cloud-gov / product

Program-level artifacts, workflow and issues for cloud.gov
Creative Commons Zero v1.0 Universal
30 stars 15 forks source link

Adequately document SA controls in SSP #271

Closed mogul closed 7 years ago

mogul commented 8 years ago

In order for compliance reviewers to understand our system, we need to update this family of control statements to explain our system (and policies and procedures) in more precise and thorough detail.

Setup

Read the guidance in HOWTO update the SSP before working on this.

Acceptance criteria

SA-1:

SA-2:

SA-3:

SA-9:

SA-9 (1):

SA-9 (2):

SA-9 (4):

SA-9 (5):

SA-10:

SA-11:

SA-11 (1):

SA-11 (2):

SA-11 (8):

SA overall:

Implementation guidance

During grooming, take items from the following and list them as specific tasks above.

brittag commented 7 years ago

This needs a lot of subject matter expertise about planning at a high level for cloud.gov - we suspect some of this is handled by GSA/18F or even 18F Products & Platforms.

NoahKunin commented 7 years ago

I'll take it from here.

mogul commented 7 years ago

Closing as "what we did on SA during PI7"; afawk SA is done.