GSA / fedramp-automation

FedRAMP Automation
https://www.fedramp.gov/using-the-fedramp-oscal-resources-and-templates/
Other
293 stars 89 forks source link

Clarification of Requirements for import-profile #213

Closed telosBA closed 1 year ago

telosBA commented 2 years ago

NOTE: For feedback related to the OSCAL syntax itself, please create or add to an issue in the NIST OSCAL Repository.

FedRAMP SSP Guide p.8 FedRAMP-SSP-OSCAL-Template.xml Lines 502-508

The profile we are using includes more controls than that of the FedRAMP Template Baseline.

What import profile is expected? Are we able to reference the file path to our own profile in order to capture all controls? Is the baseline XML file required to be included in the export?

david-waltermire commented 2 years ago

OSCAL is flexible here. Not sure if FedRAMP wants to be more specific in what is allowed for FedRAMP.