Skip to content

SSP system characteristics needs to be expanded to support multiple frameworks #34

@nikitawootten-nist

Description

@nikitawootten-nist

Problem Statement

We are interested in reworking the System Security Plan (SSP)'s system characteristics to support categorization frameworks other then fips-199. Currently the system characteristics assemblies expect users to record categorization data for a given information-type following the CIA triad of impacts and expects the user to respond with fips-199-low, -moderate, or -high. This design does not allow for users to record impacts that do not fit into the CIA triad, such as having dedicated privacy impact values. Additionally, authors writing additional OSCAL constraints would benefit from a field communicating the system categorization framework.

This issue was originally raised during the OSCAL Workshop, and in the issue usnistgov/OSCAL#1795.

Metadata

Metadata

Assignees

No one assigned

    Labels

    Step 1 - InitiationThis research effort issue requires review and consideration.

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions