18F / fedramp-automation

FedRAMP Automation
https://federalist-2372d2fd-fc94-42fe-bcc7-a8af4f664a51.app.cloud.gov/site/18f/fedramp-automation/
Other
16 stars 6 forks source link

Pre-Schematron Structured Validation Rule Data #65

Closed mike-stern closed 3 years ago

mike-stern commented 3 years ago

As as ASAP p3 developer, I would like a machine consumable list of fedRAMP authorization rules that will eventually manifest as OSCAL rules, so that I can ensure traceability from business process to automation framework.

Context:

Onboarded 10x developers and FedRAMP stakeholders have discussed a need for more structured information than what was provided previously to the 10x ASAP P2 Team last year in the form of the Agency Review Report Template. The current developers would like a more intentional, structured precursor document with a listing of rules that can be reviewed and modified over time. Once this precursor document is established, the developers would like to investigate more directly mapping it to the code outputs (in later development efforts, perhaps after Sprint 2), perhaps using it to programmatically generate tests and/or the validation code itself.

Nice to have: A rendition of this structured precursor document into HTML or an alternative presentation format with the FART and JAB team would be ideal.

Acceptance:

Acceptance Criteria:

Dependencies:

ohsh6o commented 3 years ago

Before reformatting this, this seems to be a dupe of 18F/fedramp-automation#83, which is now in sprint. This might have been a blooper on my part. Will discuss with Mike in next backlog review meeeting.

ohsh6o commented 3 years ago

Was confused and flipped since #85 was in Sprint 2 closing this one as discussed in review.