Replies: 1 comment 1 reply
-
Our focus for SAP has been on creating an MVP for the schema and FedRAMP use-case first. For the FedRAMP use-case, they have identified specific objectives with response points, which should be the focus for the test plan (think their document SRTM). The local definitions allows activities to be related to controls and/or objectives and tied to tasks, included in the mockup below. However, for predefined response points and assessment objectives, there is no easy way to link the activities without creating local definitions. Would love to be able to associate the objectives to the specific assessment subjects in the SAP without having to create specific procedures beyond what was defined in the baseline-profile. Below, created the links to tasks with props, but a defined element would be ideal. It should be optional to cover the multitude of use cases, but that would be a great element to show the planned coverage of the test objectives/controls across the different subjects.
|
Beta Was this translation helpful? Give feedback.
-
This is a repeat from the gitter chat but here is the rundown:
I am working within my organization to utilize OSCAL, and I am running into a simple issue but one I am not having much luck resolving based on the OSCAL Assessment Plan outline. When I am trying to test multiple controls based off of my AP, how would I separate the actions (via multiple activities and/or tasks) so each control would utilize a separate script to assess that control. I thought maybe an activity for each control would be the obvious answer, but that would then require another task to associate for every activity, and I just wanted to make sure I was approaching this correctly before I go too deep and add a ton of new lines when the answer might be much simpler.
Beta Was this translation helpful? Give feedback.
All reactions