During Telos analysis of the SAP and SAR models, manual process and OSCAL process, identified 3 Duplicate response points. It looks like there is an error in the OSCAL model and the Assessment Procedures where response points were excluded due to naming convention inconsistencies.
This is a ...
[ X ] fix - Something needs to be different.
[ X ] enhancement - Something could be better.
[ X ] investigation - Something needs to be investigated further.
This relates to ...
[ X ] the FedRAMP SAP OSCAL Template (JSON or XML Format)
[ X ] the FedRAMP SAR OSCAL Template (JSON or XML Format)
[ X ] the FedRAMP POA&M OSCAL Template (JSON or XML Format)
The Following FedRAMP response points and assessment procedures should be updated as follows:
<html xmlns:v="urn:schemas-microsoft-com:vml"
xmlns:o="urn:schemas-microsoft-com:office:office"
xmlns:x="urn:schemas-microsoft-com:office:excel"
xmlns="http://www.w3.org/TR/REC-html40">
Action Item
During Telos analysis of the SAP and SAR models, manual process and OSCAL process, identified 3 Duplicate response points. It looks like there is an error in the OSCAL model and the Assessment Procedures where response points were excluded due to naming convention inconsistencies.
This is a ...
This relates to ...
NOTE: For issues related to the OSCAL syntax itself, please create or add to an issue in the NIST OSCAL Repository.
Describe the problem or enhancement
The Following FedRAMP response points and assessment procedures should be updated as follows:
FedRAMP OSCAL | Assessment Procedure | Recommended Response Points -- | -- | -- CM-4(1)[1] | CM-4(1).1 | CM-4(1)[2][b] CM-4(1)[1] | CM-4(1).1 | CM-4(1)[2][b] CM-4(1)[1] | CM-4(1).1 | CM-4(1)[2][b]<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:x="urn:schemas-microsoft-com:office:excel" xmlns="http://www.w3.org/TR/REC-html40">