By Stephen Banghart, technical coordinator, OSCAL Foundation
As the General Services Administration continues with the FedRAMP 20x project, messaging out to industry has been clear – FedRAMP will be requiring machine-readable language to express compliance status with FedRAMP’s RFC-0006 Key Security Indicators (KSIs). When these KSIs were published, there were doubts from FedRAMP leadership that existing automation solutions could adequately express the requirements and implementations of these controls.
As a strong supporter of the OSCAL machine-readable language, the OSCAL Foundation would like to set the record straight. OSCAL was designed from the ground up to be framework agnostic and does not depend on NIST 800-53 or any other control catalog. Its layered architecture offers flexibility to adopt OSCAL incrementally, as needed.
FedRAMP’s RFC-0006 KSIs are easily modeled in OSCAL, making them machine-readable and automation-ready, as demonstrated in this proof-of-concept created by Foundation members.
OSCAL provides a flexible and innovative friendly framework for communicating about and automating around KSIs, with the benefit of having years of work completed by government and industry contributors. The OSCAL Foundation and its members are dedicated to carrying on work to improve and expand OSCAL, and hope that FedRAMP can take advantage of the possibilities that OSCAL opens today.
As Pete Waterman said at the recent FedRAMP 20x fireside chat with the Alliance for Digital Innovation (ADI) – “industry leads the way.” The Foundation believes that industry is doing just that.
The OSCAL Foundation has published an open letter to Pete Waterman and the FedRAMP PMO further expanding on the thoughts expressed in this blog post.