GSA / fedramp-automation

FedRAMP Automation
https://www.fedramp.gov/using-the-fedramp-oscal-resources-and-templates/
Other
254 stars 74 forks source link

4.3 Recommended and Planned Remediation Rule #460

Open rachkim00 opened 11 months ago

rachkim00 commented 11 months ago

Extended Description As a CSP, creating OSCAL based POAM based on the legacy POAM data, I want to:

Context: Currently, all types of remediation plan is melted in ‘Overall remediation Plan’. This requires significant manual work to sort this data and categorize them for each lifecycle status (recommended, planned, completed) in 'response' assembly. Also, there are cases where what the tool and 3PAO recommended is what the CSP is planned. In this case, this creates duplicate work for the CSP to clone the data just to assign different lifecycle. Also, it will look confusing in OSCAL file to have multiple same responses but different lifecycle status.

Suggest to remove the rule: Guide to OSCAL-based FedRAMP Plan of Action and Milestones (POA&M) §4.3 - A risk must have a planned response & A risk must have a recommendation response. Or simply update from 'Errors' to 'Information' or 'Warning'.

Preconditions

Acceptance Criteria

Story Tasks

Definition of Done

rachkim00 commented 9 months ago

Hello- following up to see if there has been any updates/progress on this item.