Skip to content
This repository has been archived by the owner on Dec 12, 2023. It is now read-only.

As a FedRAMP PMO member, to have confidence that validations are easily usable by stakeholders outside of FedRAMP, I want to see one successful integration with OSCAL tooling developed by an external stakeholder outside of FedRAMP. #55

Closed
3 tasks
ohsh6o opened this issue Mar 31, 2021 · 1 comment
Labels
duplicate This issue or pull request already exists obsolete

Comments

@ohsh6o
Copy link

ohsh6o commented Mar 31, 2021

Context:

An important open question from the 10x Phase Two Discovery Phase is the viability and level of effort of integrating the FedRAMP validations with one or more tools external to FedRAMP, with particular focus on language runtimes and ecosystems with different levels of XML and XSLT tooling maturity.

Acceptance Criteria:

  • A proposed integration plan with the FedRAMP PMO.
  • An external partner with a tentative documented roadmap.
  • Proof-of-concept code integration with the external tool using the FedRAMP Validations to validate a system security plan
@ohsh6o ohsh6o added the epic label Mar 31, 2021
@ohsh6o
Copy link
Author

ohsh6o commented Mar 31, 2021

One potential integration point is with the IBM Trestle team. We talked to them in P2 and it led to this oscal-compass/compliance-trestle#249. This is one potential partnership we can investigate. There are others, but this one had a concrete outcome. We should document others that are relevant to stories and tasks connected to this epic.

@ohsh6o ohsh6o added duplicate This issue or pull request already exists obsolete and removed epic labels Jul 27, 2021
@ohsh6o ohsh6o closed this as completed Jul 27, 2021
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
duplicate This issue or pull request already exists obsolete
Projects
None yet
Development

No branches or pull requests

1 participant