Skip to content

Recording Evidence and Status of a Satisfied Control? #1074

Answered by aj-stein-nist
flickerfly asked this question in Q&A
Discussion options

You must be logged in to vote

That's a great question. I guess it really depends on what specifically you are documenting that "tested for and confirmed compliance to a specific control." Do you mean what you had done at the level of description in 800-53 assessment procedures (like 800-53A's objectives and interview criteria for "[determining] the frequency of baseline configuration review and update is defined by [interviewing] organizational personnel with configuration management responsibilities" or the details supporting that objective and methods?

I am not sure it will be super helpful, but the FedRAMP Guide to OSCAL-based SARs show how some of that information would look in existing FedRAMP documents (that mig…

Replies: 1 comment 9 replies

Comment options

You must be logged in to vote
9 replies
@iMichaela
Comment options

@iMichaela
Comment options

@iMichaela
Comment options

@flickerfly
Comment options

@aj-stein-nist
Comment options

Answer selected by david-waltermire
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
3 participants