13_fr", - "name": "item", - "title": "IA-5 (13) Additional FedRAMP Requirements and Guidance", - "parts": [ - { - "id": "ia-5.13_fr_gdn.1", - "name": "guidance", - "props": [ - { - "name": "label", - "value": "Guidance:" - } - ], - "prose": "For components subject to configuration baseline(s) (such as STIG or CIS,) the time period should conform to the baseline standard." - } - ] + "name": "CORE", + "ns": "https://fedramp.gov/ns/oscal", + "value": "true" } ] } ] }, { - "control-id": "ia-11", + "control-id": "si-4", "adds": [ { "position": "ending", - "by-id": "ia-11_smt", + "by-id": "si-4_smt", "parts": [ { - "id": "ia-11_fr", + "id": "si-4_fr", "name": "item", - "title": "IA-11 Additional FedRAMP Requirements and Guidance", + "title": "SI-4 Additional FedRAMP Requirements and Guidance", "parts": [ { - "id": "ia-11_fr_gdn.1", + "id": "si-4_fr_gdn.1", "name": "guidance", "props": [ { @@ -4585,627 +39602,1078 @@ "value": "Guidance:" } ], - "prose": "The fixed time period cannot exceed the limits set in SP 800-63. At this writing they are:\n\n* AAL3 (high baseline) * 12 hours or * 15 minutes of inactivity \n" + "prose": "See US-CERT Incident Response Reporting Guidelines." } ] } ] - } - ] - }, - { - "control-id": "ia-12", - "adds": [ + }, { - "position": "ending", - "by-id": "ia-12_smt", - "parts": [ + "position": "starting", + "by-id": "si-4_obj.a.1", + "props": [ { - "id": "ia-12_fr", - "name": "item", - "title": "IA-12 Additional FedRAMP Requirements and Guidance", - "parts": [ - { - "id": "ia-12_fr_gdn.1", - "name": "guidance", - "props": [ - { - "name": "label", - "value": "Guidance:" - } - ], - "prose": "In accordance with NIST SP 800-63A Enrollment and Identity Proofing" - } - ] + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" } ] - } - ] - }, - { - "control-id": "ia-12.5", - "adds": [ + }, { - "position": "ending", - "by-id": "ia-12.5_smt", - "parts": [ + "position": "starting", + "by-id": "si-4_obj.a.2", + "props": [ { - "id": "ia-12.5_fr", - "name": "item", - "title": "IA-12 (5) Additional FedRAMP Requirements and Guidance", - "parts": [ - { - "id": "ia-12.5_fr_gdn.1", - "name": "guidance", - "props": [ - { - "name": "label", - "value": "Guidance:" - } - ], - "prose": "In accordance with NIST SP 800-63A Enrollment and Identity Proofing" - } - ] + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" } ] - } - ] - }, - { - "control-id": "ir-3", - "adds": [ + }, { - "position": "ending", - "by-id": "ir-3_smt", - "parts": [ + "position": "starting", + "by-id": "si-4_obj.b", + "props": [ { - "id": "ir-3_fr", - "name": "item", - "title": "IR-3-2 Additional FedRAMP Requirements and Guidance", - "parts": [ - { - "id": "ir-3_fr_smt.1", - "name": "item", - "props": [ - { - "name": "label", - "value": "Requirement:" - } - ], - "prose": "The service provider defines tests and/or exercises in accordance with NIST Special Publication 800-61 (as amended). Functional testing must occur prior to testing for initial authorization. Annual functional testing may be concurrent with required penetration tests (see CA-8). The service provider provides test plans to the JAB/AO annually. Test plans are approved and accepted by the JAB/AO prior to test commencing." - } - ] + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "si-4_obj.c.1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "si-4_obj.c.2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "si-4_obj.d", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "si-4_obj.e", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "si-4_obj.f", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "si-4_obj.g", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "si-4_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "si-4_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "si-4_smt.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "si-4_smt.d", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "si-4_smt.e", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "si-4_smt.f", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "si-4_smt.g", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." } ] } ] }, { - "control-id": "ir-4", + "control-id": "si-4.1", "adds": [ { - "position": "ending", - "by-id": "ir-4_smt", - "parts": [ + "position": "starting", + "by-id": "si-4.1_obj-1", + "props": [ { - "id": "ir-4_fr", - "name": "item", - "title": "IR-4 Additional FedRAMP Requirements and Guidance", - "parts": [ - { - "id": "ir-4_fr_smt.1", - "name": "item", - "props": [ - { - "name": "label", - "value": "Requirement:" - } - ], - "prose": "The FISMA definition of \\\"incident\\\" shall be used: \\\"An occurrence that actually or imminently jeopardizes, without lawful authority, the confidentiality, integrity, or availability of information or an information system; or constitutes a violation or imminent threat of violation of law, security policies, security procedures, or acceptable use policies.\\\"" - }, - { - "id": "ir-4_fr_smt.2", - "name": "item", - "props": [ - { - "name": "label", - "value": "Requirement:" - } - ], - "prose": "The service provider ensures that individuals conducting incident handling meet personnel security requirements commensurate with the criticality/sensitivity of the information being processed, stored, and transmitted by the information system." - } - ] + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" } ] - } - ] - }, - { - "control-id": "ir-6", - "adds": [ + }, { - "position": "ending", - "by-id": "ir-6_smt", - "parts": [ + "position": "starting", + "by-id": "si-4.1_obj-2", + "props": [ { - "id": "ir-6_fr", - "name": "item", - "title": "IR-6 Additional FedRAMP Requirements and Guidance", - "parts": [ - { - "id": "ir-6_fr_smt.1", - "name": "item", - "props": [ - { - "name": "label", - "value": "Requirement:" - } - ], - "prose": "Reports security incident information according to FedRAMP Incident Communications Procedure." - } - ] + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "si-4.1_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "si-4.1", + "props": [ + { + "name": "CORE", + "ns": "https://fedramp.gov/ns/oscal", + "value": "true" } ] } ] }, { - "control-id": "ir-8", + "control-id": "si-4.11", "adds": [ { - "position": "ending", - "by-id": "ir-8_smt", - "parts": [ + "position": "starting", + "by-id": "si-4.11_obj", + "props": [ { - "id": "ir-8_fr", - "name": "item", - "title": "IR-8 Additional FedRAMP Requirements and Guidance", - "parts": [ - { - "id": "ir-8_fr_smt.1", - "name": "item", - "props": [ - { - "name": "label", - "value": "(b) Requirement:" - } - ], - "prose": "The service provider defines a list of incident response personnel (identified by name and/or by role) and organizational elements. The incident response list includes designated FedRAMP personnel." - }, - { - "id": "ir-8_fr_smt.2", - "name": "item", - "props": [ - { - "name": "label", - "value": "(d) Requirement:" - } - ], - "prose": "The service provider defines a list of incident response personnel (identified by name and/or by role) and organizational elements. The incident response list includes designated FedRAMP personnel." - } - ] + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "si-4.11_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." } ] } ] }, { - "control-id": "mp-3", + "control-id": "si-4.12", "adds": [ { - "position": "ending", - "by-id": "mp-3_smt", - "parts": [ + "position": "starting", + "by-id": "si-4.12_obj", + "props": [ { - "id": "mp-3_fr", - "name": "item", - "title": "MP-3 Additional FedRAMP Requirements and Guidance", - "parts": [ - { - "id": "mp-3_fr_gdn.1", - "name": "guidance", - "props": [ - { - "name": "label", - "value": "(b) Guidance:" - } - ], - "prose": "Second parameter not-applicable" - } - ] + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "si-4.12_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." } ] } ] }, { - "control-id": "mp-4", + "control-id": "si-4.14", "adds": [ { - "position": "ending", - "by-id": "mp-4_smt", - "parts": [ + "position": "starting", + "by-id": "si-4.14_obj", + "props": [ { - "id": "mp-4_fr", - "name": "item", - "title": "MP-4 Additional FedRAMP Requirements and Guidance", - "parts": [ - { - "id": "mp-4_fr_smt.1", - "name": "item", - "props": [ - { - "name": "label", - "value": "(a) Requirement:" - } - ], - "prose": "The service provider defines controlled areas within facilities where the information and information system reside." - } - ] + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "si-4.14_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." } ] } ] }, { - "control-id": "mp-5", + "control-id": "si-4.16", "adds": [ { - "position": "ending", - "by-id": "mp-5_smt", - "parts": [ + "position": "starting", + "by-id": "si-4.16_obj", + "props": [ { - "id": "mp-5_fr", - "name": "item", - "title": "MP-5 Additional FedRAMP Requirements and Guidance", - "parts": [ - { - "id": "mp-5_fr_smt.1", - "name": "item", - "props": [ - { - "name": "label", - "value": "(a) Requirement:" - } - ], - "prose": "The service provider defines security measures to protect digital and non-digital media in transport. The security measures are approved and accepted by the JAB/AO." - } - ] + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "si-4.16_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "si-4.16", + "props": [ + { + "name": "CORE", + "ns": "https://fedramp.gov/ns/oscal", + "value": "true" } ] } ] }, { - "control-id": "mp-6.1", + "control-id": "si-4.18", "adds": [ { - "position": "ending", - "by-id": "mp-6.1_smt", - "parts": [ + "position": "starting", + "by-id": "si-4.18_obj", + "props": [ { - "id": "mp-6.1_fr", - "name": "item", - "title": "MP-6 (1) Additional FedRAMP Requirements and Guidance", - "parts": [ - { - "id": "mp-6.1_fr_smt.1", - "name": "item", - "props": [ - { - "name": "label", - "value": "Requirement:" - } - ], - "prose": "Must comply with NIST SP 800-88" - } - ] + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "si-4.18_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." } ] } ] }, { - "control-id": "mp-6.2", + "control-id": "si-4.19", "adds": [ { - "position": "ending", - "by-id": "mp-6.2_smt", - "parts": [ + "position": "starting", + "by-id": "si-4.19_obj", + "props": [ { - "id": "mp-6.2_fr", - "name": "item", - "title": "MP-6 (2) Additional FedRAMP Requirements and Guidance", - "parts": [ - { - "id": "mp-6.2_fr_smt.1", - "name": "guidance", - "props": [ - { - "name": "label", - "value": "Guidance:" - } - ], - "prose": "Equipment and procedures may be tested or validated for effectiveness" - } - ] + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "si-4.19_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "si-4.19", + "props": [ + { + "name": "CORE", + "ns": "https://fedramp.gov/ns/oscal", + "value": "true" } ] } ] }, { - "control-id": "mp-6.3", + "control-id": "si-4.2", "adds": [ { - "position": "ending", - "by-id": "mp-6.3_smt", - "parts": [ + "position": "starting", + "by-id": "si-4.2_obj", + "props": [ { - "id": "mp-6.3_fr", - "name": "item", - "title": "MP-6 (3) Additional FedRAMP Requirements and Guidance", - "parts": [ - { - "id": "mp-6.3_fr_smt.1", - "name": "item", - "props": [ - { - "name": "label", - "value": "Requirement:" - } - ], - "prose": "Must comply with NIST SP 800-88" - } - ] + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" } ] - } - ] - }, - { - "control-id": "pe-14", - "adds": [ + }, { - "position": "ending", - "by-id": "pe-14_smt", - "parts": [ + "position": "starting", + "by-id": "si-4.2_smt", + "props": [ { - "id": "pe-14_fr", - "name": "item", - "title": "PE-14 Additional FedRAMP Requirements and Guidance", - "parts": [ - { - "id": "pe-14_fr_smt.1", - "name": "item", - "props": [ - { - "name": "label", - "value": "(a) Requirement:" - } - ], - "prose": "The service provider measures temperature at server inlets and humidity levels by dew point." - } - ] + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "si-4.2", + "props": [ + { + "name": "CORE", + "ns": "https://fedramp.gov/ns/oscal", + "value": "true" } ] } ] }, { - "control-id": "pl-8", + "control-id": "si-4.20", "adds": [ { - "position": "ending", - "by-id": "pl-8_smt", - "parts": [ + "position": "starting", + "by-id": "si-4.20_obj", + "props": [ { - "id": "pl-8_fr", - "name": "item", - "title": "PL-8 Additional FedRAMP Requirements and Guidance", - "parts": [ - { - "id": "pl-8_fr_gdn.1", - "name": "guidance", - "props": [ - { - "name": "label", - "value": "(b) Guidance:" - } - ], - "prose": "Significant change is defined in NIST Special Publication 800-37 Revision 2, Appendix F." - } - ] + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "si-4.20_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "si-4.20", + "props": [ + { + "name": "CORE", + "ns": "https://fedramp.gov/ns/oscal", + "value": "true" } ] } ] }, { - "control-id": "pl-10", + "control-id": "si-4.22", "adds": [ { - "position": "ending", - "by-id": "pl-10_smt", - "parts": [ + "position": "starting", + "by-id": "si-4.22_obj.a", + "props": [ { - "id": "pl-10_fr", - "name": "item", - "title": "PL-10 Additional FedRAMP Requirements and Guidance", - "parts": [ - { - "id": "pl-10_fr_smt.1", - "name": "item", - "props": [ - { - "name": "label", - "value": "Requirement:" - } - ], - "prose": "Select the appropriate FedRAMP Baseline" - } - ] + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "si-4.22_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "si-4.22_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "si-4.22_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." } ] } ] }, { - "control-id": "ra-3", + "control-id": "si-4.23", "adds": [ { - "position": "ending", - "by-id": "ra-3_smt", - "parts": [ + "position": "starting", + "by-id": "si-4.23_obj", + "props": [ { - "id": "ra-3_fr", - "name": "item", - "title": "RA-3 Additional FedRAMP Requirements and Guidance", - "parts": [ - { - "id": "ra-3_fr_gdn.1", - "name": "guidance", - "props": [ - { - "name": "label", - "value": "Guidance:" - } - ], - "prose": "Significant change is defined in NIST Special Publication 800-37 Revision 2, Appendix F." - }, - { - "id": "ra-3_fr_smt.1", - "name": "item", - "props": [ - { - "name": "label", - "value": "(e) Requirement:" - } - ], - "prose": "Include all Authorizing Officials; for JAB authorizations to include FedRAMP." - } - ] + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "si-4.23_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "si-4.23", + "props": [ + { + "name": "CORE", + "ns": "https://fedramp.gov/ns/oscal", + "value": "true" } ] } ] }, { - "control-id": "ra-5", + "control-id": "si-4.4", "adds": [ { - "position": "ending", - "by-id": "ra-5_smt", - "parts": [ + "position": "starting", + "by-id": "si-4.4_obj.a", + "props": [ { - "id": "ra-5_fr", - "name": "item", - "title": "RA-5 Additional FedRAMP Requirements and Guidance", - "parts": [ - { - "id": "ra-5_fr_gdn.1", - "name": "guidance", - "props": [ - { - "name": "label", - "value": "Guidance:" - } - ], - "prose": "See the FedRAMP Documents page> Vulnerability Scanning Requirements https://www.FedRAMP.gov/documents/" - }, - { - "id": "ra-5_fr_smt.1", - "name": "item", - "props": [ - { - "name": "label", - "value": "(a) Requirement:" - } - ], - "prose": "an accredited independent assessor scans operating systems/infrastructure, web applications, and databases once annually." - }, - { - "id": "ra-5_fr_smt.2", - "name": "item", - "props": [ - { - "name": "label", - "value": "(d) Requirement:" - } - ], - "prose": "If a vulnerability is listed among the CISA Known Exploited Vulnerability (KEV) Catalog (https://www.cisa.gov/known-exploited-vulnerabilities-catalog) the KEV remediation date supersedes the FedRAMP parameter requirement." - }, - { - "id": "ra-5_fr_smt.3", - "name": "item", - "props": [ - { - "name": "label", - "value": "(e) Requirement:" - } - ], - "prose": "to include all Authorizing Officials; for JAB authorizations to include FedRAMP" - }, - { - "id": "ra-5_fr_gdn.2", - "name": "guidance", - "props": [ - { - "name": "label", - "value": "Guidance:" - } - ], - "prose": "Informational findings from a scanner are detailed as a returned result that holds no vulnerability risk or severity and for FedRAMP does not require an entry onto the POA&M or entry onto the RET during any assessment phase.\n\nWarning findings, on the other hand, are given a risk rating (low, moderate, high or critical) by the scanning solution and should be treated like any other finding with a risk or severity rating for tracking purposes onto either the POA&M or RET depending on when the findings originated (during assessments or during monthly continuous monitoring). If a warning is received during scanning, but further validation turns up no actual issue then this item should be categorized as a false positive. If this situation presents itself during an assessment phase (initial assessment, annual assessment or any SCR), follow guidance on how to report false positives in the Security Assessment Report (SAR). If this situation happens during monthly continuous monitoring, a deviation request will need to be submitted per the FedRAMP Vulnerability Deviation Request Form.\n\nWarnings are commonly associated with scanning solutions that also perform compliance scans, and if the scanner reports a “warning” as part of the compliance scanning of a CSO, follow guidance surrounding the tracking of compliance findings during either the assessment phases (initial assessment, annual assessment or any SCR) or monthly continuous monitoring as it applies. Guidance on compliance scan findings can be found by searching on “Tracking of Compliance Scans” in FAQs." - } - ] + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "si-4.4_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "si-4.4_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "si-4.4_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." } ] } ] }, { - "control-id": "ra-5.8", + "control-id": "si-4.5", "adds": [ { "position": "ending", - "by-id": "ra-5.8_smt", + "by-id": "si-4.5_smt", "parts": [ { - "id": "ra-5.8_fr", + "id": "si-4.5_fr", "name": "item", - "title": "RA-5(8) Additional FedRAMP Requirement", + "title": "SI-4 (5) Additional FedRAMP Requirements and Guidance", "parts": [ { - "id": "ra-5.8_fr_smt.1", - "name": "item", + "id": "si-4.5_fr_gdn.1", + "name": "guidance", "props": [ { "name": "label", - "value": "Requirement:" + "value": "Guidance:" } ], - "prose": "This enhancement is required for all high (or critical) vulnerability scan findings." + "prose": "In accordance with the incident response plan." } ] } ] + }, + { + "position": "starting", + "by-id": "si-4.5_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "si-4.5_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] } ] }, { - "control-id": "sa-4", + "control-id": "si-4.10", "adds": [ { "position": "ending", - "by-id": "sa-4_smt", + "by-id": "si-4.10_smt", "parts": [ { - "id": "sa-4_fr", + "id": "si-4.10_fr", "name": "item", - "title": "SA-4 Additional FedRAMP Requirements and Guidance", + "title": "SI-4 (10) Additional FedRAMP Requirements and Guidance", "parts": [ { - "id": "sa-4_fr_smt.1", + "id": "si-4.10_fr_smt.1", "name": "item", "props": [ { @@ -5213,443 +40681,743 @@ "value": "Requirement:" } ], - "prose": "The service provider must comply with Federal Acquisition Regulation (FAR) Subpart 7.103, and Section 889 of the John S. McCain National Defense Authorization Act (NDAA) for Fiscal Year 2019 (Pub. L. 115-232), and FAR Subpart 4.21, which implements Section 889 (as well as any added updates related to FISMA to address security concerns in the system acquisitions process)." - }, - { - "id": "sa-4_fr_gdn.1", - "name": "guidance", - "props": [ - { - "name": "label", - "value": "Guidance:" - } - ], - "prose": "The use of Common Criteria (ISO/IEC 15408) evaluated products is strongly preferred.\n\nSee https://www.niap-ccevs.org/Product/index.cfm or https://www.commoncriteriaportal.org/products/." + "prose": "The service provider must support Agency requirements to comply with M-21-31 (https://www.whitehouse.gov/wp-content/uploads/2021/08/M-21-31-Improving-the-Federal-Governments-Investigative-and-Remediation-Capabilities-Related-to-Cybersecurity-Incidents.pdf) and M-22-09 (https://www.whitehouse.gov/wp-content/uploads/2022/01/M-22-09.pdf)." } ] } ] + }, + { + "position": "starting", + "by-id": "si-4.10_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "si-4.10_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "si-4.10", + "props": [ + { + "name": "CORE", + "ns": "https://fedramp.gov/ns/oscal", + "value": "true" + } + ] } ] }, { - "control-id": "sa-10", + "control-id": "si-5", "adds": [ { "position": "ending", - "by-id": "sa-10_smt", + "by-id": "si-5_smt", "parts": [ { - "id": "sa-10_fr", + "id": "si-5_fr_smt.1", "name": "item", - "title": "SA-10 Additional FedRAMP Requirements and Guidance", - "parts": [ + "title": "SI-5 Additional FedRAMP Requirements and Guidance", + "props": [ { - "id": "sa-10_fr_smt.1", - "name": "item", - "props": [ - { - "name": "label", - "value": "(e) Requirement:" - } - ], - "prose": "track security flaws and flaw resolution within the system, component, or service and report findings to organization-defined personnel, to include FedRAMP." + "name": "label", + "value": "Requirement:" } - ] + ], + "prose": "Service Providers must address the CISA Emergency and Binding Operational Directives applicable to their cloud service offering per FedRAMP guidance. This includes listing the applicable directives and stating compliance status." + } + ] + }, + { + "position": "starting", + "by-id": "si-5_obj.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "si-5_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "si-5_obj.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "si-5_obj.d", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "si-5_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "si-5_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "si-5_smt.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "si-5_smt.d", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." } ] } ] }, { - "control-id": "sa-11.1", + "control-id": "si-5.1", "adds": [ { - "position": "ending", - "by-id": "sa-11.1_smt", - "parts": [ + "position": "starting", + "by-id": "si-5.1_obj", + "props": [ { - "id": "sa-11.1_fr", - "name": "item", - "title": "SA-11(1) Additional FedRAMP Requirements", - "parts": [ - { - "id": "sa-11.1_fr_smt.1", - "name": "item", - "props": [ - { - "name": "label", - "value": "Requirement:" - } - ], - "prose": "The service provider must document its methodology for reviewing newly developed code for the Service in its Continuous Monitoring Plan.\n\nIf Static code analysis cannot be performed (for example, when the source code is not available), then dynamic code analysis must be performed (see SA-11 (8))" - } - ] + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "si-5.1_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." } ] } ] }, { - "control-id": "sc-7", + "control-id": "si-6", "adds": [ { - "position": "ending", - "by-id": "sc-7_smt", - "parts": [ + "position": "starting", + "by-id": "si-6_obj.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "si-6_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "si-6_obj.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "si-6_obj.d", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "si-6_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "si-6_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "si-6_smt.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "si-6_smt.d", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "si-6", + "props": [ + { + "name": "CORE", + "ns": "https://fedramp.gov/ns/oscal", + "value": "true" + } + ] + } + ] + }, + { + "control-id": "si-7", + "adds": [ + { + "position": "starting", + "by-id": "si-7_obj.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "si-7_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "si-7_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "si-7_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "si-7", + "props": [ { - "id": "sc-7_fr", - "name": "item", - "title": "SC-7 Additional FedRAMP Requirements and Guidance", - "parts": [ - { - "id": "sc-7_fr_gdn.1", - "name": "guidance", - "props": [ - { - "name": "label", - "value": "(b) Guidance:" - } - ], - "prose": "SC-7 (b) should be met by subnet isolation. A subnetwork (subnet) is a physically or logically segmented section of a larger network defined at TCP/IP Layer 3, to both minimize traffic and, important for a FedRAMP Authorization, add a crucial layer of network isolation. Subnets are distinct from VLANs (Layer 2), security groups, and VPCs and are specifically required to satisfy SC-7 part b and other controls. See the FedRAMP Subnets White Paper (https://www.fedramp.gov/assets/resources/documents/FedRAMP_subnets_white_paper.pdf) for additional information." - } - ] + "name": "CORE", + "ns": "https://fedramp.gov/ns/oscal", + "value": "true" } ] } ] }, { - "control-id": "sc-7.5", + "control-id": "si-7.1", "adds": [ { - "position": "ending", - "by-id": "sc-7.5_smt", - "parts": [ + "position": "starting", + "by-id": "si-7.1_obj", + "props": [ { - "id": "sc-7.5_fr", - "name": "item", - "title": "SC-7 (5) Additional FedRAMP Requirements and Guidance", - "parts": [ - { - "id": "sc-7.5_fr_gdn.1", - "name": "guidance", - "props": [ - { - "name": "label", - "value": "Guidance:" - } - ], - "prose": "For JAB Authorization, CSPs shall include details of this control in their Architecture Briefing" - } - ] + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" } ] - } - ] - }, - { - "control-id": "sc-8", - "adds": [ + }, { - "position": "ending", - "by-id": "sc-8_smt", - "parts": [ + "position": "starting", + "by-id": "si-7.1_smt", + "props": [ { - "id": "sc-8_fr", - "name": "item", - "title": "SC-8 Additional FedRAMP Requirements and Guidance", - "parts": [ - { - "id": "sc-8_fr_gdn.1", - "name": "guidance", - "props": [ - { - "name": "label", - "value": "Guidance:" - } - ], - "prose": "For each instance of data in transit, confidentiality AND integrity should be through cryptography as specified in SC-8 (1), physical means as specified in SC-8 (5), or in combination.\n\n\n\nFor clarity, this control applies to all data in transit. Examples include the following data flows:\n\n* Crossing the system boundary\n* Between compute instances - including containers\n* From a compute instance to storage\n* Replication between availability zones\n* Transmission of backups to storage\n* From a load balancer to a compute instance\n* Flows from management tools required for their work – e.g. log collection, scanning, etc.\n\n\n\n\nThe following applies only when choosing SC-8 (5) in lieu of SC-8 (1).\n\nFedRAMP-Defined Assignment / Selection Parameters\n\nSC-8 (5)-1 [a hardened or alarmed carrier Protective Distribution System (PDS) when outside of Controlled Access Area (CAA)]\n\nSC-8 (5)-2 [prevent unauthorized disclosure of information AND detect changes to information]" - }, - { - "id": "sc-8_fr_gdn.2", - "name": "guidance", - "props": [ - { - "name": "label", - "value": "Guidance:" - } - ], - "prose": "SC-8 (5) applies when physical protection has been selected as the method to protect confidentiality and integrity. For physical protection, data in transit must be in either a Controlled Access Area (CAA), or a Hardened or alarmed PDS.\n\n\n\nHardened or alarmed PDS: Shall be as defined in SECTION X - CATEGORY 2 PDS INSTALLATION GUIDANCE of CNSSI No.7003, titled PROTECTED DISTRIBUTION SYSTEMS (PDS). Per the CNSSI No. 7003 Section VIII, PDS must originate and terminate in a Controlled Access Area (CAA).\n\n\n\nControlled Access Area (CAA): Data will be considered physically protected, and in a CAA if it meets Section 2.3 of the DHS’s Recommended Practice: Improving Industrial Control System Cybersecurity with Defense-in-Depth Strategies. CSPs can meet Section 2.3 of the DHS’ recommended practice by satisfactory implementation of the following controls PE-2 (1), PE-2 (2), PE-2 (3), PE-3 (2), PE-3 (3), PE-6 (2), and PE-6 (3).\n\n\n\nNote: When selecting SC-8 (5), the above SC-8(5), and the above referenced PE controls must be added to the SSP.\n\n\n\nCNSSI No.7003 can be accessed here:\n\nhttps://www.dcsa.mil/Portals/91/documents/ctp/nao/CNSSI_7003_PDS_September_2015.pdf\n\n\n\nDHS Recommended Practice: Improving Industrial Control System Cybersecurity with Defense-in-Depth Strategies can be accessed here:\n\nhttps://us-cert.cisa.gov/sites/default/files/FactSheets/NCCIC%20ICS_FactSheet_Defense_in_Depth_Strategies_S508C.pdf" - } - ] + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "si-7.1", + "props": [ + { + "name": "CORE", + "ns": "https://fedramp.gov/ns/oscal", + "value": "true" } ] } ] }, { - "control-id": "sc-8.1", + "control-id": "si-7.15", "adds": [ { - "position": "ending", - "by-id": "sc-8.1_smt", - "parts": [ + "position": "starting", + "by-id": "si-7.15_obj", + "props": [ { - "id": "sc-8.1_fr", - "name": "item", - "title": "SC-8 (1) Additional FedRAMP Requirements and Guidance", - "parts": [ - { - "id": "sc-8.1_fr_smt.1", - "name": "item", - "props": [ - { - "name": "label", - "value": "Requirement:" - } - ], - "prose": "Please ensure SSP Section 10.3 Cryptographic Modules Implemented for Data At Rest (DAR) and Data In Transit (DIT) is fully populated for reference in this control." - }, - { - "id": "sc-8.1_fr_gdn.1", - "name": "guidance", - "props": [ - { - "name": "label", - "value": "Guidance:" - } - ], - "prose": "See M-22-09, including \\\"Agencies encrypt all DNS requests and HTTP traffic within their environment\\\"\n\nSC-8 (1) applies when encryption has been selected as the method to protect confidentiality and integrity. Otherwise refer to SC-8 (5). SC-8 (1) is strongly encouraged." - }, - { - "id": "sc-8.1_fr_gdn.2", - "name": "guidance", - "props": [ - { - "name": "label", - "value": "Guidance:" - } - ], - "prose": "Note that this enhancement requires the use of cryptography which must be compliant with Federal requirements and utilize FIPS validated or NSA approved cryptography (see SC-13.)" - }, - { - "id": "sc-8.1_fr_gdn.3", - "name": "guidance", - "props": [ - { - "name": "label", - "value": "Guidance:" - } - ], - "prose": "When leveraging encryption from the underlying IaaS/PaaS: While some IaaS/PaaS services provide encryption by default, many require encryption to be configured, and enabled by the customer. The CSP has the responsibility to verify encryption is properly configured." - } - ] + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "si-7.15_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." } ] } ] }, { - "control-id": "sc-12", + "control-id": "si-7.2", "adds": [ { - "position": "ending", - "by-id": "sc-12_smt", - "parts": [ + "position": "starting", + "by-id": "si-7.2_obj", + "props": [ { - "id": "sc-12_fr", - "name": "item", - "title": "SC-12 Additional FedRAMP Requirements and Guidance", - "parts": [ - { - "id": "sc-12_fr_gdn.1", - "name": "guidance", - "props": [ - { - "name": "label", - "value": "Guidance:" - } - ], - "prose": "See references in NIST 800-53 documentation." - }, - { - "id": "sc-12_fr_gdn.2", - "name": "guidance", - "props": [ - { - "name": "label", - "value": "Guidance:" - } - ], - "prose": "Must meet applicable Federal Cryptographic Requirements. See References Section of control." - }, - { - "id": "sc-12_fr_gdn.3", - "name": "guidance", - "props": [ - { - "name": "label", - "value": "Guidance:" - } - ], - "prose": "Wildcard certificates may be used internally within the system, but are not permitted for external customer access to the system." - } - ] + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "si-7.2_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." } ] } ] }, { - "control-id": "sc-13", + "control-id": "si-7.5", "adds": [ { - "position": "ending", - "by-id": "sc-13_smt", - "parts": [ + "position": "starting", + "by-id": "si-7.5_obj", + "props": [ { - "id": "sc-13_fr", - "name": "item", - "title": "SC-13 Additional FedRAMP Requirements and Guidance", - "parts": [ - { - "id": "sc-13_fr_gdn.1", - "name": "guidance", - "props": [ - { - "name": "label", - "value": "Guidance:" - } - ], - "prose": "This control applies to all use of cryptography. In addition to encryption, this includes functions such as hashing, random number generation, and key generation. Examples include the following:\n\n* Encryption of data\n* Decryption of data\n* Generation of one time passwords (OTPs) for MFA\n* Protocols such as TLS, SSH, and HTTPS\n\n\n\n\nThe requirement for FIPS 140 validation, as well as timelines for acceptance of FIPS 140-2, and 140-3 can be found at the NIST Cryptographic Module Validation Program (CMVP).\n\nhttps://csrc.nist.gov/projects/cryptographic-module-validation-program" - }, - { - "id": "sc-13_fr_gdn.2", - "name": "guidance", - "props": [ - { - "name": "label", - "value": "Guidance:" - } - ], - "prose": "For NSA-approved cryptography, the National Information Assurance Partnership (NIAP) oversees a national program to evaluate Commercial IT Products for Use in National Security Systems. The NIAP Product Compliant List can be found at the following location:\n\nhttps://www.niap-ccevs.org/Product/index.cfm" - }, - { - "id": "sc-13_fr_gdn.3", - "name": "guidance", - "props": [ - { - "name": "label", - "value": "Guidance:" - } - ], - "prose": "When leveraging encryption from underlying IaaS/PaaS: While some IaaS/PaaS provide encryption by default, many require encryption to be configured, and enabled by the customer. The CSP has the responsibility to verify encryption is properly configured." - }, - { - "id": "sc-13_fr_gdn.4", - "name": "guidance", - "props": [ - { - "name": "label", - "value": "Guidance:" - } - ], - "prose": "Moving to non-FIPS CM or product is acceptable when:\n\n* FIPS validated version has a known vulnerability\n* Feature with vulnerability is in use\n* Non-FIPS version fixes the vulnerability\n* Non-FIPS version is submitted to NIST for FIPS validation\n* POA&M is added to track approval, and deployment when ready\n" - }, - { - "id": "sc-13_fr_gdn.5", - "name": "guidance", - "props": [ - { - "name": "label", - "value": "Guidance:" - } - ], - "prose": "At a minimum, this control applies to cryptography in use for the following controls: AU-9(3), CP-9(8), IA-2(6), IA-5(1), MP-5, SC-8(1), and SC-28(1)." - } - ] + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "si-7.5_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." } ] } ] }, { - "control-id": "sc-15", + "control-id": "si-7.7", "adds": [ { - "position": "ending", - "by-id": "sc-15_smt", - "parts": [ + "position": "starting", + "by-id": "si-7.7_obj", + "props": [ { - "id": "sc-15_fr", - "name": "item", - "title": "SC-15 Additional FedRAMP Requirements and Guidance", - "parts": [ - { - "id": "sc-15_fr_smt.1", - "name": "item", - "props": [ - { - "name": "label", - "value": "Requirement:" - } - ], - "prose": "The information system provides disablement (instead of physical disconnect) of collaborative computing devices in a manner that supports ease of use." - } - ] + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "si-7.7_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." } ] } ] }, { - "control-id": "sc-20", + "control-id": "si-8", "adds": [ { "position": "ending", - "by-id": "sc-20_smt", + "by-id": "si-8_smt", "parts": [ { - "id": "sc-20_fr", + "id": "si-8_fr", "name": "item", - "title": "SC-20 Additional FedRAMP Requirements and Guidance", + "title": "SI-8 Additional FedRAMP Requirements and Guidance", "parts": [ { - "id": "sc-20_fr_smt.1", - "name": "item", - "props": [ - { - "name": "label", - "value": "Requirement:" - } - ], - "prose": "Control Description should include how DNSSEC is implemented on authoritative DNS servers to supply valid responses to external DNSSEC requests." - }, - { - "id": "sc-20_fr_smt.2", - "name": "item", - "props": [ - { - "name": "label", - "value": "Requirement:" - } - ], - "prose": "Authoritative DNS servers must be geolocated in accordance with SA-9 (5)." - }, - { - "id": "sc-20_fr_gdn.1", - "name": "guidance", - "props": [ - { - "name": "label", - "value": "Guidance:" - } - ], - "prose": "SC-20 applies to use of external authoritative DNS to access a CSO from outside the boundary." - }, - { - "id": "sc-20_fr_gdn.2", + "id": "si-8_fr_gdn.1", "name": "guidance", "props": [ { @@ -5657,10 +41425,10 @@ "value": "Guidance:" } ], - "prose": "External authoritative DNS servers may be located outside an authorized environment. Positioning these servers inside an authorized boundary is encouraged." + "prose": "When CSO sends email on behalf of the government as part of the business offering, Control Description should include implementation of Domain-based Message Authentication, Reporting & Conformance (DMARC) on the sending domain for outgoing messages as described in DHS Binding Operational Directive (BOD) 18-01.\n\nhttps://cyber.dhs.gov/bod/18-01/" }, { - "id": "sc-20_fr_gdn.3", + "id": "si-8_fr_gdn.2", "name": "guidance", "props": [ { @@ -5668,39 +41436,96 @@ "value": "Guidance:" } ], - "prose": "CSPs are recommended to self-check DNSSEC configuration through one of many available analyzers such as Sandia National Labs (https://dnsviz.net)" + "prose": "CSPs should confirm DMARC configuration (where appropriate) to ensure that policy=reject and the rua parameter includes reports@dmarc.cyber.dhs.gov. DMARC compliance should be documented in the SI-08 control implementation solution description, and list the FROM: domain(s) that will be seen by email recipients." } ] } ] + }, + { + "position": "starting", + "by-id": "si-8_obj.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "si-8_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "si-8_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "si-8_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] } ] }, { - "control-id": "sc-21", + "control-id": "si-10", "adds": [ { "position": "ending", - "by-id": "sc-21_smt", + "by-id": "si-10_smt", "parts": [ { - "id": "sc-21_fr", + "id": "si-10_fr", "name": "item", - "title": "SC-21 Additional FedRAMP Requirements and Guidance", + "title": "SI-10 Additional FedRAMP Requirements and Guidance", "parts": [ { - "id": "sc-21_fr_smt.1", - "name": "item", - "props": [ - { - "name": "label", - "value": "Requirement:" - } - ], - "prose": "Control description should include how DNSSEC is implemented on recursive DNS servers to make DNSSEC requests when resolving DNS requests from internal components to domains external to the CSO boundary.\n\n* If the reply is signed, and fails DNSSEC, do not use the reply\n* If the reply is unsigned: * CSP chooses the policy to apply \n" - }, - { - "id": "sc-21_fr_smt.2", + "id": "si-10_fr_smt.1", "name": "item", "props": [ { @@ -5708,341 +41533,748 @@ "value": "Requirement:" } ], - "prose": "Internal recursive DNS servers must be located inside an authorized environment. It is typically within the boundary, or leveraged from an underlying IaaS/PaaS." - }, - { - "id": "sc-21_fr_gdn.1", - "name": "guidance", - "props": [ - { - "name": "label", - "value": "Guidance:" - } - ], - "prose": "Accepting an unsigned reply is acceptable" - }, - { - "id": "sc-21_fr_gdn.2", - "name": "guidance", - "props": [ - { - "name": "label", - "value": "Guidance:" - } - ], - "prose": "SC-21 applies to use of internal recursive DNS to access a domain outside the boundary by a component inside the boundary.\n\n- DNSSEC resolution to access a component inside the boundary is excluded." + "prose": "Validate all information inputs and document any exceptions" } ] } ] - } - ] - }, - { - "control-id": "sc-28", - "adds": [ + }, + { + "position": "starting", + "by-id": "si-10_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "si-10_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "si-10", + "props": [ + { + "name": "CORE", + "ns": "https://fedramp.gov/ns/oscal", + "value": "true" + } + ] + } + ] + }, + { + "control-id": "si-8.2", + "adds": [ + { + "position": "starting", + "by-id": "si-8.2_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "si-8.2_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "sr-1", + "adds": [ + { + "position": "starting", + "by-id": "sr-1_obj.a-1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sr-1_obj.a-2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sr-1_obj.a-3", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sr-1_obj.a-4", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sr-1_obj.a.1.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sr-1_obj.a.1.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sr-1_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sr-1_obj.c.1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sr-1_obj.c.2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sr-1_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point.", + "remarks": "This response must address all control sub-statement requirements." + } + ] + }, + { + "position": "starting", + "by-id": "sr-1_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, { - "position": "ending", - "by-id": "sc-28_smt", - "parts": [ + "position": "starting", + "by-id": "sr-1_smt.c", + "props": [ { - "id": "sc-28_fr", - "name": "item", - "title": "SC-28 Additional FedRAMP Requirements and Guidance", - "parts": [ - { - "id": "sc-28_fr_gdn.1", - "name": "guidance", - "props": [ - { - "name": "label", - "value": "Guidance:" - } - ], - "prose": "The organization supports the capability to use cryptographic mechanisms to protect information at rest." - }, - { - "id": "sc-28_fr_gdn.2", - "name": "guidance", - "props": [ - { - "name": "label", - "value": "Guidance:" - } - ], - "prose": "When leveraging encryption from underlying IaaS/PaaS: While some IaaS/PaaS services provide encryption by default, many require encryption to be configured, and enabled by the customer. The CSP has the responsibility to verify encryption is properly configured." - }, - { - "id": "sc-28_fr_gdn.3", - "name": "guidance", - "props": [ - { - "name": "label", - "value": "Guidance:" - } - ], - "prose": "Note that this enhancement requires the use of cryptography in accordance with SC-13." - } - ] + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point.", + "remarks": "This response must address all control sub-statement requirements." } ] } ] }, { - "control-id": "sc-28.1", + "control-id": "sr-10", "adds": [ { - "position": "ending", - "by-id": "sc-28.1_smt", - "parts": [ + "position": "starting", + "by-id": "sr-10_obj", + "props": [ { - "id": "sc-28.1_fr", - "name": "item", - "title": "SC-28 (1) Additional FedRAMP Requirements and Guidance", - "parts": [ - { - "id": "sc-28.1_fr_gdn.1", - "name": "guidance", - "props": [ - { - "name": "label", - "value": "Guidance:" - } - ], - "prose": "Organizations should select a mode of protection that is targeted towards the relevant threat scenarios.\n\nExamples:\n\nA. Organizations may apply full disk encryption (FDE) to a mobile device where the primary threat is loss of the device while storage is locked.\n\nB. For a database application housing data for a single customer, encryption at the file system level would often provide more protection than FDE against the more likely threat of an intruder on the operating system accessing the storage.\n\nC. For a database application housing data for multiple customers, encryption with unique keys for each customer at the database record level may be more appropriate." - } - ] + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sr-10_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." } ] } ] }, { - "control-id": "sc-45.1", + "control-id": "sr-11.1", "adds": [ { - "position": "ending", - "by-id": "sc-45.1_smt", - "parts": [ + "position": "starting", + "by-id": "sr-11.1_obj", + "props": [ { - "id": "sc-45.1_fr", - "name": "item", - "title": "SC-45(1) Additional FedRAMP Requirements and Guidance", - "parts": [ - { - "id": "sc-45.1_fr_smt.1", - "name": "item", - "props": [ - { - "name": "label", - "value": "Requirement:" - } - ], - "prose": "The service provider selects primary and secondary time servers used by the NIST Internet time service. The secondary server is selected from a different geographic region than the primary server." - }, - { - "id": "sc-45.1_fr_smt.2", - "name": "item", - "props": [ - { - "name": "label", - "value": "Requirement:" - } - ], - "prose": "The service provider synchronizes the system clocks of network computers that run operating systems other than Windows to the Windows Server Domain Controller emulator or to the same time source for that server." - }, - { - "id": "sc-45.1_fr_gdn.1", - "name": "guidance", - "props": [ - { - "name": "label", - "value": "Guidance:" - } - ], - "prose": "Synchronization of system clocks improves the accuracy of log analysis." - } - ] + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sr-11.1_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." } ] } ] }, { - "control-id": "si-4", + "control-id": "sr-11.2", "adds": [ { - "position": "ending", - "by-id": "si-4_smt", - "parts": [ + "position": "starting", + "by-id": "sr-11.2_obj", + "props": [ { - "id": "si-4_fr", - "name": "item", - "title": "SI-4 Additional FedRAMP Requirements and Guidance", - "parts": [ - { - "id": "si-4_fr_gdn.1", - "name": "guidance", - "props": [ - { - "name": "label", - "value": "Guidance:" - } - ], - "prose": "See US-CERT Incident Response Reporting Guidelines." - } - ] + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sr-11.2_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." } ] } ] }, { - "control-id": "si-4.5", + "control-id": "sr-12", "adds": [ { - "position": "ending", - "by-id": "si-4.5_smt", - "parts": [ + "position": "starting", + "by-id": "sr-12_obj", + "props": [ { - "id": "si-4.5_fr", - "name": "item", - "title": "SI-4 (5) Additional FedRAMP Requirements and Guidance", - "parts": [ - { - "id": "si-4.5_fr_gdn.1", - "name": "guidance", - "props": [ - { - "name": "label", - "value": "Guidance:" - } - ], - "prose": "In accordance with the incident response plan." - } - ] + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sr-12_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." } ] } ] }, { - "control-id": "si-4.10", + "control-id": "sr-2", "adds": [ { - "position": "ending", - "by-id": "si-4.10_smt", - "parts": [ + "position": "starting", + "by-id": "sr-2_obj.a-1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sr-2_obj.a-2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sr-2_obj.a-3", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sr-2_obj.a-4", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sr-2_obj.a-5", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sr-2_obj.a-6", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sr-2_obj.a-7", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sr-2_obj.a-8", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sr-2_obj.a-9", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sr-2_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sr-2_obj.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sr-2_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "sr-2_smt.b", + "props": [ { - "id": "si-4.10_fr", - "name": "item", - "title": "SI-4 (10) Additional FedRAMP Requirements and Guidance", - "parts": [ - { - "id": "si-4.10_fr_smt.1", - "name": "item", - "props": [ - { - "name": "label", - "value": "Requirement:" - } - ], - "prose": "The service provider must support Agency requirements to comply with M-21-31 (https://www.whitehouse.gov/wp-content/uploads/2021/08/M-21-31-Improving-the-Federal-Governments-Investigative-and-Remediation-Capabilities-Related-to-Cybersecurity-Incidents.pdf) and M-22-09 (https://www.whitehouse.gov/wp-content/uploads/2022/01/M-22-09.pdf)." - } - ] + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." } ] - } - ] - }, - { - "control-id": "si-5", - "adds": [ + }, { - "position": "ending", - "by-id": "si-5_smt", - "parts": [ + "position": "starting", + "by-id": "sr-2_smt.c", + "props": [ { - "id": "si-5_fr_smt.1", - "name": "item", - "title": "SI-5 Additional FedRAMP Requirements and Guidance", - "props": [ - { - "name": "label", - "value": "Requirement:" - } - ], - "prose": "Service Providers must address the CISA Emergency and Binding Operational Directives applicable to their cloud service offering per FedRAMP guidance. This includes listing the applicable directives and stating compliance status." + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." } ] } ] }, { - "control-id": "si-8", + "control-id": "sr-2.1", "adds": [ { - "position": "ending", - "by-id": "si-8_smt", - "parts": [ + "position": "starting", + "by-id": "sr-2.1_obj", + "props": [ { - "id": "si-8_fr", - "name": "item", - "title": "SI-8 Additional FedRAMP Requirements and Guidance", - "parts": [ - { - "id": "si-8_fr_gdn.1", - "name": "guidance", - "props": [ - { - "name": "label", - "value": "Guidance:" - } - ], - "prose": "When CSO sends email on behalf of the government as part of the business offering, Control Description should include implementation of Domain-based Message Authentication, Reporting & Conformance (DMARC) on the sending domain for outgoing messages as described in DHS Binding Operational Directive (BOD) 18-01.\n\nhttps://cyber.dhs.gov/bod/18-01/" - }, - { - "id": "si-8_fr_gdn.2", - "name": "guidance", - "props": [ - { - "name": "label", - "value": "Guidance:" - } - ], - "prose": "CSPs should confirm DMARC configuration (where appropriate) to ensure that policy=reject and the rua parameter includes reports@dmarc.cyber.dhs.gov. DMARC compliance should be documented in the SI-08 control implementation solution description, and list the FROM: domain(s) that will be seen by email recipients." - } - ] + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" } ] - } - ] - }, - { - "control-id": "si-10", - "adds": [ + }, { - "position": "ending", - "by-id": "si-10_smt", - "parts": [ + "position": "starting", + "by-id": "sr-2.1_smt", + "props": [ { - "id": "si-10_fr", - "name": "item", - "title": "SI-10 Additional FedRAMP Requirements and Guidance", - "parts": [ - { - "id": "si-10_fr_smt.1", - "name": "item", - "props": [ - { - "name": "label", - "value": "Requirement:" - } - ], - "prose": "Validate all information inputs and document any exceptions" - } - ] + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." } ] } @@ -6074,6 +42306,176 @@ ] } ] + }, + { + "position": "starting", + "by-id": "sr-3_obj.a-1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sr-3_obj.a-2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sr-3_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sr-3_obj.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sr-3_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "sr-3_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "sr-3_smt.c", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "sr-5", + "adds": [ + { + "position": "starting", + "by-id": "sr-5_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sr-5_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] } ] }, @@ -6103,6 +42505,40 @@ ] } ] + }, + { + "position": "starting", + "by-id": "sr-6_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "TEST", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sr-6_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] } ] }, @@ -6132,6 +42568,40 @@ ] } ] + }, + { + "position": "starting", + "by-id": "sr-8_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sr-8_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] } ] }, @@ -6161,6 +42631,79 @@ ] } ] + }, + { + "position": "starting", + "by-id": "sr-9_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sr-9_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + } + ] + }, + { + "control-id": "sr-9.1", + "adds": [ + { + "position": "starting", + "by-id": "sr-9.1_obj", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sr-9.1_smt", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] } ] }, @@ -6190,6 +42733,143 @@ ] } ] + }, + { + "position": "starting", + "by-id": "sr-11_obj.a-1", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sr-11_obj.a-2", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sr-11_obj.a-3", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sr-11_obj.a-4", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sr-11_obj.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "EXAMINE", + "class": "fedramp" + }, + { + "name": "method", + "ns": "https://fedramp.gov/ns/oscal", + "value": "INTERVIEW", + "class": "fedramp" + } + ] + }, + { + "position": "starting", + "by-id": "sr-11_smt.a", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] + }, + { + "position": "starting", + "by-id": "sr-11_smt.b", + "props": [ + { + "name": "response-point", + "ns": "https://fedramp.gov/ns/oscal", + "value": "You must fill in this response point." + } + ] } ] } @@ -6223,17 +42903,17 @@ }, { "uuid": "051a77c1-b61d-4995-8275-dacfe688d510", - "title": "NIST Special Publication (SP) 800-53", + "title": "NIST Special Publication (SP) 800-53 revision 5", "props": [ { "name": "version", - "value": "Revision 5" + "value": "5.1.1" } ], "rlinks": [ { - "href": "https://raw.githubusercontent.com/usnistgov/oscal-content/main/nist.gov/SP800-53/rev5/json/NIST_SP-800-53_rev5_catalog.json", - "media-type": "application/json" + "href": "NIST_SP-800-53_rev5_catalog.json", + "media-type": "application/oscal+json" } ] }