GSA / fedramp-automation

FedRAMP Automation
https://www.fedramp.gov/using-the-fedramp-oscal-resources-and-templates/
Other
277 stars 85 forks source link

SAP validation error for controls in the associated SSP #449

Closed Telos-sa closed 1 year ago

Telos-sa commented 1 year ago

Describe the bug

When validating a FedRAMP OSCAL SAP, an error appears for included controls not being in the associated SSP when only the SAP has been uploaded.

What version of OSCAL are you using?

OSCAL version 1.0.0

How do we replicate the issue?

  1. Run the following SAP through the validator: FedRAMP Example Project_OSCAL_SAP.json.zip

  2. The following error appears in 4.1:

    Screenshot 2023-07-18 at 16 43 12

Expected behavior (i.e. solution)

Assertions involving the associated SSP should not be marked as errors when only the SAP is uploaded. Passing this test would require a full package with artifacts to be able to perform a cross reference.

volpet2014 commented 1 year ago

Automation Team agrees and has relaxed this to a warning in OEAW portal validations. Updates to fedramp-automation GH pending for this relaxation.