GSA / fedramp-automation

FedRAMP Automation
https://www.fedramp.gov/using-the-fedramp-oscal-resources-and-templates/
Other
277 stars 85 forks source link

Penetration Test Plan Requirement #452

Open Telos-sa opened 1 year ago

Telos-sa commented 1 year ago

Action Item

This is a ...

This relates to ...

Describe the problem or enhancement

There is a requirement in the SAP guide and template for the Penetration Testing Plan and Methodology - however, most of the data required of it is already in the SAP. There is no template or guidance of format and it is unclear what the significant differences are, making the required data seems redundant.

Goals:

There are a couple potential solutions. One would be to provide information on the differences in the guide for the Penetration Test Plan and a template or guidance on the expected format. If the data is mostly or all redundant, it may not need to be a requirement and the additional information could instead be added to the OSCAL data model.

Dependencies:

No dependencies on previous issues.

Acceptance Criteria