Inherited Control Description Guidance Mismatched with Validations #589
Labels
bug
Something isn't working
documentation
Improvements or additions to documentation
Scope: Guides
Scope: Validation
This relates to ...
What happened?
According to the Guide to OSCAL-based FedRAMP System Security Plans (SSP), an inherited control implementation description is optional, however according to NIST a description property is required on an 'inherited' object. Furthermore, the FedRAMP validations requires that an inherited control implementation description must contain at least 32 words.
Relevant log output
No response
How do we replicate this issue?
Where, exactly?
FedRAMP validation rule:
https://github.com/GSA/fedramp-automation/blob/master/src/validations/rules/rev5/ssp.sch#L3514-L3521
NIST reference:
https://pages.nist.gov/OSCAL-Reference/models/v1.0.4/system-security-plan/json-reference/#/system-security-plan/control-implementation/implemented-requirements/by-components/inherited
Guide to OSCAL-based FedRAMP System Security Plans (SSP):
![image](https://private-user-images.githubusercontent.com/143224415/326603504-20a9effd-2586-495e-bcad-5652a130b0a7.png?jwt=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpc3MiOiJnaXRodWIuY29tIiwiYXVkIjoicmF3LmdpdGh1YnVzZXJjb250ZW50LmNvbSIsImtleSI6ImtleTUiLCJleHAiOjE3MjA1ODYyMjQsIm5iZiI6MTcyMDU4NTkyNCwicGF0aCI6Ii8xNDMyMjQ0MTUvMzI2NjAzNTA0LTIwYTllZmZkLTI1ODYtNDk1ZS1iY2FkLTU2NTJhMTMwYjBhNy5wbmc_WC1BbXotQWxnb3JpdGhtPUFXUzQtSE1BQy1TSEEyNTYmWC1BbXotQ3JlZGVudGlhbD1BS0lBVkNPRFlMU0E1M1BRSzRaQSUyRjIwMjQwNzEwJTJGdXMtZWFzdC0xJTJGczMlMkZhd3M0X3JlcXVlc3QmWC1BbXotRGF0ZT0yMDI0MDcxMFQwNDMyMDRaJlgtQW16LUV4cGlyZXM9MzAwJlgtQW16LVNpZ25hdHVyZT0wOTA5ZjUyZjg3Y2NjYjhhODJhZTZkNjJkMTM4ODdlODE4ZDVlNDE4MmNkYmE1YWVjZDQ1MDZjYmM0NmM1ZTgyJlgtQW16LVNpZ25lZEhlYWRlcnM9aG9zdCZhY3Rvcl9pZD0wJmtleV9pZD0wJnJlcG9faWQ9MCJ9.xw1taq7cllGcHjGDJg0I_cvHqOiapBZ2jgoNJhk2ndE)
Other relevant details
FedRAMP should follow the NIST OCSAL guidance for inherited controls descriptions making them required. FedRAMP should then remove the requirement for a minimum of 32 words in the control implementation description for inherited controls (even the example provided is not 32 words in length).
The text was updated successfully, but these errors were encountered: