From 4398796237deaa97a88083d19ca6577a5353dc65 Mon Sep 17 00:00:00 2001
From: Gabeblis
Date: Fri, 13 Dec 2024 17:29:19 +0000
Subject: [PATCH] wip
---
.../awesome-cloud/xml/AwesomeCloudSSP1.xml | 68 +-
.../awesome-cloud/xml/AwesomeCloudSSP2.xml | 70 +-
.../FedRAMP_rev5_HIGH-baseline_profile.xml | 8328 ++++++++---------
.../FedRAMP_rev5_LI-SaaS-baseline_profile.xml | 512 +-
.../xml/FedRAMP_rev5_LOW-baseline_profile.xml | 4838 +++++-----
...FedRAMP_rev5_MODERATE-baseline_profile.xml | 7310 +++++++--------
.../ssp/xml/fedramp-ssp-example.oscal.xml | 1542 +--
.../rev5/resources/xml/FedRAMP_extensions.xml | 24 +-
.../rev5/resources/xml/fedramp_threats.xml | 4 +-
.../rev5/resources/xml/fedramp_values.xml | 32 +-
.../rev5/resources/xml/information-types.xml | 4 +-
.../poam/xml/FedRAMP-POAM-OSCAL-Template.xml | 44 +-
.../sap/xml/FedRAMP-SAP-OSCAL-Template.xml | 234 +-
.../sar/xml/FedRAMP-SAR-OSCAL-Template.xml | 84 +-
.../ssp/xml/FedRAMP-SSP-OSCAL-Template.xml | 262 +-
.../content/fedramp-tailoring-profile.xml | 2 +-
.../content/profile-all-INVALID.xml | 4 +-
.../content/ssp-attachment-type-INVALID.xml | 2 +-
...hentication-method-has-remarks-INVALID.xml | 2 +-
.../ssp-authorization-type-INVALID.xml | 2 +-
.../ssp-boundary-diagram-link-VALID.xml | 42 +-
...nent-has-authentication-method-INVALID.xml | 18 +-
...-control-implementation-status-INVALID.xml | 2 +-
...sp-control-implementation-status-VALID.xml | 66 +-
...nal-system-nature-of-agreement-INVALID.xml | 4 +-
...neous-implemented-requirements-INVALID.xml | 6 +-
...ully-operational-date-is-valid-INVALID.xml | 2 +-
...-fully-operational-date-type-INVALID-1.xml | 2 +-
...-fully-operational-date-type-INVALID-2.xml | 2 +-
...-authenticator-assurance-level-INVALID.xml | 2 +-
...ndary-diagram-link-href-target-VALID-1.xml | 38 +-
...-configuration-management-plan-INVALID.xml | 2 +-
...-flow-diagram-link-href-target-VALID-1.xml | 38 +-
...has-federation-assurance-level-INVALID.xml | 2 +-
...p-has-identity-assurance-level-INVALID.xml | 2 +-
...ssp-has-incident-response-plan-INVALID.xml | 2 +-
...mation-system-contingency-plan-INVALID.xml | 2 +-
.../ssp-has-inventory-items-INVALID.xml | 2 +-
...cture-diagram-link-href-target-VALID-1.xml | 38 +-
.../ssp-has-rules-of-behavior-INVALID.xml | 2 +-
.../content/ssp-has-user-guide-INVALID.xml | 2 +-
...le-resolves-to-fedramp-content-VALID-1.xml | 34 +-
...le-resolves-to-fedramp-content-VALID-2.xml | 38 +-
...le-resolves-to-fedramp-content-VALID-3.xml | 36 +-
...direction-incoming-has-ipv-uri-INVALID.xml | 4 +-
...undary-component-has-direction-INVALID.xml | 8 +-
.../ssp-interconnection-direction-INVALID.xml | 4 +-
.../ssp-interconnection-direction-VALID.xml | 62 +-
.../ssp-interconnection-security-INVALID.xml | 4 +-
.../ssp-interconnection-security-VALID.xml | 62 +-
...ization-has-valid-impact-level-INVALID.xml | 2 +-
...orization-has-valid-impact-level-VALID.xml | 44 +-
...horization-nature-of-agreement-INVALID.xml | 2 +-
...-misplaced-response-components-INVALID.xml | 2 +-
...sp-missing-response-components-INVALID.xml | 6 +-
...t-has-connection-security-prop-INVALID.xml | 4 +-
...sponsible-role-references-user-INVALID.xml | 2 +-
.../content/ssp-privilege-level-INVALID.xml | 2 +-
.../ssp-profile-response-point-INVALID.xml | 4 +-
...p-resource-has-base64-or-rlink-INVALID.xml | 2 +-
.../ssp-resource-has-title-INVALID.xml | 2 +-
...sp-responsible-party-is-person-INVALID.xml | 2 +-
...rty-prepared-by-location-valid-VALID-1.xml | 38 +-
...ty-prepared-for-location-valid-VALID-1.xml | 38 +-
...saas-has-leveraged-authorization-VALID.xml | 38 +-
.../content/ssp-scan-type-INVALID.xml | 2 +-
...unique-inventory-item-asset-id-INVALID.xml | 4 +-
.../ssp-user-authentication-INVALID.xml | 18 +-
.../ssp-user-privilege-level-INVALID.xml | 2 +-
.../ssp-user-sensitivity-level-INVALID.xml | 2 +-
.../fedramp-external-allowed-values.xml | 26 +-
.../fedramp-external-constraints.xml | 36 +-
.../unit-tests/has-system-id-FAIL.yaml | 2 +-
.../unit-tests/has-system-id-PASS.yaml | 2 +-
src/validations/styleguides/STYLE.md | 14 +-
75 files changed, 12096 insertions(+), 12096 deletions(-)
diff --git a/src/content/awesome-cloud/xml/AwesomeCloudSSP1.xml b/src/content/awesome-cloud/xml/AwesomeCloudSSP1.xml
index ed6d0b95a..6921615ca 100644
--- a/src/content/awesome-cloud/xml/AwesomeCloudSSP1.xml
+++ b/src/content/awesome-cloud/xml/AwesomeCloudSSP1.xml
@@ -111,7 +111,7 @@
-
+
@@ -191,7 +191,7 @@
-
+
system-owner
GRC Access (Read Only)
@@ -203,7 +203,7 @@
-
+
authorizing-official
GRC Access (Read Only)
@@ -215,7 +215,7 @@
-
+
system-poc-management
GRC Access (Read Only)
@@ -227,7 +227,7 @@
-
+
system-poc-technical
GRC Access
@@ -239,7 +239,7 @@
-
+
system-poc-other
GRC Access
@@ -251,7 +251,7 @@
-
+
information-system-security-officer
Managerial Access
@@ -263,7 +263,7 @@
-
+
authorizing-official-poc
Managerial Access
@@ -275,7 +275,7 @@
-
+
sys-admin
Administrative Access
@@ -305,7 +305,7 @@
-
+
This is an appliance.
@@ -332,7 +332,7 @@
-
+
This is an appliance.
@@ -359,7 +359,7 @@
-
+
This is an appliance.
@@ -388,7 +388,7 @@
-
+
@@ -409,7 +409,7 @@
-
+
@@ -430,7 +430,7 @@
-
+
@@ -449,7 +449,7 @@
-
+
This is an appliance.
@@ -478,7 +478,7 @@
-
+
@@ -499,7 +499,7 @@
-
+
@@ -520,7 +520,7 @@
-
+
@@ -541,7 +541,7 @@
-
+
@@ -562,7 +562,7 @@
-
+
@@ -583,7 +583,7 @@
-
+
@@ -604,7 +604,7 @@
-
+
@@ -617,8 +617,8 @@
-
-
+
+
Access Control policy is disseminated to all personnel with access to the system. The Access Control procedures are disseminated to the System Owner, Information System Security Officer, and all personnel with signifigant security responsibilities.
@@ -661,8 +661,8 @@
-
-
+
+
the information contained in the FedRAMP Integrated Inventory Workbook Template
@@ -760,43 +760,43 @@
Laws and Regulations
-
+
User Guide
-
+
Rules of Behavior
-
+
Contingency Plan
-
+
Configuration Management Plan
-
+
Incident Response Plan
-
+
Separation of Duties Matrix
-
+
diff --git a/src/content/awesome-cloud/xml/AwesomeCloudSSP2.xml b/src/content/awesome-cloud/xml/AwesomeCloudSSP2.xml
index 9da0b5937..59165e473 100644
--- a/src/content/awesome-cloud/xml/AwesomeCloudSSP2.xml
+++ b/src/content/awesome-cloud/xml/AwesomeCloudSSP2.xml
@@ -111,7 +111,7 @@
-
+
@@ -179,7 +179,7 @@
-
+
system-owner
GRC Access (Read Only)
@@ -191,7 +191,7 @@
-
+
authorizing-official
GRC Access (Read Only)
@@ -203,7 +203,7 @@
-
+
system-poc-management
GRC Access (Read Only)
@@ -215,7 +215,7 @@
-
+
system-poc-technical
GRC Access
@@ -227,7 +227,7 @@
-
+
system-poc-other
GRC Access
@@ -239,7 +239,7 @@
-
+
information-system-security-officer
Managerial Access
@@ -250,7 +250,7 @@
-
+
authorizing-official-poc
Managerial Access
@@ -261,7 +261,7 @@
-
+
sys-admin
Administrative Access
@@ -289,7 +289,7 @@
-
+
This is an appliance.
@@ -316,7 +316,7 @@
-
+
This is an appliance.
@@ -343,7 +343,7 @@
-
+
This is an appliance.
@@ -372,7 +372,7 @@
-
+
@@ -393,7 +393,7 @@
-
+
@@ -414,7 +414,7 @@
-
+
@@ -433,7 +433,7 @@
-
+
This is an appliance.
@@ -462,7 +462,7 @@
-
+
@@ -483,7 +483,7 @@
-
+
@@ -504,7 +504,7 @@
-
+
@@ -525,7 +525,7 @@
-
+
@@ -546,7 +546,7 @@
-
+
@@ -567,7 +567,7 @@
-
+
@@ -588,7 +588,7 @@
-
+
@@ -609,7 +609,7 @@
-
+
@@ -630,7 +630,7 @@
-
+
@@ -651,7 +651,7 @@
-
+
@@ -662,8 +662,8 @@
-
-
+
+
the information contained in the FedRAMP Integrated Inventory Workbook Template
@@ -755,43 +755,43 @@
Laws and Regulations
-
+
User Guide
-
+
Rules of Behavior
-
+
Contingency Plan
-
+
Configuration Management Plan
-
+
Incident Response Plan
-
+
Separation of Duties Matrix
-
+
diff --git a/src/content/rev5/baselines/xml/FedRAMP_rev5_HIGH-baseline_profile.xml b/src/content/rev5/baselines/xml/FedRAMP_rev5_HIGH-baseline_profile.xml
index 4bab812a2..b09c44342 100644
--- a/src/content/rev5/baselines/xml/FedRAMP_rev5_HIGH-baseline_profile.xml
+++ b/src/content/rev5/baselines/xml/FedRAMP_rev5_HIGH-baseline_profile.xml
@@ -2404,471 +2404,471 @@
-
-
-
+
+
+
-
-
-
+
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
This response must address all control sub-statement requirements.
-
+
-
+
This response must address all control sub-statement requirements.
-
-
-
+
+
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
-
-
+
+
+
-
+
-
-
-
+
+
+
-
+
-
-
-
+
+
+
-
-
+
+
-
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
-
-
+
+
+
-
+
-
-
-
+
+
+
-
+
-
+
-
-
-
+
+
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
+
+
-
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
-
-
+
+
+
-
+
-
-
-
+
+
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
-
-
+
+
+
-
+
-
-
+
+
-
-
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
-
-
+
+
+
-
+
-
+
-
-
-
+
+
+
-
+
-
+
-
-
-
+
+
+
-
+
-
+
-
-
+
+
-
+
-
+
@@ -2890,52 +2890,52 @@
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
+
-
+
-
-
-
+
+
+
-
+
-
+
@@ -2949,52 +2949,52 @@
-
-
-
+
+
+
-
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
+
-
+
@@ -3008,15 +3008,15 @@
-
-
-
+
+
+
-
+
-
+
@@ -3034,136 +3034,136 @@
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
-
-
+
+
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
+
-
-
-
+
+
+
-
+
-
+
-
-
-
+
+
+
-
+
-
-
-
+
+
+
-
+
@@ -3177,12 +3177,12 @@
-
-
-
+
+
+
-
+
@@ -3196,62 +3196,62 @@
-
-
+
+
-
-
+
+
-
+
-
+
-
-
-
+
+
+
-
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
-
-
+
+
+
-
+
-
+
@@ -3265,86 +3265,86 @@
-
-
-
+
+
+
-
+
-
+
-
-
-
+
+
+
-
-
+
+
-
+
-
+
-
-
-
+
+
+
-
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
-
-
+
+
+
-
+
-
+
-
-
-
+
+
+
-
+
@@ -3358,20 +3358,20 @@
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
@@ -3397,43 +3397,43 @@
-
-
-
+
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
-
+
+
+
-
-
+
+
-
+
-
+
-
+
@@ -3450,319 +3450,319 @@
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
This response must address all control sub-statement requirements.
-
+
-
+
This response must address all control sub-statement requirements.
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
+
-
-
-
+
+
+
-
+
-
-
-
+
+
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
-
-
+
+
+
-
-
+
+
-
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
This response must address all control sub-statement requirements.
-
+
-
+
This response must address all control sub-statement requirements.
-
-
-
+
+
+
-
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
+
+
-
+
-
+
-
+
-
+
-
-
-
+
+
+
-
+
-
+
-
-
-
+
+
+
-
+
-
+
@@ -3780,78 +3780,78 @@
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
+
+
-
-
-
+
+
+
-
-
+
+
-
+
-
+
-
+
-
+
-
+
-
+
-
-
-
+
+
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
@@ -3865,75 +3865,75 @@
-
-
-
+
+
+
-
+
-
+
-
-
-
+
+
+
-
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
-
-
+
+
+
-
+
-
+
-
-
-
+
+
+
-
+
-
+
@@ -3947,83 +3947,83 @@
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
+
-
-
-
+
+
+
-
+
-
+
-
-
-
+
+
+
-
+
-
+
-
-
-
+
+
+
-
+
-
+
-
-
-
+
+
+
-
+
-
+
@@ -4037,106 +4037,106 @@
-
-
-
+
+
+
-
+
-
+
-
-
-
+
+
+
-
+
-
+
-
-
-
-
+
+
+
+
-
-
-
+
+
+
-
+
-
+
-
-
-
+
+
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
-
-
+
+
+
-
+
@@ -4150,12 +4150,12 @@
-
-
-
+
+
+
-
+
@@ -4177,79 +4177,79 @@
-
-
-
+
+
+
-
+
-
+
-
-
-
+
+
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
This response must address all control sub-statement requirements.
-
+
-
+
This response must address all control sub-statement requirements.
@@ -4265,59 +4265,59 @@
-
-
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
+
+
-
-
+
+
-
+
-
+
-
+
-
+
-
+
-
+
@@ -4331,12 +4331,12 @@
-
-
-
+
+
+
-
+
@@ -4350,57 +4350,57 @@
-
-
-
+
+
+
-
+
-
-
-
+
+
+
-
+
-
-
-
+
+
+
-
-
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
-
-
+
+
+
-
+
@@ -4418,20 +4418,20 @@
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
@@ -4445,48 +4445,48 @@
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
+
+
-
+
-
+
-
+
-
+
-
+
@@ -4508,111 +4508,111 @@
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
-
-
+
+
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
@@ -4626,22 +4626,22 @@
-
-
-
+
+
+
-
+
-
-
-
+
+
+
-
+
@@ -4656,155 +4656,155 @@
-
-
-
+
+
+
-
+
-
+
-
-
-
+
+
+
-
-
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
This response must address all control sub-statement requirements.
-
+
-
+
This response must address all control sub-statement requirements.
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
+
+
-
+
-
+
-
+
@@ -4818,66 +4818,66 @@
-
-
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
-
-
+
+
+
-
+
-
-
+
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
@@ -4895,260 +4895,260 @@
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
+
+
-
-
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
+
-
+
-
+
-
-
-
+
+
+
-
+
-
-
-
+
+
+
-
+
-
-
-
+
+
+
-
+
-
-
-
+
+
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
-
-
+
+
+
-
+
-
-
-
+
+
+
-
+
-
+
-
-
+
+
-
-
-
+
+
+
-
+
-
+
-
-
+
+
-
-
-
+
+
+
-
+
-
+
@@ -5171,63 +5171,63 @@
-
-
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
+
-
+
-
-
+
+
-
+
-
+
-
-
-
+
+
+
-
+
-
+
@@ -5241,43 +5241,43 @@
-
-
-
+
+
+
-
-
+
+
-
+
-
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
@@ -5291,42 +5291,42 @@
-
-
+
+
-
+
-
+
-
-
-
+
+
+
-
-
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
+
@@ -5340,89 +5340,89 @@
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
-
-
+
+
+
-
+
-
-
-
+
+
+
-
+
-
-
+
+
-
-
+
+
-
+
-
+
-
-
-
+
+
+
-
+
@@ -5433,53 +5433,53 @@
-
-
+
+
-
-
+
+
-
-
-
+
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
-
+
+
+
-
-
+
+
-
+
-
+
-
+
-
+
-
+
@@ -5493,38 +5493,38 @@
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
@@ -5538,11 +5538,11 @@
-
-
+
+
-
+
@@ -5553,101 +5553,101 @@
-
-
-
+
+
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
This response must address all control sub-statement requirements.
-
+
-
+
This response must address all control sub-statement requirements.
-
-
-
-
+
+
+
+
-
+
-
-
-
-
+
+
+
+
-
+
-
-
-
-
+
+
+
+
-
+
@@ -5665,161 +5665,161 @@
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
-
+
+
+
+
-
-
-
-
+
+
+
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
-
-
+
+
+
-
+
-
-
-
-
+
+
+
+
-
+
-
-
-
+
+
+
-
+
-
-
-
-
+
+
+
+
-
-
-
-
+
+
+
+
-
+
-
-
-
+
+
+
-
+
@@ -5833,46 +5833,46 @@
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
-
-
-
+
+
+
+
-
+
@@ -5890,138 +5890,138 @@
-
-
-
-
+
+
+
+
-
-
-
-
+
+
+
+
-
-
-
-
+
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
+
-
-
-
-
+
+
+
+
-
+
-
-
-
-
+
+
+
+
-
-
-
-
+
+
+
+
-
+
-
+
-
-
-
-
+
+
+
+
-
-
-
-
+
+
+
+
-
-
-
-
+
+
+
+
-
+
-
+
-
-
-
-
+
+
+
+
-
+
-
-
-
-
+
+
+
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
@@ -6035,37 +6035,37 @@
-
-
-
-
+
+
+
+
-
-
-
-
+
+
+
+
-
-
-
-
+
+
+
+
-
-
-
-
+
+
+
+
-
+
-
+
-
+
@@ -6079,48 +6079,48 @@
-
-
-
+
+
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
-
-
+
+
+
-
+
-
-
-
-
+
+
+
+
-
+
@@ -6134,79 +6134,79 @@
-
-
-
-
+
+
+
+
-
+
-
-
-
-
+
+
+
+
-
-
-
-
+
+
+
+
-
+
-
+
-
-
-
+
+
+
-
+
-
-
-
+
+
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
@@ -6232,88 +6232,88 @@
-
-
-
-
+
+
+
+
-
-
-
-
+
+
+
+
-
-
-
-
+
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
+
-
-
-
-
+
+
+
+
-
+
-
-
-
+
+
+
-
+
-
-
-
-
+
+
+
+
-
+
-
-
-
-
+
+
+
+
-
-
-
-
+
+
+
+
-
+
@@ -6327,100 +6327,100 @@
-
-
-
-
+
+
+
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
This response must address all control sub-statement requirements.
-
+
-
+
This response must address all control sub-statement requirements.
-
-
-
+
+
+
-
+
-
-
-
-
+
+
+
+
-
+
-
-
-
+
+
+
-
+
@@ -6446,22 +6446,22 @@
-
-
-
-
+
+
+
+
-
-
-
-
+
+
+
+
-
+
-
+
@@ -6483,14 +6483,14 @@
-
-
+
+
-
+
-
+
@@ -6512,26 +6512,26 @@
-
-
+
+
-
+
-
+
-
-
+
+
-
+
-
+
@@ -6549,23 +6549,23 @@
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
@@ -6579,85 +6579,85 @@
-
-
-
+
+
+
-
+
-
+
-
-
-
+
+
+
-
+
-
+
-
-
-
+
+
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
+
-
+
-
-
-
+
+
+
-
+
@@ -6675,84 +6675,84 @@
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
@@ -6775,96 +6775,96 @@
-
-
-
+
+
+
-
-
-
+
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
+
-
+
-
-
+
+
-
+
@@ -6878,11 +6878,11 @@
-
-
+
+
-
+
@@ -6896,12 +6896,12 @@
-
-
-
+
+
+
-
+
@@ -6915,12 +6915,12 @@
-
-
-
+
+
+
-
+
@@ -6941,13 +6941,13 @@
-
-
-
-
+
+
+
+
-
+
@@ -6961,29 +6961,29 @@
-
-
-
-
+
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
@@ -6997,186 +6997,186 @@
-
-
-
+
+
+
-
+
-
-
+
+
-
+
-
-
-
-
+
+
+
+
-
+
-
-
+
+
-
+
-
-
+
+
-
+
-
-
+
+
-
-
-
+
+
+
-
+
-
+
-
-
-
-
+
+
+
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
This response must address all control sub-statement requirements.
-
+
-
+
This response must address all control sub-statement requirements.
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
-
-
+
+
+
-
+
-
-
+
+
-
+
@@ -7190,25 +7190,25 @@
-
-
-
+
+
+
-
+
-
+
-
-
-
+
+
+
-
+
@@ -7226,137 +7226,137 @@
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
+
-
+
-
-
-
+
+
+
-
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
-
-
+
+
+
-
+
-
+
-
-
-
+
+
+
-
+
-
+
-
-
-
+
+
+
-
+
-
+
-
-
-
+
+
+
-
+
-
-
-
-
+
+
+
+
-
+
@@ -7370,67 +7370,67 @@
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
-
-
-
+
+
+
+
-
+
-
-
-
+
+
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
-
-
-
+
+
+
+
-
+
@@ -7448,555 +7448,555 @@
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
+
+
-
+
-
+
-
+
-
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
-
+
+
-
+
-
-
+
+
-
+
-
-
+
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
This response must address all control sub-statement requirements.
-
+
-
+
This response must address all control sub-statement requirements.
-
-
-
-
+
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
+
+
-
-
+
+
-
+
-
+
-
+
-
+
-
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
-
-
-
+
+
+
+
-
-
-
-
+
+
+
+
-
+
-
+
-
-
-
-
+
+
+
+
-
+
-
-
-
-
+
+
+
+
-
+
-
+
-
-
-
-
+
+
+
+
-
+
-
+
-
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
+
+
-
-
-
-
+
+
+
+
-
-
+
+
-
-
+
+
-
+
-
+
-
+
-
+
-
+
-
-
-
+
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
+
-
+
-
-
+
+
-
-
-
-
+
+
+
+
-
-
-
-
+
+
+
+
-
+
-
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
-
+
+
+
+
-
+
-
+
-
-
-
-
+
+
+
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
This response must address all control sub-statement requirements.
-
+
-
+
This response must address all control sub-statement requirements.
-
-
-
-
+
+
+
+
-
-
-
-
+
+
+
+
-
+
@@ -8010,18 +8010,18 @@
-
-
+
+
-
-
+
+
-
+
-
+
@@ -8035,40 +8035,40 @@
-
-
-
-
+
+
+
+
-
-
-
-
+
+
+
+
-
-
-
-
+
+
+
+
-
-
-
-
+
+
+
+
-
-
-
-
+
+
+
+
-
+
-
+
@@ -8082,61 +8082,61 @@
-
-
-
-
+
+
+
+
-
-
-
-
+
+
+
+
-
-
+
+
-
-
-
+
+
+
-
-
+
+
-
+
-
+
-
+
-
+
-
-
-
-
+
+
+
+
-
-
-
-
+
+
+
+
-
+
-
+
@@ -8150,11 +8150,11 @@
-
-
+
+
-
+
@@ -8168,11 +8168,11 @@
-
-
+
+
-
+
@@ -8186,240 +8186,240 @@
-
-
-
+
+
+
-
+
-
-
-
-
+
+
+
+
-
-
-
-
+
+
+
+
-
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
This response must address all control sub-statement requirements.
-
+
-
+
This response must address all control sub-statement requirements.
-
-
-
+
+
+
-
-
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
-
-
+
+
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
-
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
-
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
@@ -8433,655 +8433,655 @@
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
-
+
+
-
-
-
+
+
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
-
+
+
-
-
-
+
+
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
+
-
-
-
+
+
+
-
+
-
-
-
+
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
+
-
+
-
+
-
+
-
-
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
+
+
-
-
+
+
-
-
-
+
+
+
-
-
+
+
-
-
-
+
+
+
-
-
+
+
-
-
+
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
-
+
+
-
-
+
+
-
+
-
-
-
+
+
+
-
+
-
-
+
+
-
+
-
-
-
+
+
+
-
-
+
+
-
-
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
-
+
+
-
+
-
-
+
+
-
+
-
-
-
+
+
+
-
-
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
-
-
+
+
+
-
-
+
+
-
+
-
-
+
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
This response must address all control sub-statement requirements.
-
+
-
+
This response must address all control sub-statement requirements.
-
-
-
+
+
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
-
+
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
@@ -9095,66 +9095,66 @@
-
-
-
+
+
+
-
-
-
+
+
+
-
-
+
+
-
-
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
@@ -9168,390 +9168,390 @@
-
-
+
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
This response must address all control sub-statement requirements.
-
+
-
+
This response must address all control sub-statement requirements.
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
-
+
+
-
-
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
+
-
+
-
-
-
+
+
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
+
-
-
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
-
+
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
This response must address all control sub-statement requirements.
-
+
-
+
This response must address all control sub-statement requirements.
-
-
+
+
-
-
+
+
-
-
-
+
+
+
-
+
-
+
-
+
@@ -9569,79 +9569,79 @@
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
+
-
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
@@ -9673,131 +9673,131 @@
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
-
-
+
+
+
-
+
-
-
-
+
+
+
-
+
-
+
-
-
-
+
+
+
-
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
-
-
+
+
+
-
+
@@ -9811,472 +9811,472 @@
-
-
-
+
+
+
-
+
-
-
-
+
+
+
-
+
-
-
-
+
+
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
This response must address all control sub-statement requirements.
-
+
-
+
This response must address all control sub-statement requirements.
-
-
-
-
+
+
+
+
-
-
-
-
+
+
+
+
-
-
-
-
+
+
+
+
-
-
-
-
+
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
-
+
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
-
-
+
+
+
-
+
-
+
-
-
-
+
+
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
+
@@ -10295,91 +10295,91 @@
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
@@ -10393,45 +10393,45 @@
-
-
-
+
+
+
-
-
-
-
+
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
+
-
+
@@ -10446,521 +10446,521 @@
-
-
-
+
+
+
-
+
-
+
-
-
-
+
+
+
-
+
-
-
-
+
+
+
-
+
-
-
-
+
+
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
-
-
+
+
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
-
-
+
+
+
-
+
-
-
-
+
+
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
This response must address all control sub-statement requirements.
-
+
-
+
This response must address all control sub-statement requirements.
-
-
-
-
+
+
+
+
-
+
-
-
-
+
+
+
-
+
-
-
-
+
+
+
-
-
-
-
+
+
+
+
-
+
-
+
-
-
+
+
-
-
-
+
+
+
-
+
-
+
-
-
-
+
+
+
-
+
-
-
-
-
+
+
+
+
-
+
-
-
-
-
+
+
+
+
-
+
-
-
-
-
+
+
+
+
-
+
-
-
-
+
+
+
-
+
-
-
-
-
+
+
+
+
-
+
-
-
-
+
+
+
-
+
-
-
-
-
+
+
+
+
-
+
-
-
-
+
+
+
-
-
+
+
-
+
-
+
@@ -10974,210 +10974,210 @@
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
-
+
+
+
+
-
-
-
-
+
+
+
+
-
+
-
+
-
+
-
+
-
-
-
-
+
+
+
+
-
-
-
+
+
+
-
+
-
+
-
-
-
-
+
+
+
+
-
+
-
+
-
-
-
-
+
+
+
+
-
+
-
+
-
-
-
-
+
+
+
+
-
+
-
+
-
-
-
-
+
+
+
+
-
+
-
+
-
-
-
-
+
+
+
+
-
+
-
+
-
-
-
-
+
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
-
+
+
+
+
-
-
-
-
+
+
+
+
-
-
-
-
+
+
+
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
@@ -11191,44 +11191,44 @@
-
-
-
-
+
+
+
+
-
+
-
+
-
-
-
-
+
+
+
+
-
+
-
+
-
-
-
-
+
+
+
+
-
+
-
+
@@ -11274,16 +11274,16 @@
-
-
-
-
+
+
+
+
-
+
-
+
@@ -11310,13 +11310,13 @@
-
-
-
-
+
+
+
+
-
+
@@ -11338,16 +11338,16 @@
-
-
-
-
+
+
+
+
-
+
-
+
@@ -11395,24 +11395,24 @@
-
-
-
+
+
+
-
-
-
-
+
+
+
+
-
+
-
+
-
+
@@ -11426,21 +11426,21 @@
-
-
-
+
+
+
-
-
-
-
+
+
+
+
-
+
-
+
@@ -11470,28 +11470,28 @@
-
-
-
-
+
+
+
+
-
-
-
-
+
+
+
+
-
-
-
-
+
+
+
+
-
+
-
+
@@ -11525,16 +11525,16 @@
-
-
-
-
+
+
+
+
-
+
-
+
@@ -11556,16 +11556,16 @@
-
-
-
-
+
+
+
+
-
+
-
+
@@ -11583,13 +11583,13 @@
-
-
-
-
+
+
+
+
-
+
@@ -11611,231 +11611,231 @@
-
-
-
+
+
+
-
-
+
+
-
+
-
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
This response must address all control sub-statement requirements.
-
+
-
+
This response must address all control sub-statement requirements.
-
-
+
+
-
-
+
+
-
+
-
+
-
-
-
+
+
+
-
+
-
-
-
+
+
+
-
+
-
-
-
-
+
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
+
-
-
-
-
+
+
+
+
-
+
-
-
-
-
+
+
+
+
-
-
-
+
+
+
-
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
+
-
+
@@ -11849,241 +11849,241 @@
-
-
-
-
+
+
+
+
-
-
-
-
+
+
+
+
-
-
-
+
+
+
-
-
-
-
+
+
+
+
-
-
-
-
+
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
-
+
+
+
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
-
-
-
+
+
+
+
-
+
-
-
-
-
+
+
+
+
-
+
-
-
-
+
+
+
-
+
-
-
-
+
+
+
-
+
-
+
-
-
-
+
+
+
-
+
-
-
-
+
+
+
-
+
-
+
-
-
-
-
+
+
+
+
-
+
-
+
-
-
-
-
+
+
+
+
-
+
-
+
-
-
-
-
+
+
+
+
-
-
-
+
+
+
-
+
-
+
-
-
-
-
+
+
+
+
-
+
-
+
-
-
-
+
+
+
-
-
-
-
+
+
+
+
-
+
-
+
@@ -12097,13 +12097,13 @@
-
-
-
-
+
+
+
+
-
+
@@ -12117,15 +12117,15 @@
-
-
-
+
+
+
-
+
-
+
@@ -12137,162 +12137,162 @@
-
-
-
-
+
+
+
+
-
-
-
+
+
+
-
-
-
-
+
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
+
-
-
-
+
+
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
-
-
-
+
+
+
+
-
+
-
+
-
-
-
+
+
+
-
+
-
-
-
-
+
+
+
+
-
+
-
-
-
-
+
+
+
+
-
+
-
-
-
+
+
+
-
+
@@ -12311,20 +12311,20 @@
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
@@ -12338,188 +12338,188 @@
-
-
+
+
-
+
-
+
-
-
-
+
+
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
This response must address all control sub-statement requirements.
-
+
-
+
This response must address all control sub-statement requirements.
-
-
-
+
+
+
-
+
-
-
-
+
+
+
-
+
-
-
-
+
+
+
-
+
-
-
-
+
+
+
-
+
-
-
-
+
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
-
-
+
+
+
-
+
@@ -12533,44 +12533,44 @@
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
-
-
-
+
+
+
+
-
+
@@ -12584,12 +12584,12 @@
-
-
-
+
+
+
-
+
@@ -12603,12 +12603,12 @@
-
-
-
+
+
+
-
+
@@ -12622,22 +12622,22 @@
-
-
-
+
+
+
-
+
-
-
-
+
+
+
-
+
@@ -12651,35 +12651,35 @@
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
diff --git a/src/content/rev5/baselines/xml/FedRAMP_rev5_LI-SaaS-baseline_profile.xml b/src/content/rev5/baselines/xml/FedRAMP_rev5_LI-SaaS-baseline_profile.xml
index 02107db56..b7549d299 100644
--- a/src/content/rev5/baselines/xml/FedRAMP_rev5_LI-SaaS-baseline_profile.xml
+++ b/src/content/rev5/baselines/xml/FedRAMP_rev5_LI-SaaS-baseline_profile.xml
@@ -1316,7 +1316,7 @@
-
+
@@ -1333,31 +1333,31 @@
-
+
-
+
-
-
-
-
+
+
+
+
Determine if the organization defines information system account types to be identified and selected to support organizational missions/business functions.
-
+
Access control policy; procedures addressing account management; security plan; information system design documentation; information system configuration settings and associated documentation; list of active system accounts along with the name of the individual associated with each account; list of conditions for group and role membership; notifications or records of recently transferred, separated, or terminated employees; list of recently disabled information system accounts along with the name of the individual associated with each account; access authorization records; account management compliance reviews; information system monitoring records; information system audit records; other relevant documents or records.
-
+
Organizational personnel with account management responsibilities; system/network administrators; organizational personnel with information security responsibilities.
-
+
Organizational processes for account management on the information system; automated mechanisms for implementing account management.
@@ -1367,21 +1367,21 @@
-
+
-
+
-
+
-
-
+
+
NSO for non-privileged users. Attestation for privileged users related to multi-factor identification and authentication.
@@ -1392,7 +1392,7 @@
-
+
FED - This is related to agency data and agency policy solution.
@@ -1403,7 +1403,7 @@
-
+
FED - This is related to agency data and agency policy solution.
@@ -1412,10 +1412,10 @@
-
+
-
+
@@ -1424,7 +1424,7 @@
-
+
NSO - All access to Cloud SaaS are via web services and/or API. The device accessed from or whether via wired or wireless connection is out of scope. Regardless of device accessed from, must utilize approved remote access methods (AC-17), secure communication with strong encryption (SC-13), key management (SC-12), and multi-factor authentication for privileged access (IA-2[1]).
@@ -1436,7 +1436,7 @@
-
+
NSO - All access to Cloud SaaS are via web service and/or API. The device accessed from is out of the scope. Regardless of device accessed from, must utilize approved remote access methods (AC-17), secure communication with strong encryption (SC-13), key management (SC-12), and multi-factor authentication for privileged access (IA-2 [1]).
@@ -1447,17 +1447,17 @@
-
+
-
+
-
+
@@ -1466,7 +1466,7 @@
-
+
@@ -1475,7 +1475,7 @@
-
+
@@ -1484,7 +1484,7 @@
-
+
@@ -1493,7 +1493,7 @@
-
+
@@ -1502,7 +1502,7 @@
-
+
@@ -1511,7 +1511,7 @@
-
+
@@ -1520,16 +1520,16 @@
-
+
-
+
-
+
@@ -1537,7 +1537,7 @@
-
+
NSO - Loss of availability of the audit data has been determined to have little or no impact to government business/mission needs.
@@ -1546,20 +1546,20 @@
-
+
-
+
-
+
-
+
@@ -1567,7 +1567,7 @@
-
+
@@ -1575,7 +1575,7 @@
-
+
@@ -1584,7 +1584,7 @@
-
+
NSO - Loss of availability of the audit data has been determined as little or no impact to government business/mission needs.
@@ -1595,7 +1595,7 @@
-
+
@@ -1604,17 +1604,17 @@
-
+
-
+
-
+
@@ -1622,18 +1622,18 @@
-
+
-
+
-
-
+
+
Condition: There are connection(s) to external systems. Connections (if any) shall be authorized and must: 1) Identify the interface/connection. 2) Detail what data is involved and its sensitivity. 3) Determine whether the connection is one-way or bi-directional. 4) Identify how the connection is secured.
@@ -1645,7 +1645,7 @@
-
+
Attestation - for compliance with FedRAMP Tailored LI-SaaS Continuous Monitoring Requirements.
@@ -1654,51 +1654,51 @@
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
-
+
+
Condition: There are connection(s) to external systems. Connections (if any) shall be authorized and must: 1) Identify the interface/connection. 2) Detail what data is involved and its sensitivity. 3) Determine whether the connection is one-way or bi-directional. 4) Identify how the connection is secured.
@@ -1710,7 +1710,7 @@
-
+
@@ -1718,36 +1718,36 @@
-
+
-
+
-
+
-
+
-
+
-
+
-
+
Required - Specifically include details of least functionality.
@@ -1773,17 +1773,17 @@
-
+
-
+
-
+
@@ -1791,7 +1791,7 @@
-
+
NSO- Not directly related to protection of the data.
@@ -1802,7 +1802,7 @@
-
+
NSO - Boundary is specific to SaaS environment; all access is via web services; users' machine or internal network are not contemplated. External services (SA-9), internal connection (CA-9), remote access (AC-17), and secure access (SC-12 and SC-13), and privileged authentication (IA-2[1]) are considerations.
@@ -1814,7 +1814,7 @@
-
+
@@ -1823,7 +1823,7 @@
-
+
NSO - Loss of availability of the SaaS has been determined as little or no impact to government business/mission needs.
@@ -1835,7 +1835,7 @@
-
+
NSO - Loss of availability of the SaaS has been determined as little or no impact to government business/mission needs.
@@ -1847,7 +1847,7 @@
-
+
NSO - Loss of availability of the SaaS has been determined as little or no impact to government business/mission needs.
@@ -1856,10 +1856,10 @@
-
+
-
+
@@ -1867,7 +1867,7 @@
-
+
NSO - Loss of availability of the SaaS has been determined as little or no impact to government business/mission needs.
@@ -1879,7 +1879,7 @@
-
+
@@ -1887,8 +1887,8 @@
-
-
+
+
NSO for non-privileged users. Attestation for privileged users related to multi-factor identification and authentication - specifically include description of management of service accounts.
@@ -1897,10 +1897,10 @@
-
+
-
+
IA-2(1) Additional FedRAMP Requirements and Guidance
@@ -1915,35 +1915,35 @@
-
+
-
+
-
+
-
+
-
+
-
-
+
+
-
-
-
-
+
+
+
+
Determine if the information system:
Accepts PIV credentials.
@@ -1958,7 +1958,7 @@
-
+
@@ -1967,7 +1967,7 @@
-
+
@@ -1976,16 +1976,16 @@
-
+
-
+
-
+
@@ -1993,10 +1993,10 @@
-
+
-
+
@@ -2004,17 +2004,17 @@
-
+
-
+
-
-
+
+
Condition: Must document and assess for privileged users. May attest to this control for non-privileged users. FedRAMP requires a minimum of multi-factor authentication for all Federal privileged users, if acceptance of PIV credentials is not supported. The implementation status and details of how this control is implemented must be clearly defined by the CSP.
@@ -2023,11 +2023,11 @@
-
+
-
-
+
+
Condition: Must document and assess for privileged users. May attest to this control for non-privileged users. FedRAMP requires a minimum of multi-factor authentication for all Federal privileged users, if acceptance of PIV credentials is not supported. The implementation status and details of how this control is implemented must be clearly defined by the CSP.
@@ -2038,7 +2038,7 @@
-
+
@@ -2047,7 +2047,7 @@
-
+
@@ -2056,7 +2056,7 @@
-
+
@@ -2065,16 +2065,16 @@
-
+
-
+
-
+
@@ -2082,17 +2082,17 @@
-
+
-
+
-
+
@@ -2100,7 +2100,7 @@
-
+
@@ -2109,7 +2109,7 @@
-
+
Attestation - Specifically attest to US-CERT compliance.
@@ -2121,17 +2121,17 @@
-
+
-
+
-
-
+
+
Condition: Control is not inherited from a FedRAMP-authorized PaaS or IaaS.
@@ -2143,17 +2143,17 @@
-
+
-
+
-
-
+
+
Condition: Control is not inherited from a FedRAMP-authorized PaaS or IaaS.
@@ -2165,17 +2165,17 @@
-
+
-
+
-
-
+
+
Condition: Control is not inherited from a FedRAMP-authorized PaaS or IaaS.
@@ -2184,11 +2184,11 @@
-
+
-
-
+
+
Condition: Control is not inherited from a FedRAMP-authorized PaaS or IaaS.
@@ -2197,11 +2197,11 @@
-
+
-
-
+
+
Condition: Control is not inherited from a FedRAMP-authorized PaaS or IaaS.
@@ -2213,18 +2213,18 @@
-
+
-
+
-
-
+
+
Condition: Control is not inherited from a FedRAMP-authorized PaaS or IaaS.
@@ -2234,11 +2234,11 @@
-
+
-
-
+
+
Condition: Control is not inherited from a FedRAMP-authorized PaaS or IaaS.
@@ -2248,11 +2248,11 @@
-
+
-
-
+
+
Condition: Control is not inherited from a FedRAMP-authorized PaaS or IaaS.
@@ -2262,11 +2262,11 @@
-
+
-
-
+
+
Condition: Control is not inherited from a FedRAMP-authorized PaaS or IaaS.
@@ -2275,11 +2275,11 @@
-
+
-
-
+
+
Condition: Control is not inherited from a FedRAMP-authorized PaaS or IaaS.
@@ -2288,11 +2288,11 @@
-
+
-
-
+
+
Condition: Control is not inherited from a FedRAMP-authorized PaaS or IaaS.
@@ -2301,11 +2301,11 @@
-
+
-
-
+
+
Condition: Control is not inherited from a FedRAMP-authorized PaaS or IaaS.
@@ -2323,11 +2323,11 @@
-
+
-
-
+
+
Condition: Control is not inherited from a FedRAMP-authorized PaaS or IaaS.
@@ -2336,11 +2336,11 @@
-
+
-
-
+
+
Condition: Control is not inherited from a FedRAMP-authorized PaaS or IaaS.
@@ -2352,17 +2352,17 @@
-
+
-
+
-
+
@@ -2370,7 +2370,7 @@
-
+
@@ -2379,17 +2379,17 @@
-
+
-
+
-
+
@@ -2398,7 +2398,7 @@
-
+
@@ -2407,7 +2407,7 @@
-
+
@@ -2416,7 +2416,7 @@
-
+
@@ -2424,16 +2424,16 @@
-
+
-
+
-
+
@@ -2442,7 +2442,7 @@
-
+
@@ -2451,7 +2451,7 @@
-
+
@@ -2460,7 +2460,7 @@
-
+
@@ -2469,7 +2469,7 @@
-
+
Attestation - Specifically stating that any third-party security personnel are treated as CSP employees.
@@ -2480,7 +2480,7 @@
-
+
@@ -2489,7 +2489,7 @@
-
+
@@ -2498,7 +2498,7 @@
-
+
@@ -2506,19 +2506,19 @@
-
+
-
+
-
+
-
+
@@ -2527,47 +2527,47 @@
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
@@ -2576,7 +2576,7 @@
-
+
@@ -2584,7 +2584,7 @@
-
+
@@ -2592,7 +2592,7 @@
-
+
@@ -2600,7 +2600,7 @@
-
+
@@ -2609,7 +2609,7 @@
-
+
@@ -2617,7 +2617,7 @@
-
+
@@ -2626,26 +2626,26 @@
-
+
-
+
-
+
-
+
-
+
@@ -2654,17 +2654,17 @@
-
+
-
+
-
-
+
+
Condition: If availability is a requirement, define protections in place as per control requirement.
@@ -2673,50 +2673,50 @@
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
-
+
+
Condition: If implementing need to detail how they meet it or don't meet it.
@@ -2727,7 +2727,7 @@
-
+
NSO - Not directly related to the security of the SaaS.
@@ -2738,7 +2738,7 @@
-
+
@@ -2746,7 +2746,7 @@
-
+
@@ -2754,27 +2754,27 @@
-
+
-
+
-
+
-
+
-
+
@@ -2782,7 +2782,7 @@
-
+
@@ -2791,37 +2791,37 @@
-
+
-
+
-
+
-
+
-
+
-
+
-
+
@@ -2829,7 +2829,7 @@
-
+
@@ -2837,7 +2837,7 @@
-
+
Attestation - Specifically related to US-CERT and FedRAMP communications procedures.
@@ -2849,7 +2849,7 @@
-
+
@@ -2858,7 +2858,7 @@
-
+
@@ -2867,7 +2867,7 @@
-
+
@@ -2876,7 +2876,7 @@
-
+
@@ -2885,7 +2885,7 @@
-
+
@@ -2894,7 +2894,7 @@
-
+
@@ -2903,7 +2903,7 @@
-
+
@@ -2912,7 +2912,7 @@
-
+
@@ -2921,7 +2921,7 @@
-
+
@@ -2930,7 +2930,7 @@
-
+
@@ -2939,7 +2939,7 @@
-
+
diff --git a/src/content/rev5/baselines/xml/FedRAMP_rev5_LOW-baseline_profile.xml b/src/content/rev5/baselines/xml/FedRAMP_rev5_LOW-baseline_profile.xml
index afd2125c7..47de559c1 100644
--- a/src/content/rev5/baselines/xml/FedRAMP_rev5_LOW-baseline_profile.xml
+++ b/src/content/rev5/baselines/xml/FedRAMP_rev5_LOW-baseline_profile.xml
@@ -1312,294 +1312,294 @@
-
-
-
+
+
+
-
-
-
+
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
This response must address all control sub-statement requirements.
-
+
-
+
This response must address all control sub-statement requirements.
-
-
-
+
+
+
-
-
+
+
-
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
-
+
+
-
-
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
+
-
-
-
+
+
+
-
+
-
+
@@ -1614,20 +1614,20 @@
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
@@ -1653,43 +1653,43 @@
-
-
-
+
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
-
+
+
+
-
-
+
+
-
+
-
+
-
+
@@ -1708,20 +1708,20 @@
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
@@ -1733,252 +1733,252 @@
-
-
-
+
+
+
-
-
-
+
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
This response must address all control sub-statement requirements.
-
+
-
+
This response must address all control sub-statement requirements.
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
+
-
-
-
+
+
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
-
-
+
+
+
-
-
+
+
-
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
This response must address all control sub-statement requirements.
-
+
-
+
This response must address all control sub-statement requirements.
-
-
-
+
+
+
-
-
-
+
+
+
-
-
+
+
-
+
-
+
-
+
-
+
@@ -1997,112 +1997,112 @@
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
+
+
-
-
-
+
+
+
-
-
+
+
-
+
-
+
-
+
-
+
-
+
-
+
-
-
-
+
+
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
-
-
+
+
+
-
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
@@ -2117,31 +2117,31 @@
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
+
@@ -2164,109 +2164,109 @@
-
-
-
+
+
+
-
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
This response must address all control sub-statement requirements.
-
+
-
+
This response must address all control sub-statement requirements.
@@ -2283,96 +2283,96 @@
-
-
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
+
+
-
-
+
+
-
+
-
+
-
+
-
+
-
+
-
+
-
-
-
+
+
+
-
+
-
-
-
+
+
+
-
-
+
+
-
-
-
+
+
+
-
+
-
+
-
+
@@ -2391,20 +2391,20 @@
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
@@ -2418,48 +2418,48 @@
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
+
+
-
+
-
+
-
+
-
+
-
+
@@ -2482,102 +2482,102 @@
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
@@ -2591,154 +2591,154 @@
-
-
-
+
+
+
-
+
-
-
-
+
+
+
-
-
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
This response must address all control sub-statement requirements.
-
+
-
+
This response must address all control sub-statement requirements.
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
+
+
-
+
-
+
-
+
@@ -2752,53 +2752,53 @@
-
-
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
-
-
+
+
+
-
+
-
-
-
+
+
+
-
+
-
+
@@ -2822,38 +2822,38 @@
-
-
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
+
-
+
@@ -2867,22 +2867,22 @@
-
-
-
+
+
+
-
-
+
+
-
+
-
+
-
+
@@ -2897,111 +2897,111 @@
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
This response must address all control sub-statement requirements.
-
+
-
+
This response must address all control sub-statement requirements.
-
-
-
-
+
+
+
+
-
+
@@ -3020,102 +3020,102 @@
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
-
+
+
+
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
@@ -3130,35 +3130,35 @@
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
@@ -3177,44 +3177,44 @@
-
-
-
-
+
+
+
+
-
-
-
-
+
+
+
+
-
-
-
-
+
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
+
@@ -3240,94 +3240,94 @@
-
-
-
-
+
+
+
+
-
-
-
-
+
+
+
+
-
-
-
-
+
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
This response must address all control sub-statement requirements.
-
+
-
+
This response must address all control sub-statement requirements.
@@ -3355,22 +3355,22 @@
-
-
-
-
+
+
+
+
-
-
-
-
+
+
+
+
-
+
-
+
@@ -3392,14 +3392,14 @@
-
-
+
+
-
+
-
+
@@ -3421,14 +3421,14 @@
-
-
+
+
-
+
-
+
@@ -3443,66 +3443,66 @@
-
-
-
+
+
+
-
+
-
+
-
-
-
+
+
+
-
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
+
-
+
@@ -3521,84 +3521,84 @@
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
@@ -3621,63 +3621,63 @@
-
-
-
+
+
+
-
-
-
+
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
@@ -3699,170 +3699,170 @@
-
-
-
-
+
+
+
+
-
+
-
-
+
+
-
+
-
-
-
-
+
+
+
+
-
+
-
-
+
+
-
+
-
-
+
+
-
+
-
-
+
+
-
-
-
+
+
+
-
+
-
+
-
-
-
-
+
+
+
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
This response must address all control sub-statement requirements.
-
+
-
+
This response must address all control sub-statement requirements.
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
@@ -3880,59 +3880,59 @@
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
+
-
+
-
-
-
+
+
+
-
+
@@ -3947,35 +3947,35 @@
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
@@ -3994,77 +3994,77 @@
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
+
+
-
+
-
+
-
+
-
+
-
+
@@ -4077,404 +4077,404 @@
-
-
-
+
+
+
-
-
-
+
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
This response must address all control sub-statement requirements.
-
+
-
+
This response must address all control sub-statement requirements.
-
-
-
-
+
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
+
+
-
-
+
+
-
+
-
+
-
+
-
+
-
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
+
+
-
-
-
-
+
+
+
+
-
-
+
+
-
-
+
+
-
+
-
+
-
+
-
+
-
+
-
-
+
+
-
-
-
-
+
+
+
+
-
-
-
-
+
+
+
+
-
+
-
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
This response must address all control sub-statement requirements.
-
+
-
+
This response must address all control sub-statement requirements.
-
-
-
-
+
+
+
+
-
-
-
-
+
+
+
+
-
+
-
-
-
-
+
+
+
+
-
-
-
-
+
+
+
+
-
+
-
+
-
-
-
-
+
+
+
+
-
-
-
-
+
+
+
+
-
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
This response must address all control sub-statement requirements.
-
+
-
+
This response must address all control sub-statement requirements.
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
@@ -4488,20 +4488,20 @@
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
@@ -4509,500 +4509,500 @@
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
-
-
+
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
+
-
+
-
+
-
+
-
-
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
+
+
-
-
+
+
-
-
-
+
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
-
+
+
+
-
-
+
+
-
-
+
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
-
-
+
+
+
-
-
+
+
-
-
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
-
-
+
+
+
-
-
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
This response must address all control sub-statement requirements.
-
+
-
+
This response must address all control sub-statement requirements.
-
-
-
+
+
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
-
+
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
@@ -5017,66 +5017,66 @@
-
-
-
+
+
+
-
-
-
+
+
+
-
-
+
+
-
-
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
@@ -5091,11 +5091,11 @@
-
-
+
+
-
+
@@ -5108,358 +5108,358 @@
-
-
-
+
+
+
-
-
-
+
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
This response must address all control sub-statement requirements.
-
+
-
+
This response must address all control sub-statement requirements.
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
-
+
+
-
-
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
+
-
-
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
-
+
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
This response must address all control sub-statement requirements.
-
+
-
+
This response must address all control sub-statement requirements.
-
-
+
+
-
-
+
+
-
-
-
+
+
+
-
+
-
+
-
+
@@ -5477,80 +5477,80 @@
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
+
-
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
@@ -5583,70 +5583,70 @@
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
@@ -5655,204 +5655,204 @@
-
-
-
+
+
+
-
+
-
-
-
+
+
+
-
+
-
+
-
-
-
+
+
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
This response must address all control sub-statement requirements.
-
+
-
+
This response must address all control sub-statement requirements.
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
+
@@ -5871,91 +5871,91 @@
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
@@ -5964,302 +5964,302 @@
-
-
-
+
+
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
This response must address all control sub-statement requirements.
-
+
-
+
This response must address all control sub-statement requirements.
-
-
-
-
+
+
+
+
-
+
-
-
-
-
+
+
+
+
-
+
-
-
-
+
+
+
-
-
+
+
-
+
-
+
@@ -6273,48 +6273,48 @@
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
-
+
+
+
+
-
-
-
-
+
+
+
+
-
+
-
+
-
+
-
+
@@ -6360,16 +6360,16 @@
-
-
-
-
+
+
+
+
-
+
-
+
@@ -6396,13 +6396,13 @@
-
-
-
-
+
+
+
+
-
+
@@ -6424,16 +6424,16 @@
-
-
-
-
+
+
+
+
-
+
-
+
@@ -6482,24 +6482,24 @@
-
-
-
+
+
+
-
-
-
-
+
+
+
+
-
+
-
+
-
+
@@ -6513,21 +6513,21 @@
-
-
-
+
+
+
-
-
-
-
+
+
+
+
-
+
-
+
@@ -6553,28 +6553,28 @@
-
-
-
-
+
+
+
+
-
-
-
-
+
+
+
+
-
-
-
-
+
+
+
+
-
+
-
+
@@ -6610,16 +6610,16 @@
-
-
-
-
+
+
+
+
-
+
-
+
@@ -6641,16 +6641,16 @@
-
-
-
-
+
+
+
+
-
+
-
+
@@ -6668,13 +6668,13 @@
-
-
-
-
+
+
+
+
-
+
@@ -6682,155 +6682,155 @@
-
-
-
+
+
+
-
-
-
+
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
This response must address all control sub-statement requirements.
-
+
-
+
This response must address all control sub-statement requirements.
-
-
-
+
+
+
-
+
-
-
-
-
+
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
+
-
+
@@ -6845,75 +6845,75 @@
-
-
-
-
+
+
+
+
-
-
-
-
+
+
+
+
-
-
-
+
+
+
-
-
-
-
+
+
+
+
-
-
-
-
+
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
-
+
+
+
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
@@ -6925,38 +6925,38 @@
-
-
-
-
+
+
+
+
-
-
-
+
+
+
-
-
-
-
+
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
+
@@ -6964,166 +6964,166 @@
-
-
-
+
+
+
-
-
-
+
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
This response must address all control sub-statement requirements.
-
+
-
+
This response must address all control sub-statement requirements.
-
-
-
+
+
+
-
+
-
-
-
+
+
+
-
+
-
-
-
+
+
+
-
+
-
-
-
+
+
+
-
+
-
-
-
+
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
-
-
+
+
+
-
+
@@ -7138,45 +7138,45 @@
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
-
-
-
+
+
+
+
-
+
@@ -7191,12 +7191,12 @@
-
-
-
+
+
+
-
+
@@ -7212,35 +7212,35 @@
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
diff --git a/src/content/rev5/baselines/xml/FedRAMP_rev5_MODERATE-baseline_profile.xml b/src/content/rev5/baselines/xml/FedRAMP_rev5_MODERATE-baseline_profile.xml
index c598a2a9a..5a406adc7 100644
--- a/src/content/rev5/baselines/xml/FedRAMP_rev5_MODERATE-baseline_profile.xml
+++ b/src/content/rev5/baselines/xml/FedRAMP_rev5_MODERATE-baseline_profile.xml
@@ -2072,423 +2072,423 @@
-
-
-
+
+
+
-
-
-
+
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
This response must address all control sub-statement requirements.
-
+
-
+
This response must address all control sub-statement requirements.
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
-
-
+
+
+
-
+
-
-
-
+
+
+
-
+
-
-
-
+
+
+
-
-
+
+
-
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
-
-
+
+
+
-
+
-
-
-
+
+
+
-
+
-
+
-
-
-
+
+
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
+
+
-
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
-
-
+
+
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
-
-
+
+
+
-
+
-
-
+
+
-
-
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
-
-
+
+
+
-
+
-
+
-
-
-
+
+
+
-
+
-
+
-
-
+
+
-
+
-
+
@@ -2511,52 +2511,52 @@
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
+
-
+
-
-
-
+
+
+
-
+
-
+
@@ -2571,52 +2571,52 @@
-
-
-
+
+
+
-
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
+
-
+
@@ -2630,15 +2630,15 @@
-
-
-
+
+
+
-
+
-
+
@@ -2657,137 +2657,137 @@
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
-
-
+
+
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
+
-
-
-
+
+
+
-
+
-
+
-
-
-
+
+
+
-
+
-
-
-
+
+
+
-
+
@@ -2801,62 +2801,62 @@
-
-
+
+
-
-
+
+
-
+
-
+
-
-
-
+
+
+
-
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
-
-
+
+
+
-
+
-
+
@@ -2870,57 +2870,57 @@
-
-
-
+
+
+
-
+
-
+
-
-
-
+
+
+
-
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
-
-
+
+
+
-
+
@@ -2935,20 +2935,20 @@
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
@@ -2974,43 +2974,43 @@
-
-
-
+
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
-
+
+
+
-
-
+
+
-
+
-
+
-
+
@@ -3032,20 +3032,20 @@
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
@@ -3057,262 +3057,262 @@
-
-
-
+
+
+
-
-
-
+
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
This response must address all control sub-statement requirements.
-
+
-
+
This response must address all control sub-statement requirements.
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
+
-
-
-
+
+
+
-
+
-
-
-
+
+
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
-
-
+
+
+
-
-
+
+
-
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
This response must address all control sub-statement requirements.
-
+
-
+
This response must address all control sub-statement requirements.
-
-
-
+
+
+
-
-
-
+
+
+
-
-
+
+
-
+
-
+
-
+
-
+
@@ -3331,78 +3331,78 @@
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
+
+
-
-
-
+
+
+
-
-
+
+
-
+
-
+
-
+
-
+
-
+
-
+
-
-
-
+
+
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
@@ -3416,49 +3416,49 @@
-
-
-
+
+
+
-
+
-
+
-
-
-
+
+
+
-
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
@@ -3473,31 +3473,31 @@
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
+
@@ -3523,174 +3523,174 @@
-
-
-
+
+
+
-
+
-
+
-
-
-
+
+
+
-
+
-
+
-
-
-
+
+
+
-
+
-
+
-
-
-
-
+
+
+
+
-
-
-
+
+
+
-
+
-
+
-
-
-
+
+
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
-
-
+
+
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
This response must address all control sub-statement requirements.
-
+
-
+
This response must address all control sub-statement requirements.
@@ -3707,59 +3707,59 @@
-
-
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
+
+
-
-
+
+
-
+
-
+
-
+
-
+
-
+
-
+
@@ -3773,12 +3773,12 @@
-
-
-
+
+
+
-
+
@@ -3786,37 +3786,37 @@
-
-
-
+
+
+
-
+
-
-
-
+
+
+
-
-
+
+
-
-
-
+
+
+
-
+
-
+
-
+
@@ -3835,20 +3835,20 @@
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
@@ -3862,48 +3862,48 @@
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
+
+
-
+
-
+
-
+
-
+
-
+
@@ -3926,112 +3926,112 @@
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
-
-
+
+
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
@@ -4046,22 +4046,22 @@
-
-
-
+
+
+
-
+
-
-
-
+
+
+
-
+
@@ -4076,157 +4076,157 @@
-
-
-
+
+
+
-
+
-
+
-
-
-
+
+
+
-
-
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
This response must address all control sub-statement requirements.
-
+
-
+
This response must address all control sub-statement requirements.
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
+
+
-
+
-
+
-
+
@@ -4241,66 +4241,66 @@
-
-
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
-
-
+
+
+
-
+
-
-
+
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
@@ -4319,152 +4319,152 @@
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
+
+
-
-
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
-
-
+
+
+
-
+
-
-
-
+
+
+
-
+
-
-
-
+
+
+
-
+
-
-
-
+
+
+
-
+
-
-
-
+
+
+
-
+
-
+
-
-
+
+
-
-
-
+
+
+
-
+
-
+
-
-
+
+
-
-
-
+
+
+
-
+
-
+
@@ -4488,50 +4488,50 @@
-
-
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
+
-
+
-
-
+
+
-
+
-
+
@@ -4545,44 +4545,44 @@
-
-
-
+
+
+
-
-
+
+
-
+
-
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
@@ -4596,43 +4596,43 @@
-
-
+
+
-
+
-
+
-
-
-
+
+
+
-
-
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
+
@@ -4647,70 +4647,70 @@
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
-
-
+
+
+
-
+
-
-
+
+
-
-
+
+
-
+
-
+
@@ -4722,53 +4722,53 @@
-
-
+
+
-
-
+
+
-
-
-
+
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
-
+
+
+
-
-
+
+
-
+
-
+
-
+
-
+
-
+
@@ -4783,38 +4783,38 @@
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
@@ -4829,91 +4829,91 @@
-
-
+
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
This response must address all control sub-statement requirements.
-
+
-
+
This response must address all control sub-statement requirements.
-
-
-
-
+
+
+
+
-
+
-
-
-
-
+
+
+
+
-
+
@@ -4932,132 +4932,132 @@
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
-
+
+
+
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
-
-
+
+
+
-
+
-
-
-
+
+
+
-
+
-
-
-
+
+
+
-
+
@@ -5072,35 +5072,35 @@
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
@@ -5119,107 +5119,107 @@
-
-
-
-
+
+
+
+
-
-
-
-
+
+
+
+
-
-
-
-
+
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
+
-
-
-
-
+
+
+
+
-
+
-
-
-
-
+
+
+
+
-
-
-
-
+
+
+
+
-
-
-
-
+
+
+
+
-
+
-
+
-
-
-
-
+
+
+
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
@@ -5233,37 +5233,37 @@
-
-
-
-
+
+
+
+
-
-
-
-
+
+
+
+
-
-
-
-
+
+
+
+
-
-
-
-
+
+
+
+
-
+
-
+
-
+
@@ -5277,37 +5277,37 @@
-
-
-
+
+
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
-
-
+
+
+
-
+
@@ -5321,43 +5321,43 @@
-
-
-
-
+
+
+
+
-
+
-
-
-
-
+
+
+
+
-
-
-
-
+
+
+
+
-
+
-
+
-
-
-
+
+
+
-
+
@@ -5383,51 +5383,51 @@
-
-
-
-
+
+
+
+
-
-
-
-
+
+
+
+
-
-
-
-
+
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
+
-
-
-
-
+
+
+
+
-
+
@@ -5442,91 +5442,91 @@
-
-
-
-
+
+
+
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
This response must address all control sub-statement requirements.
-
+
-
+
This response must address all control sub-statement requirements.
-
-
-
+
+
+
-
+
-
-
-
-
+
+
+
+
-
+
@@ -5552,22 +5552,22 @@
-
-
-
-
+
+
+
+
-
-
-
-
+
+
+
+
-
+
-
+
@@ -5589,14 +5589,14 @@
-
-
+
+
-
+
-
+
@@ -5618,26 +5618,26 @@
-
-
+
+
-
+
-
+
-
-
+
+
-
+
-
+
@@ -5655,23 +5655,23 @@
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
@@ -5685,86 +5685,86 @@
-
-
-
+
+
+
-
+
-
+
-
-
-
+
+
+
-
+
-
+
-
-
-
+
+
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
+
-
+
-
-
-
+
+
+
-
+
@@ -5783,84 +5783,84 @@
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
@@ -5883,96 +5883,96 @@
-
-
-
+
+
+
-
-
-
+
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
+
-
+
-
-
+
+
-
+
@@ -5986,11 +5986,11 @@
-
-
+
+
-
+
@@ -6014,13 +6014,13 @@
-
-
-
-
+
+
+
+
-
+
@@ -6035,29 +6035,29 @@
-
-
-
-
+
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
@@ -6075,169 +6075,169 @@
-
-
-
+
+
+
-
+
-
-
+
+
-
+
-
-
-
-
+
+
+
+
-
+
-
-
+
+
-
+
-
-
+
+
-
+
-
-
+
+
-
-
-
+
+
+
-
+
-
+
-
-
-
-
+
+
+
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
This response must address all control sub-statement requirements.
-
+
-
+
This response must address all control sub-statement requirements.
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
@@ -6252,25 +6252,25 @@
-
-
-
+
+
+
-
+
-
+
-
-
-
+
+
+
-
+
@@ -6288,73 +6288,73 @@
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
+
-
+
-
-
-
+
+
+
-
+
-
+
-
-
-
+
+
+
-
+
@@ -6369,68 +6369,68 @@
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
-
-
-
+
+
+
+
-
+
-
-
-
+
+
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
-
-
-
+
+
+
+
-
+
@@ -6449,77 +6449,77 @@
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
+
+
-
+
-
+
-
+
-
+
-
+
@@ -6527,329 +6527,329 @@
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
-
+
+
-
+
-
-
+
+
-
+
-
-
+
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
This response must address all control sub-statement requirements.
-
+
-
+
This response must address all control sub-statement requirements.
-
-
-
-
+
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
+
+
-
-
+
+
-
+
-
+
-
+
-
+
-
+
-
+
-
-
-
-
+
+
+
+
-
-
-
-
+
+
+
+
-
+
-
+
-
-
-
-
+
+
+
+
-
+
-
-
-
-
+
+
+
+
-
+
-
+
-
-
-
-
+
+
+
+
-
+
-
+
-
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
+
+
-
-
-
-
+
+
+
+
-
-
+
+
-
-
+
+
-
+
-
+
-
+
-
+
-
+
-
-
+
+
-
-
-
-
+
+
+
+
-
-
-
-
+
+
+
+
-
+
-
+
-
+
@@ -6863,111 +6863,111 @@
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
-
+
+
+
+
-
+
-
+
-
-
-
-
+
+
+
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
This response must address all control sub-statement requirements.
-
+
-
+
This response must address all control sub-statement requirements.
-
-
-
-
+
+
+
+
-
-
-
-
+
+
+
+
-
+
@@ -6981,18 +6981,18 @@
-
-
+
+
-
-
+
+
-
+
-
+
@@ -7006,40 +7006,40 @@
-
-
-
-
+
+
+
+
-
-
-
-
+
+
+
+
-
-
-
-
+
+
+
+
-
-
-
-
+
+
+
+
-
-
-
-
+
+
+
+
-
+
-
+
@@ -7053,41 +7053,41 @@
-
-
-
-
+
+
+
+
-
-
-
-
+
+
+
+
-
-
+
+
-
-
-
+
+
+
-
-
+
+
-
+
-
+
-
+
-
+
@@ -7100,235 +7100,235 @@
-
-
-
-
+
+
+
+
-
-
-
-
+
+
+
+
-
+
-
+
-
-
-
-
+
+
+
+
-
-
-
-
+
+
+
+
-
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
This response must address all control sub-statement requirements.
-
+
-
+
This response must address all control sub-statement requirements.
-
-
-
+
+
+
-
-
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
-
-
+
+
+
-
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
-
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
-
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
@@ -7342,591 +7342,591 @@
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
+
-
-
-
+
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
+
-
+
-
+
-
+
-
-
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
+
+
-
-
+
+
-
-
-
+
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
-
+
+
+
-
-
+
+
-
-
+
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
-
-
+
+
+
-
+
-
-
+
+
-
+
-
-
-
+
+
+
-
-
+
+
-
-
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
-
+
+
-
+
-
-
-
+
+
+
-
-
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
-
+
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
This response must address all control sub-statement requirements.
-
+
-
+
This response must address all control sub-statement requirements.
-
-
-
+
+
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
-
+
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
@@ -7941,66 +7941,66 @@
-
-
-
+
+
+
-
-
-
+
+
+
-
-
+
+
-
-
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
@@ -8015,11 +8015,11 @@
-
-
+
+
-
+
@@ -8033,376 +8033,376 @@
-
-
-
+
+
+
-
-
-
+
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
This response must address all control sub-statement requirements.
-
+
-
+
This response must address all control sub-statement requirements.
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
-
+
+
-
-
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
+
-
-
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
-
+
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
This response must address all control sub-statement requirements.
-
+
-
+
This response must address all control sub-statement requirements.
-
-
+
+
-
-
+
+
-
-
-
+
+
+
-
+
-
+
-
+
@@ -8420,80 +8420,80 @@
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
+
-
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
@@ -8526,70 +8526,70 @@
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
@@ -8601,439 +8601,439 @@
-
-
-
+
+
+
-
+
-
-
-
+
+
+
-
+
-
+
-
-
-
+
+
+
-
+
-
+
-
-
-
+
+
+
-
+
-
-
-
+
+
+
-
+
-
-
-
+
+
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
This response must address all control sub-statement requirements.
-
+
-
+
This response must address all control sub-statement requirements.
-
-
-
-
+
+
+
+
-
-
-
-
+
+
+
+
-
-
-
-
+
+
+
+
-
-
-
-
+
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
-
+
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
-
-
+
+
+
-
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
+
@@ -9052,91 +9052,91 @@
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
@@ -9151,45 +9151,45 @@
-
-
-
+
+
+
-
-
-
-
+
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
+
-
+
@@ -9204,15 +9204,15 @@
-
-
-
+
+
+
-
+
-
+
@@ -9220,459 +9220,459 @@
-
-
-
+
+
+
-
+
-
-
-
+
+
+
-
+
-
-
-
+
+
+
-
+
-
-
-
+
+
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
-
-
+
+
+
-
+
-
-
-
+
+
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
This response must address all control sub-statement requirements.
-
+
-
+
This response must address all control sub-statement requirements.
-
-
-
-
+
+
+
+
-
+
-
-
-
+
+
+
-
-
-
-
+
+
+
+
-
+
-
+
-
-
+
+
-
-
-
+
+
+
-
+
-
+
-
-
-
+
+
+
-
+
-
-
-
-
+
+
+
+
-
+
-
-
-
-
+
+
+
+
-
+
-
-
-
-
+
+
+
+
-
+
-
-
-
+
+
+
-
+
-
-
-
-
+
+
+
+
-
+
-
-
-
+
+
+
-
-
+
+
-
+
-
+
@@ -9686,164 +9686,164 @@
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
-
+
+
+
+
-
-
-
-
+
+
+
+
-
+
-
+
-
+
-
+
-
-
-
-
+
+
+
+
-
+
-
+
-
-
-
-
+
+
+
+
-
+
-
+
-
-
-
-
+
+
+
+
-
+
-
+
-
-
-
-
+
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
-
+
+
+
+
-
-
-
-
+
+
+
+
-
-
-
-
+
+
+
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
@@ -9857,44 +9857,44 @@
-
-
-
-
+
+
+
+
-
+
-
+
-
-
-
-
+
+
+
+
-
+
-
+
-
-
-
-
+
+
+
+
-
+
-
+
@@ -9940,16 +9940,16 @@
-
-
-
-
+
+
+
+
-
+
-
+
@@ -9976,13 +9976,13 @@
-
-
-
-
+
+
+
+
-
+
@@ -10004,16 +10004,16 @@
-
-
-
-
+
+
+
+
-
+
-
+
@@ -10062,24 +10062,24 @@
-
-
-
+
+
+
-
-
-
-
+
+
+
+
-
+
-
+
-
+
@@ -10093,21 +10093,21 @@
-
-
-
+
+
+
-
-
-
-
+
+
+
+
-
+
-
+
@@ -10133,28 +10133,28 @@
-
-
-
-
+
+
+
+
-
-
-
-
+
+
+
+
-
-
-
-
+
+
+
+
-
+
-
+
@@ -10190,16 +10190,16 @@
-
-
-
-
+
+
+
+
-
+
-
+
@@ -10221,16 +10221,16 @@
-
-
-
-
+
+
+
+
-
+
-
+
@@ -10248,13 +10248,13 @@
-
-
-
-
+
+
+
+
-
+
@@ -10277,22 +10277,22 @@
-
-
-
+
+
+
-
-
+
+
-
+
-
+
-
+
@@ -10301,211 +10301,211 @@
-
-
-
+
+
+
-
-
-
+
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
This response must address all control sub-statement requirements.
-
+
-
+
This response must address all control sub-statement requirements.
-
-
+
+
-
-
+
+
-
+
-
+
-
-
-
+
+
+
-
+
-
-
-
+
+
+
-
+
-
-
-
-
+
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
+
-
-
-
-
+
+
+
+
-
+
-
-
-
-
+
+
+
+
-
-
-
+
+
+
-
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
+
-
+
@@ -10520,164 +10520,164 @@
-
-
-
-
+
+
+
+
-
-
-
-
+
+
+
+
-
-
-
+
+
+
-
-
-
-
+
+
+
+
-
-
-
-
+
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
-
+
+
+
+
-
+
-
+
-
+
-
+
-
+
-
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
-
-
+
+
+
-
+
-
+
-
-
-
+
+
+
-
+
-
-
-
-
+
+
+
+
-
+
-
+
-
-
-
-
+
+
+
+
-
+
-
+
-
-
-
+
+
+
-
-
-
-
+
+
+
+
-
+
-
+
@@ -10691,13 +10691,13 @@
-
-
-
-
+
+
+
+
-
+
@@ -10712,38 +10712,38 @@
-
-
-
-
+
+
+
+
-
-
-
+
+
+
-
-
-
-
+
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
+
@@ -10751,84 +10751,84 @@
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
-
-
-
+
+
+
+
-
+
-
+
-
-
-
+
+
+
-
+
@@ -10847,20 +10847,20 @@
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
@@ -10875,14 +10875,14 @@
-
-
+
+
-
+
-
+
@@ -10890,176 +10890,176 @@
-
-
-
+
+
+
-
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
This response must address all control sub-statement requirements.
-
+
-
+
This response must address all control sub-statement requirements.
-
-
-
+
+
+
-
+
-
-
-
+
+
+
-
+
-
-
-
+
+
+
-
+
-
-
-
+
+
+
-
+
-
-
-
+
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
-
-
+
+
+
-
+
@@ -11074,45 +11074,45 @@
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
+
-
-
-
-
+
+
+
+
-
+
@@ -11127,12 +11127,12 @@
-
-
-
+
+
+
-
+
@@ -11147,12 +11147,12 @@
-
-
-
+
+
+
-
+
@@ -11170,35 +11170,35 @@
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
diff --git a/src/content/rev5/examples/ssp/xml/fedramp-ssp-example.oscal.xml b/src/content/rev5/examples/ssp/xml/fedramp-ssp-example.oscal.xml
index ffb073ec3..ba2a537d8 100644
--- a/src/content/rev5/examples/ssp/xml/fedramp-ssp-example.oscal.xml
+++ b/src/content/rev5/examples/ssp/xml/fedramp-ssp-example.oscal.xml
@@ -12,7 +12,7 @@
2023-06-30T00:00:00Z
1.0
1.0.4
-
+
Initial publication.
@@ -21,14 +21,14 @@
2023-07-06T00:00:00Z
1.1
1.0.4
-
+
Minor prop
updates.
-
+
@@ -561,7 +561,7 @@
-
+
This example points to the FedRAMP Rev 5 Moderate baseline that is part of the official
FedRAMP 3.0.0 release.
@@ -605,10 +605,10 @@
-
+
-
+
fips-199-moderate
@@ -775,15 +775,15 @@
AwesomeCloud Commercial(IaaS)
-
-
+
+
For now, this is a required field. In the future we intend
to pull this information directly from FedRAMP's records
based on the "leveraged-system-identifier" property's value.
-
+
For now, this is a required field. In the future we intend
to pull this information directly from FedRAMP's records
@@ -804,10 +804,10 @@
-
+
-
-
+
+
system-poc-technical
Admin
@@ -825,10 +825,10 @@
-
+
-
-
+
+
system-poc-technical
@@ -837,10 +837,10 @@
-
+
-
-
+
+
system-poc-technical
Admin
@@ -851,10 +851,10 @@
-
+
-
-
+
+
system-poc-technical
Admin
@@ -865,9 +865,9 @@
-
-
-
+
+
+
system-owner
@@ -914,16 +914,16 @@
-
-
+
+
If 'yes', describe the authentication method.
If 'no', explain why no authentication is used.
If 'not-applicable', attest explain why authentication is not applicable in the remarks.
-
-
+
+
@@ -936,8 +936,8 @@
-
-
+
+
This is a leveraged system within which this system operates.
@@ -1028,13 +1028,13 @@
-
-
+
+
-
-
+
+
This is a service offered by a leveraged system and used by this system.
@@ -1088,21 +1088,21 @@
Describe the service and what it is used for.
-
-
-
-
-
+
+
+
+
+
If 'yes', describe the authentication method.
If 'no', explain why no authentication is used.
If 'not-applicable', attest explain why authentication is not applicable in the remarks.
-
-
-
-
+
+
+
+
@@ -1183,11 +1183,11 @@
An external system to which this system shares an interconnection.
-
-
-
+
+
+
-
+
If 'yes', describe the authentication method.
If 'no', explain why no authentication is used.
@@ -1197,10 +1197,10 @@
-
-
-
-
+
+
+
+
@@ -1267,34 +1267,34 @@
for connectivity (e.g., system monitoring, system alerting, download updates, etc.)
-
-
-
-
+
+
+
+
If 'yes', describe the authentication method in the remarks.
If 'no', explain why no authentication is used in the remarks.
If 'not-applicable', attest explain why authentication is not applicable in the remarks.
-
-
-
-
-
-
+
+
+
+
+
+
Describe the hosting of the interconnection itself (NOT the hosting of the remote system).
-
-
-
-
+
+
+
+
-
+
@@ -1367,8 +1367,8 @@
-
-
+
+
@@ -1414,16 +1414,16 @@
-
-
+
+
If 'yes', describe the authentication method in the remarks.
If 'no', explain why no authentication is used in the remarks.
If 'not-applicable', attest explain why authentication is not applicable in the remarks.
-
-
+
+
This can only be known if provided by the leveraged system.
@@ -1504,28 +1504,28 @@
-
-
-
-
+
+
+
+
If 'yes', describe the authentication method in the remarks.
If 'no', explain why no authentication is used in the remarks.
If 'not-applicable', attest explain why authentication is not applicable in the remarks.
-
+
Either describe a risk associated with this service, or indicate there is no identified risk.
If there is no risk, please explain your basis for that conclusion.
-
+
If there are one or more identified risks, describe any resulting impact.
-
+
If there are one or more identified risks, describe any mitigating factors.
@@ -1580,30 +1580,30 @@
-
-
-
-
+
+
+
+
If 'yes', describe the authentication method in the remarks.
If 'no', explain why no authentication is used in the remarks.
If 'not-applicable', attest explain why authentication is not applicable in the remarks.
-
-
-
+
+
+
Either describe a risk associated with this CLI, or indicate there is no identified risk.
If there is no risk, please explain your basis for that conclusion.
-
+
If there are one or more identified risks, describe any resulting impact.
-
+
If there are one or more identified risks, describe any mitigating factors.
@@ -1653,9 +1653,9 @@
compliance (e.g., Module in Process).
-
-
-
+
+
+
@@ -1672,9 +1672,9 @@
compliance (e.g., Module in Process).
-
-
-
+
+
+
@@ -1697,7 +1697,7 @@
FUNCTION: Describe typical component function.
-
+
@@ -1718,7 +1718,7 @@
FUNCTION: Describe typical component function.
-
+
@@ -1740,8 +1740,8 @@
FUNCTION: Describe typical component function.
-
-
+
+
@@ -1762,7 +1762,7 @@
None
-
+
@@ -1772,11 +1772,11 @@
None
-
+
-
-
-
+
+
+
If 'yes', describe the authentication method.
If 'no', explain why no authentication is used.
@@ -1784,15 +1784,15 @@
-
+
-
-
-
-
+
+
+
+
@@ -1814,8 +1814,8 @@
None
-
-
+
+
@@ -2195,11 +2195,11 @@
Email Service
-
+
-
-
-
+
+
+
If 'yes', describe the authentication method.
If 'no', explain why no authentication is used.
@@ -2207,10 +2207,10 @@
-
-
-
-
+
+
+
+
@@ -2252,8 +2252,8 @@
-
-
+
+
If no, explain why. If yes, omit remarks field.
@@ -2313,7 +2313,7 @@
If no, explain why. If yes, omit remark.
-
+
11111111-2222-4000-8000-004000000010
@@ -2339,7 +2339,7 @@
-
+
@@ -2353,7 +2353,7 @@
-
+
@@ -2367,7 +2367,7 @@
-
+
@@ -2398,7 +2398,7 @@
-
+
@@ -2429,7 +2429,7 @@
-
+
@@ -2446,7 +2446,7 @@
FedRAMP does not require any specific information here.
-
+
@@ -2488,7 +2488,7 @@
There
-
+
Describe the plan to complete the implementation.
@@ -2499,7 +2499,7 @@
Describe how this policy currently satisfies part a.
-
+
Describe the plan for addressing the missing policy elements.
@@ -2529,14 +2529,14 @@
-
-
+
+
Describe the plan to complete the implementation.
-
-
+
+
Describe any customer-configured requirements for satisfying this control.
@@ -2647,13 +2647,13 @@
-
-
+
+
Describe the plan to complete the implementation.
-
+
@@ -2712,13 +2712,13 @@
-
-
+
+
Describe the plan to complete the implementation.
-
+
@@ -2780,13 +2780,13 @@
-
-
+
+
Describe the plan to complete the implementation.
-
+
@@ -2845,13 +2845,13 @@
-
-
+
+
Describe the plan to complete the implementation.
-
+
@@ -2910,13 +2910,13 @@
-
-
+
+
Describe the plan to complete the implementation.
-
+
11111111-2222-4000-8000-004000000011
@@ -2973,7 +2973,7 @@
-
+
@@ -2986,7 +2986,7 @@
-
+
@@ -3002,7 +3002,7 @@
-
+
@@ -3015,7 +3015,7 @@
-
+
@@ -3028,7 +3028,7 @@
-
+
@@ -3041,7 +3041,7 @@
-
+
@@ -3054,7 +3054,7 @@
-
+
@@ -3067,7 +3067,7 @@
-
+
@@ -3080,7 +3080,7 @@
-
+
@@ -3093,7 +3093,7 @@
-
+
@@ -3106,7 +3106,7 @@
-
+
@@ -3119,7 +3119,7 @@
-
+
@@ -3132,7 +3132,7 @@
-
+
@@ -3145,7 +3145,7 @@
-
+
@@ -3158,13 +3158,13 @@
-
-
+
+
Describe the plan to complete the implementation.
-
+
@@ -3223,13 +3223,13 @@
-
-
+
+
Describe the plan to complete the implementation.
-
+
@@ -3288,13 +3288,13 @@
-
-
+
+
Describe the plan to complete the implementation.
-
+
@@ -3353,7 +3353,7 @@
-
+
@@ -3372,7 +3372,7 @@
-
+
@@ -3387,7 +3387,7 @@
-
+
@@ -3400,7 +3400,7 @@
-
+
@@ -3413,7 +3413,7 @@
-
+
@@ -3430,7 +3430,7 @@
-
+
@@ -3450,7 +3450,7 @@
-
+
@@ -3466,7 +3466,7 @@
-
+
@@ -3485,7 +3485,7 @@
-
+
@@ -3504,13 +3504,13 @@
-
-
+
+
Describe the plan to complete the implementation.
-
+
@@ -3569,13 +3569,13 @@
-
-
+
+
Describe the plan to complete the implementation.
-
+
@@ -3634,13 +3634,13 @@
-
-
+
+
Describe the plan to complete the implementation.
-
+
@@ -3699,13 +3699,13 @@
-
-
+
+
Describe the plan to complete the implementation.
-
+
@@ -3764,13 +3764,13 @@
-
-
+
+
Describe the plan to complete the implementation.
-
+
@@ -3829,13 +3829,13 @@
-
-
+
+
Describe the plan to complete the implementation.
-
+
@@ -3894,13 +3894,13 @@
-
-
+
+
Describe the plan to complete the implementation.
-
+
@@ -3959,13 +3959,13 @@
-
-
+
+
Describe the plan to complete the implementation.
-
+
@@ -4024,8 +4024,8 @@
-
-
+
+
11111111-2222-4000-8000-004000000018
@@ -4050,13 +4050,13 @@
-
-
+
+
Describe the plan to complete the implementation.
-
+
@@ -4101,8 +4101,8 @@
-
-
+
+
@@ -4112,8 +4112,8 @@
-
-
+
+
@@ -4123,8 +4123,8 @@
-
-
+
+
@@ -4134,8 +4134,8 @@
-
-
+
+
@@ -4145,8 +4145,8 @@
-
-
+
+
@@ -4156,8 +4156,8 @@
-
-
+
+
@@ -4167,8 +4167,8 @@
-
-
+
+
@@ -4178,8 +4178,8 @@
-
-
+
+
@@ -4189,8 +4189,8 @@
-
-
+
+
@@ -4200,8 +4200,8 @@
-
-
+
+
@@ -4211,8 +4211,8 @@
-
-
+
+
@@ -4222,8 +4222,8 @@
-
-
+
+
@@ -4233,8 +4233,8 @@
-
-
+
+
@@ -4244,8 +4244,8 @@
-
-
+
+
@@ -4255,8 +4255,8 @@
-
-
+
+
@@ -4266,8 +4266,8 @@
-
-
+
+
@@ -4277,8 +4277,8 @@
-
-
+
+
@@ -4288,8 +4288,8 @@
-
-
+
+
@@ -4299,8 +4299,8 @@
-
-
+
+
@@ -4310,8 +4310,8 @@
-
-
+
+
@@ -4321,8 +4321,8 @@
-
-
+
+
@@ -4332,8 +4332,8 @@
-
-
+
+
@@ -4343,8 +4343,8 @@
-
-
+
+
@@ -4354,8 +4354,8 @@
-
-
+
+
@@ -4365,8 +4365,8 @@
-
-
+
+
@@ -4376,8 +4376,8 @@
-
-
+
+
@@ -4387,8 +4387,8 @@
-
-
+
+
@@ -4398,8 +4398,8 @@
-
-
+
+
@@ -4409,8 +4409,8 @@
-
-
+
+
@@ -4420,8 +4420,8 @@
-
-
+
+
@@ -4431,8 +4431,8 @@
-
-
+
+
@@ -4442,8 +4442,8 @@
-
-
+
+
@@ -4453,8 +4453,8 @@
-
-
+
+
@@ -4464,8 +4464,8 @@
-
-
+
+
@@ -4475,8 +4475,8 @@
-
-
+
+
@@ -4486,8 +4486,8 @@
-
-
+
+
@@ -4497,8 +4497,8 @@
-
-
+
+
@@ -4508,8 +4508,8 @@
-
-
+
+
@@ -4519,8 +4519,8 @@
-
-
+
+
@@ -4530,8 +4530,8 @@
-
-
+
+
@@ -4541,8 +4541,8 @@
-
-
+
+
@@ -4552,8 +4552,8 @@
-
-
+
+
@@ -4563,8 +4563,8 @@
-
-
+
+
@@ -4574,8 +4574,8 @@
-
-
+
+
@@ -4585,8 +4585,8 @@
-
-
+
+
@@ -4596,8 +4596,8 @@
-
-
+
+
@@ -4607,8 +4607,8 @@
-
-
+
+
@@ -4618,8 +4618,8 @@
-
-
+
+
@@ -4629,8 +4629,8 @@
-
-
+
+
@@ -4640,8 +4640,8 @@
-
-
+
+
@@ -4651,8 +4651,8 @@
-
-
+
+
@@ -4662,8 +4662,8 @@
-
-
+
+
@@ -4673,8 +4673,8 @@
-
-
+
+
@@ -4684,8 +4684,8 @@
-
-
+
+
@@ -4695,8 +4695,8 @@
-
-
+
+
@@ -4706,8 +4706,8 @@
-
-
+
+
@@ -4717,8 +4717,8 @@
-
-
+
+
@@ -4728,8 +4728,8 @@
-
-
+
+
@@ -4739,8 +4739,8 @@
-
-
+
+
@@ -4750,8 +4750,8 @@
-
-
+
+
@@ -4761,8 +4761,8 @@
-
-
+
+
@@ -4772,8 +4772,8 @@
-
-
+
+
@@ -4783,8 +4783,8 @@
-
-
+
+
@@ -4794,8 +4794,8 @@
-
-
+
+
@@ -4805,8 +4805,8 @@
-
-
+
+
@@ -4816,8 +4816,8 @@
-
-
+
+
@@ -4827,8 +4827,8 @@
-
-
+
+
@@ -4838,8 +4838,8 @@
-
-
+
+
@@ -4849,8 +4849,8 @@
-
-
+
+
@@ -4860,8 +4860,8 @@
-
-
+
+
@@ -4871,8 +4871,8 @@
-
-
+
+
@@ -4882,8 +4882,8 @@
-
-
+
+
@@ -4893,8 +4893,8 @@
-
-
+
+
@@ -4904,8 +4904,8 @@
-
-
+
+
@@ -4915,8 +4915,8 @@
-
-
+
+
@@ -4926,8 +4926,8 @@
-
-
+
+
@@ -4937,8 +4937,8 @@
-
-
+
+
@@ -4948,8 +4948,8 @@
-
-
+
+
@@ -4959,8 +4959,8 @@
-
-
+
+
@@ -4970,8 +4970,8 @@
-
-
+
+
@@ -4981,8 +4981,8 @@
-
-
+
+
@@ -4992,8 +4992,8 @@
-
-
+
+
@@ -5003,8 +5003,8 @@
-
-
+
+
@@ -5014,8 +5014,8 @@
-
-
+
+
@@ -5025,8 +5025,8 @@
-
-
+
+
@@ -5036,8 +5036,8 @@
-
-
+
+
@@ -5047,8 +5047,8 @@
-
-
+
+
@@ -5058,8 +5058,8 @@
-
-
+
+
@@ -5069,8 +5069,8 @@
-
-
+
+
@@ -5080,8 +5080,8 @@
-
-
+
+
@@ -5091,8 +5091,8 @@
-
-
+
+
@@ -5102,8 +5102,8 @@
-
-
+
+
@@ -5113,8 +5113,8 @@
-
-
+
+
@@ -5124,8 +5124,8 @@
-
-
+
+
@@ -5135,8 +5135,8 @@
-
-
+
+
@@ -5146,8 +5146,8 @@
-
-
+
+
@@ -5157,8 +5157,8 @@
-
-
+
+
@@ -5168,8 +5168,8 @@
-
-
+
+
@@ -5179,8 +5179,8 @@
-
-
+
+
@@ -5190,8 +5190,8 @@
-
-
+
+
@@ -5201,8 +5201,8 @@
-
-
+
+
@@ -5212,8 +5212,8 @@
-
-
+
+
@@ -5223,8 +5223,8 @@
-
-
+
+
@@ -5234,8 +5234,8 @@
-
-
+
+
@@ -5245,8 +5245,8 @@
-
-
+
+
@@ -5256,8 +5256,8 @@
-
-
+
+
@@ -5267,8 +5267,8 @@
-
-
+
+
@@ -5278,8 +5278,8 @@
-
-
+
+
@@ -5289,8 +5289,8 @@
-
-
+
+
@@ -5300,8 +5300,8 @@
-
-
+
+
@@ -5311,8 +5311,8 @@
-
-
+
+
@@ -5322,8 +5322,8 @@
-
-
+
+
@@ -5333,8 +5333,8 @@
-
-
+
+
@@ -5344,8 +5344,8 @@
-
-
+
+
@@ -5355,8 +5355,8 @@
-
-
+
+
@@ -5366,8 +5366,8 @@
-
-
+
+
@@ -5377,8 +5377,8 @@
-
-
+
+
@@ -5388,8 +5388,8 @@
-
-
+
+
@@ -5399,8 +5399,8 @@
-
-
+
+
@@ -5410,8 +5410,8 @@
-
-
+
+
@@ -5421,8 +5421,8 @@
-
-
+
+
@@ -5432,8 +5432,8 @@
-
-
+
+
@@ -5443,8 +5443,8 @@
-
-
+
+
@@ -5454,8 +5454,8 @@
-
-
+
+
@@ -5465,8 +5465,8 @@
-
-
+
+
@@ -5476,8 +5476,8 @@
-
-
+
+
@@ -5487,8 +5487,8 @@
-
-
+
+
@@ -5498,8 +5498,8 @@
-
-
+
+
@@ -5509,8 +5509,8 @@
-
-
+
+
@@ -5520,8 +5520,8 @@
-
-
+
+
@@ -5531,8 +5531,8 @@
-
-
+
+
@@ -5542,8 +5542,8 @@
-
-
+
+
@@ -5553,8 +5553,8 @@
-
-
+
+
@@ -5564,8 +5564,8 @@
-
-
+
+
@@ -5575,8 +5575,8 @@
-
-
+
+
@@ -5586,8 +5586,8 @@
-
-
+
+
@@ -5597,8 +5597,8 @@
-
-
+
+
@@ -5608,8 +5608,8 @@
-
-
+
+
@@ -5619,8 +5619,8 @@
-
-
+
+
@@ -5630,8 +5630,8 @@
-
-
+
+
@@ -5641,8 +5641,8 @@
-
-
+
+
@@ -5652,8 +5652,8 @@
-
-
+
+
@@ -5663,8 +5663,8 @@
-
-
+
+
@@ -5674,8 +5674,8 @@
-
-
+
+
@@ -5685,8 +5685,8 @@
-
-
+
+
@@ -5696,8 +5696,8 @@
-
-
+
+
@@ -5707,8 +5707,8 @@
-
-
+
+
@@ -5718,8 +5718,8 @@
-
-
+
+
@@ -5729,8 +5729,8 @@
-
-
+
+
@@ -5740,8 +5740,8 @@
-
-
+
+
@@ -5751,8 +5751,8 @@
-
-
+
+
@@ -5762,8 +5762,8 @@
-
-
+
+
@@ -5773,8 +5773,8 @@
-
-
+
+
@@ -5784,8 +5784,8 @@
-
-
+
+
@@ -5795,8 +5795,8 @@
-
-
+
+
@@ -5806,8 +5806,8 @@
-
-
+
+
@@ -5817,8 +5817,8 @@
-
-
+
+
@@ -5828,8 +5828,8 @@
-
-
+
+
@@ -5839,8 +5839,8 @@
-
-
+
+
@@ -5850,8 +5850,8 @@
-
-
+
+
@@ -5861,8 +5861,8 @@
-
-
+
+
@@ -5872,8 +5872,8 @@
-
-
+
+
@@ -5883,8 +5883,8 @@
-
-
+
+
@@ -5894,8 +5894,8 @@
-
-
+
+
@@ -5905,8 +5905,8 @@
-
-
+
+
@@ -5916,8 +5916,8 @@
-
-
+
+
@@ -5927,8 +5927,8 @@
-
-
+
+
@@ -5938,8 +5938,8 @@
-
-
+
+
@@ -5949,8 +5949,8 @@
-
-
+
+
@@ -5960,8 +5960,8 @@
-
-
+
+
@@ -5971,8 +5971,8 @@
-
-
+
+
@@ -5982,8 +5982,8 @@
-
-
+
+
@@ -5993,8 +5993,8 @@
-
-
+
+
@@ -6004,8 +6004,8 @@
-
-
+
+
@@ -6015,8 +6015,8 @@
-
-
+
+
@@ -6026,8 +6026,8 @@
-
-
+
+
@@ -6037,8 +6037,8 @@
-
-
+
+
@@ -6048,8 +6048,8 @@
-
-
+
+
@@ -6059,8 +6059,8 @@
-
-
+
+
@@ -6070,8 +6070,8 @@
-
-
+
+
@@ -6081,8 +6081,8 @@
-
-
+
+
@@ -6092,8 +6092,8 @@
-
-
+
+
@@ -6103,8 +6103,8 @@
-
-
+
+
@@ -6114,8 +6114,8 @@
-
-
+
+
@@ -6125,8 +6125,8 @@
-
-
+
+
@@ -6136,8 +6136,8 @@
-
-
+
+
@@ -6147,8 +6147,8 @@
-
-
+
+
@@ -6158,8 +6158,8 @@
-
-
+
+
@@ -6169,8 +6169,8 @@
-
-
+
+
@@ -6180,8 +6180,8 @@
-
-
+
+
@@ -6191,8 +6191,8 @@
-
-
+
+
@@ -6202,8 +6202,8 @@
-
-
+
+
@@ -6213,8 +6213,8 @@
-
-
+
+
@@ -6224,8 +6224,8 @@
-
-
+
+
@@ -6235,8 +6235,8 @@
-
-
+
+
@@ -6246,8 +6246,8 @@
-
-
+
+
@@ -6257,8 +6257,8 @@
-
-
+
+
@@ -6268,8 +6268,8 @@
-
-
+
+
@@ -6279,8 +6279,8 @@
-
-
+
+
@@ -6290,8 +6290,8 @@
-
-
+
+
@@ -6301,8 +6301,8 @@
-
-
+
+
@@ -6312,8 +6312,8 @@
-
-
+
+
@@ -6323,8 +6323,8 @@
-
-
+
+
@@ -6334,8 +6334,8 @@
-
-
+
+
@@ -6345,8 +6345,8 @@
-
-
+
+
@@ -6356,8 +6356,8 @@
-
-
+
+
@@ -6367,8 +6367,8 @@
-
-
+
+
@@ -6378,8 +6378,8 @@
-
-
+
+
@@ -6389,8 +6389,8 @@
-
-
+
+
@@ -6400,8 +6400,8 @@
-
-
+
+
@@ -6411,8 +6411,8 @@
-
-
+
+
@@ -6422,8 +6422,8 @@
-
-
+
+
@@ -6433,8 +6433,8 @@
-
-
+
+
@@ -6444,8 +6444,8 @@
-
-
+
+
@@ -6455,8 +6455,8 @@
-
-
+
+
@@ -6466,8 +6466,8 @@
-
-
+
+
@@ -6477,8 +6477,8 @@
-
-
+
+
@@ -6488,8 +6488,8 @@
-
-
+
+
@@ -6499,8 +6499,8 @@
-
-
+
+
@@ -6510,8 +6510,8 @@
-
-
+
+
@@ -6521,8 +6521,8 @@
-
-
+
+
@@ -6532,8 +6532,8 @@
-
-
+
+
@@ -6543,8 +6543,8 @@
-
-
+
+
@@ -6554,8 +6554,8 @@
-
-
+
+
@@ -6565,8 +6565,8 @@
-
-
+
+
@@ -6576,8 +6576,8 @@
-
-
+
+
@@ -6587,8 +6587,8 @@
-
-
+
+
@@ -6598,8 +6598,8 @@
-
-
+
+
@@ -6609,8 +6609,8 @@
-
-
+
+
@@ -6620,8 +6620,8 @@
-
-
+
+
@@ -6631,8 +6631,8 @@
-
-
+
+
@@ -6642,8 +6642,8 @@
-
-
+
+
@@ -6653,8 +6653,8 @@
-
-
+
+
@@ -6664,8 +6664,8 @@
-
-
+
+
@@ -6675,8 +6675,8 @@
-
-
+
+
@@ -6686,8 +6686,8 @@
-
-
+
+
@@ -6697,8 +6697,8 @@
-
-
+
+
@@ -6708,8 +6708,8 @@
-
-
+
+
@@ -6719,8 +6719,8 @@
-
-
+
+
@@ -6730,8 +6730,8 @@
-
-
+
+
@@ -6741,8 +6741,8 @@
-
-
+
+
@@ -6752,8 +6752,8 @@
-
-
+
+
@@ -6763,8 +6763,8 @@
-
-
+
+
@@ -6774,8 +6774,8 @@
-
-
+
+
@@ -6785,8 +6785,8 @@
-
-
+
+
@@ -6796,8 +6796,8 @@
-
-
+
+
@@ -6807,8 +6807,8 @@
-
-
+
+
@@ -6818,8 +6818,8 @@
-
-
+
+
@@ -6829,8 +6829,8 @@
-
-
+
+
@@ -6840,8 +6840,8 @@
-
-
+
+
@@ -6851,8 +6851,8 @@
-
-
+
+
@@ -6862,8 +6862,8 @@
-
-
+
+
@@ -6873,8 +6873,8 @@
-
-
+
+
@@ -6884,8 +6884,8 @@
-
-
+
+
@@ -6895,8 +6895,8 @@
-
-
+
+
@@ -6906,8 +6906,8 @@
-
-
+
+
@@ -6917,8 +6917,8 @@
-
-
+
+
@@ -6928,8 +6928,8 @@
-
-
+
+
@@ -6939,8 +6939,8 @@
-
-
+
+
@@ -6950,8 +6950,8 @@
-
-
+
+
@@ -6961,8 +6961,8 @@
-
-
+
+
@@ -6972,8 +6972,8 @@
-
-
+
+
@@ -6983,8 +6983,8 @@
-
-
+
+
@@ -6994,8 +6994,8 @@
-
-
+
+
@@ -7005,8 +7005,8 @@
-
-
+
+
@@ -7016,8 +7016,8 @@
-
-
+
+
@@ -7027,8 +7027,8 @@
-
-
+
+
@@ -7038,8 +7038,8 @@
-
-
+
+
@@ -7049,8 +7049,8 @@
-
-
+
+
@@ -7060,8 +7060,8 @@
-
-
+
+
@@ -7071,8 +7071,8 @@
-
-
+
+
@@ -7082,8 +7082,8 @@
-
-
+
+
@@ -7093,8 +7093,8 @@
-
-
+
+
@@ -7104,8 +7104,8 @@
-
-
+
+
@@ -7115,8 +7115,8 @@
-
-
+
+
@@ -7126,8 +7126,8 @@
-
-
+
+
@@ -7137,8 +7137,8 @@
-
-
+
+
@@ -7149,8 +7149,8 @@
-
-
+
+
@@ -7160,8 +7160,8 @@
-
-
+
+
@@ -7171,8 +7171,8 @@
-
-
+
+
@@ -8054,7 +8054,7 @@
FedRAMP Logo
-
+
00000000
@@ -8201,7 +8201,7 @@
Separation of Duties Matrix
-
+
diff --git a/src/content/rev5/resources/xml/FedRAMP_extensions.xml b/src/content/rev5/resources/xml/FedRAMP_extensions.xml
index 1419b68ac..678bcce77 100644
--- a/src/content/rev5/resources/xml/FedRAMP_extensions.xml
+++ b/src/content/rev5/resources/xml/FedRAMP_extensions.xml
@@ -9,7 +9,7 @@
2023-06-30T00:00:00Z
DRAFT-01
-
+
Initial draft for fedramp-2.0.0-oscal-1.1.1 release. Subject to change.
@@ -94,7 +94,7 @@
-
+
@@ -349,7 +349,7 @@
-
+
Deprecated.
@@ -427,7 +427,7 @@
interconnection-direction
Interconnection Direction
Identifies the direction of information flow for the interconnection.
-
+
@@ -446,7 +446,7 @@
interconnection-security
Interconnection Security
Identifies the type of security applied to the interconnection.
-
+
@@ -1458,7 +1458,7 @@
Control Origination
The point(s) from which the control satisfaction originates.
-
+
Service Provider (Corporate)
@@ -1472,7 +1472,7 @@
Control Implementation Status Constraints
Defines the data type and allowed values for the Control Implementation Status
-
+
The assessor finds sufficient evidence to agree the control objective is fully implemented.
@@ -1491,7 +1491,7 @@
Remarks are required for certain Control Implementation Status values.
-
+
@@ -1509,10 +1509,10 @@
If the control implementation status is "Planned" a "Planned Implementation Date" must be provided.
3.1
-
-
-
-
+
+
+
+
In the SSP, if implemented-requirement
includes prop[@name='implementation-status']
with value='planned'
, a planned-completion-date
extension must be provided.
diff --git a/src/content/rev5/resources/xml/fedramp_threats.xml b/src/content/rev5/resources/xml/fedramp_threats.xml
index 39fe5fd84..45f113d05 100644
--- a/src/content/rev5/resources/xml/fedramp_threats.xml
+++ b/src/content/rev5/resources/xml/fedramp_threats.xml
@@ -1,5 +1,5 @@
-
+
FedRAMP Defined Threat Table [Experimental]
@@ -10,7 +10,7 @@
2023-06-30T00:00:00Z
DRAFT-01
-
+
Initial draft for fedramp-2.0.0-oscal-1.1.1 release. Subject to change.
diff --git a/src/content/rev5/resources/xml/fedramp_values.xml b/src/content/rev5/resources/xml/fedramp_values.xml
index c444ee15f..4e20625d4 100644
--- a/src/content/rev5/resources/xml/fedramp_values.xml
+++ b/src/content/rev5/resources/xml/fedramp_values.xml
@@ -1,6 +1,6 @@
+ xmlns="http://fedramp.gov/ns/oscal">
[EXPERIMENTAL] FedRAMP Defined Identifiers and Accepted Values
FedRAMP Data Values (Experimental)
@@ -13,7 +13,7 @@
DRAFT-01
Initial draft for fedramp-2.0.0-oscal-1.1.1 release. Subject to change.
@@ -28,7 +28,7 @@
+ ns="http://fedramp.gov/ns/oscal"/>
Authorization Type
The FedRAMP Authorization Type
+ pattern="system-characteristics/prop[@name='authorization-type'][@ns='http://fedramp.gov/ns/oscal']"/>
Deployment Model
The cloud deployment model.
+ pattern="system-characteristics/prop[@name='cloud-deployment-model'][@ns='http://fedramp.gov/ns/oscal']/@value"/>
Privacy Threshold Analysis (Q1)
Does the ISA collect, maintain, or share PII in any identifiable form?
+ pattern="system-information/prop[@name='pta-1'][@ns='http://fedramp.gov/ns/oscal']"/>
Privacy Threshold Analysis (Q2)
Does the ISA collect, maintain, share PII info from or about the public?
+ pattern="system-information/prop[@name='pta-2'][@ns='http://fedramp.gov/ns/oscal']"/>
Privacy Threshold Analysis (Q3)
Has a Privacy Impact Assessment ever been performed for the ISA?
+ pattern="system-information/prop[@name='pta-3'][@ns='http://fedramp.gov/ns/oscal']"/>
Privacy Threshold Analysis (Q4)
Is there a Privacy Act System of Records Notice (SORN) for this ISA system?
+ pattern="system-information/prop[@name='pta-4'][@ns='http://fedramp.gov/ns/oscal']"/>
User Sensitivity level
Identifies the sensitivity level of the user.
+ pattern="user/prop[@name='sensitivity'][@ns='http://fedramp.gov/ns/oscal']"/>
Interconnection Direction
Identifies the direction of information flow for the interconnection.
+ pattern="component[@component-type='interconnection']/prop[@name='interconnection-direction'][@ns='http://fedramp.gov/ns/oscal']"/>
Interconnection Security
Identifies the type of security applied to the interconnection.
+ pattern="component[@component-type='interconnection']/prop[@name='interconnection-security'][@ns='http://fedramp.gov/ns/oscal']/@value"/>
Scan Type
Identifies the type of scan.
+ pattern="component/prop[@name='scan-type'][@ns='http://fedramp.gov/ns/oscal']"/>
+ pattern="inventory-item/prop[@name='scan-type'][@ns='http://fedramp.gov/ns/oscal']"/>
Control Origination
The point(s) from which the control satisfaction originates.
+ pattern="implemented-requirement/prop[@name='control-origination'][@ns='http://fedramp.gov/ns/oscal']/@value"/>
Attachment Type
Identifies the type of attachment.
+ pattern="resource/prop[@name='type'][@ns='http://fedramp.gov/ns/oscal']"/>
-
+
FedRAMP Acceptable Information Types (Experimental)
2024-09-24T02:24:00Z
@@ -10,7 +10,7 @@
2023-06-30T00:00:00Z
DRAFT-01
-
+
Initial draft for fedramp-2.0.0-oscal-1.1.1 release.
diff --git a/src/content/rev5/templates/poam/xml/FedRAMP-POAM-OSCAL-Template.xml b/src/content/rev5/templates/poam/xml/FedRAMP-POAM-OSCAL-Template.xml
index 9c62e92a1..f0e87a167 100644
--- a/src/content/rev5/templates/poam/xml/FedRAMP-POAM-OSCAL-Template.xml
+++ b/src/content/rev5/templates/poam/xml/FedRAMP-POAM-OSCAL-Template.xml
@@ -9,7 +9,7 @@
1.0.4
-
+
@@ -134,8 +134,8 @@
Provide description
-
-
+
+
@@ -294,7 +294,7 @@
Describe the risk
-
+
open
@@ -346,17 +346,17 @@
This is a statement about the identified risk as provided by the tool.
This field must be present, but may be blank (or state 'No Risk Statement' if no statement is provided by the tool.
-
-
-
-
-
+
+
+
+
+
open
-
-
+
+
@@ -501,7 +501,7 @@
Provide description
-
+
@@ -514,7 +514,7 @@
An example set of infrastructure scan findings.
-
+
@@ -534,7 +534,7 @@
[System Name] [FIPS-199 Level] SSP
-
+
@@ -551,12 +551,12 @@
ONLY USE THIS RESOURCE WHEN NO OSCAL-BASED SSP EXISTS
Briefly describe the system. This will appear in the SAR.
-
-
-
-
-
-
+
+
+
+
+
+
Only include this resource if no OSCAL-based SSP is available.
Delete it otherwise.
@@ -565,7 +565,7 @@
FedRAMP Applicable Laws and Regulations
-
+
00000000
@@ -575,7 +575,7 @@
FedRAMP Master Acronym and Glossary
-
+
00000000
diff --git a/src/content/rev5/templates/sap/xml/FedRAMP-SAP-OSCAL-Template.xml b/src/content/rev5/templates/sap/xml/FedRAMP-SAP-OSCAL-Template.xml
index 22a3e5190..01719f8ff 100644
--- a/src/content/rev5/templates/sap/xml/FedRAMP-SAP-OSCAL-Template.xml
+++ b/src/content/rev5/templates/sap/xml/FedRAMP-SAP-OSCAL-Template.xml
@@ -9,12 +9,12 @@
1.0.4
-
+
-
-
+
+
-
+
@@ -125,7 +125,7 @@
Assessment Organization Name
Acronym/Short Name
-
+
2ba201ac-8ee9-4a1d-812a-a755591a3963
@@ -250,8 +250,8 @@
bcf47707-49e4-4acc-bf43-e63156046390
abc15ce6-1f43-4951-bcd5-ab62cdff7ed9
-
-
+
+
One or more parties
If the "responsible-party" contains multiple "party-uuid", FedRAMP assumes the "ia-validated" and "csp-validated" prop values apply to each referenced party.
@@ -261,8 +261,8 @@
9135b789-a40c-4a20-9be6-fab23c0ab0f3
-
-
+
+
e934d8b5-13e5-4f77-b55e-871e6f2df2fe
@@ -345,7 +345,7 @@
A known subnet, which is not defined in the SSP inventory.
-
+
Use any needed prop/annotation allowed in an SSP inventory-item.
@@ -365,11 +365,11 @@
-
+
-
-
+
+
Use any needed prop/annotation allowed in an SSP inventory-item.
@@ -389,9 +389,9 @@
-
+
-
+
Use any needed prop/annotation allowed in an SSP inventory-item.
@@ -493,25 +493,25 @@
Description of the manual test
-
-
+
+
Describe test step #1
-
+
Describe test step #2
-
+
Describe test step #3
-
+
@@ -520,8 +520,8 @@
We will login as a customer and try to see if we can gain access to the Network Administrator and Database Administrator privileges and authorizations by navigating to different views and manually forcing the browser to various URLs
-
-
+
+
[SAMPLE]CAPTCHA
@@ -529,8 +529,8 @@
We will test the CAPTCHA function on the web form manually
-
-
+
+
[SAMPLE]OCSP
@@ -538,8 +538,8 @@
We will manually test to see if OCSP is validating certificates.
-
-
+
+
Web Application Test #1
@@ -547,7 +547,7 @@
Describe this web application test.
-
+
Web Application Test #2
@@ -555,7 +555,7 @@
Describe this web application test.
-
+
Role Based Test #1
@@ -563,7 +563,7 @@
Describe this role based test.
-
+
Role Based Test #2
@@ -571,41 +571,41 @@
Describe this role based test.
-
+
-
+
Background
FedRAMP is a government-wide program that provides a standardized approach to security assessment, authorization, and continuous monitoring for cloud services. Security assessments are an integral part of the FedRAMP security authorization process.
Cloud services must be assessed by an IA. The use of an IA reduces the potential for conflicts of interest that could occur in verifying the implementation status and effectiveness of the security controls. National Institute of Standards and Technology (NIST) Special Publication (SP) 800-39, Managing Information Security Risk states:
-
+
Assessor independence is an important factor in: (i) preserving the impartial and unbiased nature of the assessment process; (ii) determining the credibility of the security assessment results; and (iii) ensuring that the authorizing official receives the most objective information possible in order to make an informed, risk-based, authorization decision.
-
+
Purpose
-
+
This SAP has been developed by [IA Name] and is for [an initial assessment/an annual assessment/an annual assessment and significant change assessment/a significant change assessment] of the [CSP Name], [CSO Name]. The SAP provides the goals for the assessment and details how the assessment will be conducted.
-
+
Applicable Laws, Regulations, Standards and Guidance
-
+
The FedRAMP-applicable laws, regulations, standards and guidance is included in the [CSO Name] SSP section – System Security Plan Approvals. Additionally, in Appendix L of the SSP, the [CSP Name] has included laws, regulations, standards, and guidance that apply specifically to this system.
-
+
Scope
-
+
Initial Assessment
-
+
This plan is for an initial assessment of [CSO Name], a [One: High/Moderate/ Low] baseline system. 100% of the FedRAMP security controls in the system baseline are assessed. The security controls that will be assessed are listed in Appendix A.
-
+
Annual Assessment
This plan is for an annual assessment of [CSO Name], a [One: High/Moderate/ Low] baseline system. After the initial security assessment, FedRAMP requires that the system is assessed annually thereafter (12 months from an agency ATO / JAB P-ATO date). While the entire set of security controls is assessed during the initial assessment, a subset is assessed during the annual assessment. The control selection is in accordance with the criteria outlined in the FedRAMP Annual Assessment Guidance and includes:
The detailed control list, including the rationale for each control’s selection, is included in SAP Appendix A, FedRAMP [CSO Name] Security Controls Selection Worksheet.
-
+
Significant Change
-
+
This document [is for/also includes] the assessment plan for [a significant change/several significant changes]. Appendix D includes the significant change request documentation submitted by [CSP Name] to the [AO/JAB].
Appendix A includes the associated control selections. [IA Name] will evaluate (review and/or test), as necessary, [all items related to continuous monitoring activities/all items related to continuous monitoring activities as well as those that are applicable to the significant change assessment/continuous monitoring activities that are only applicable to the significant change assessment], [IA Name] will evaluate all open POA&M items (including VDs); POA&M closures (to confirm adequate closure) and validate and confirm continued relevance and applicability of DRs ((false positives (FPs), risk adjustments (RAs), and operational requirements (ORs)) [(if significant change(s) are included): including those applicable to the significant change assessment/applicable only to the significant change assessment].
[CSO Name] leverages the FedRAMP Authorized CSOs listed in Table 3-2. [CSP Name], as a customer of these CSOs, must meet customer requirements documented by the leveraged CSOs in the customer responsibility matrix (CRM). Therefore, [IA Name] will validate to the best of their ability that [CSO Name] is in compliance with customer requirements documented in the CRMs of the leveraged CSOs.
@@ -639,7 +639,7 @@
-
+
Location of Component
The physical locations of all the different components that will be tested are described in Table 3-3.
@@ -657,7 +657,7 @@
-
+
IP Addresses Slated for Testing
SSP Appendix M, FedRAMP Integrated Inventory Workbook, captures the inventory items for the entire system and includes all the following required to be tested for the authorization of this system:
-
+
Role Testing Exclusions
-
+
Role Testing for Significant Change Requests
Additional roles that are being introduced as part of significant changes will be tested and are noted in Appendix D. Role testing will be performed to test the authorization restrictions for each role. [IA Name] will access the system while logged in as different user types and attempt to perform restricted functions for that user.
@@ -694,7 +694,7 @@
Assumptions
-
+
The following assumptions were agreed upon between [CSP Name] and [IA Name] when developing this SAP:
This SAP is based on [CSO Name] SSP [Version X.X], dated [MM/DD/YYYY], in its entirety. This includes all SSP appendices. The [CSP Name] is responsible for providing [IA Name] the most current SSP.
@@ -717,9 +717,9 @@
Methodology
-
+
Control Testing
-
+
[IA Name] will perform an assessment of the [CSO Name] security controls using the methodology described in NIST SP 800-53A, incorporating the methodology required by FedRAMP as noted below, and any other methods of testing that may be required to thoroughly test this system authorization boundary. [IA Name] will use the FedRAMP Security Requirements Traceability Matrix (SRTM) Workbook to evaluate the security controls. Contained in Excel worksheets, these test procedures contain the test objectives and associated test cases to determine if a control is effectively implemented and operating as intended. The results of the testing shall be recorded in the SRTM workbook for the appropriate High, Moderate, or Low baseline (provided on the FedRAMP Documents and Resources page under Templates) along with information that notes whether the control (or control enhancement) is satisfied or not.
[IA Name] will ensure that all [CSO Name] security controls that have an alternative implementation are included in the final SRTM workbook with test procedures that capture the intent of the control. [CSP Name] is advised that testing alternative control implementations involves additional IA rigor since it is much more difficult to prove the intent of the control is being met. The alternative control implementations that are tested for this assessment are:
-
+
Data Gathering
-
+
[IA Name] data gathering activities will consist of the following:
Request [CSP Name] to provide FedRAMP required documentation.
@@ -748,10 +748,10 @@
-
+
Sampling
-
-
+
+
The sampling methodology for evidence/artifact gathering, related to controls assessment, is described in Appendix B.
[IA Name] [will/will not] use sampling when performing vulnerability scanning.
[IA Name] [will/will not] use sampling when testing the following controls:
@@ -763,19 +763,19 @@
[IA Name] validates that all security controls required to be tested have appropriate sample sizes for items such as account requests, account terminations, account transfers, change control processes as captured in the [CSO Name] SSP, [Version X.X], [MM/DD/YYYY]. The controls sampling methodology is described in Appendix B.
-
-
+
+
The Penetration Test Plan and Methodology is attached in Appendix C.
-
+
Test Plan
The [IA Name] security assessment team, [CSP Name] points of contact, testing schedule, and testing tools that will be used are described in the sections that follow.
-
+
Security Assessment Team
-
+
The [IA Name] security assessment team consists of the individuals listed in Table 6-1. [CSP Name] is urged to check the capabilities of the named individuals to ensure that each is qualified to hold the position, per A2LA’s personnel requirements specified in the A2LA R311 - Specific Requirements: Federal Risk and Authorization Management Program (FedRAMP) .
Note that this document is signed in Section 8, by the [IA Name] and [CSP Name]. [CSP Name] has a right and a responsibility to ensure that competent assessors are providing the assessment services. The document should not be signed until [CSP Name] has validated the IA team.
@@ -795,9 +795,9 @@
-
+
CSP Testing Points of Contact (POCs)
-
+
The [CSP Name] POCs are found in Table 6-2. [IA Name] has internal processes to contact the CSP should the need arise.
@@ -814,7 +814,7 @@
Testing Performed Using Automated Tools
-
+
[IA Name] plans to use the following tools noted in Table 6-3 to perform testing of the [CSO Name].
-
+
Testing Performed Using Manual Methods
-
+
-
+
Schedule
-
+
The security assessment schedule can be found in Table 6-5. Any deviations from this accepted schedule are recorded in the SAR as Deviations.
@@ -877,12 +877,12 @@
Disclosures
-
-
+
+
Any testing will be performed according to the terms and conditions, cited in this SAP and the Penetration Testing ROE, once this SAP is signed by both parties. These ROEs must be upheld to minimize risk exposure that could occur during security assessment testing.
-
-
+
+
The following sections provide additional disclosures accepted by the IA and the CSP for proceeding with this Security Assessment.
@@ -890,47 +890,47 @@
Security Testing May Include
Every assessment requires certain disclosures. Sometimes a CSO may have the same disclosures as another CSO, but not usually. IAs and CSPs are required to ensure that all requirements contracted between the CSP and IA are adequate for both parties. Examples of inclusive disclosures appear below. Add to and delete from this list, as applicable.
-
+
Port scans and other network service interaction and queries
-
+
Port scans and other network service interaction and queries
-
+
Network sniffing, traffic monitoring, traffic analysis, and host discovery
-
+
Attempted logins or other use of systems, with any account name, token, password, and privilege
-
+
Attempted SQL injection and other forms of input parameter testing
-
+
Use of exploit code for leveraging discovered vulnerabilities
-
+
Password cracking via capture and scanning of authentication databases
-
+
Spoofing or deceiving servers regarding network traffic
-
+
Altering running system configuration except where denial of service would result
-
+
Adding user accounts
-
+
Adding other activities as needed...
@@ -939,35 +939,35 @@
Security Testing Will Not Include
Examples of exclusive disclosures appear below. Security testing will not include any of the following activities:
-
+
Changes to assigned user passwords
-
+
Modification of user files or system files
-
+
Telephone modem probes and scans (active and passive)
-
+
Intentional viewing of [CSP Name] staff email, Internet caches, and/or personnel cookie files
-
+
Denial of Service attacks
-
+
Exploits that will introduce new weaknesses to the system
-
+
Intentional introduction of malicious code (e.g., viruses, Trojans, worms, etc.)
-
+
Add exclusions here; however, be aware that FedRAMP may not agree with the exclusions listed (e.g., no testing of client side components indicated as imperative for use of the system)
@@ -976,28 +976,28 @@
End of Testing
-
+
[IA Name] will notify [Name of Person] at [CSP Name] when security testing has been completed.
Communications of Test Results
-
+
All documentation generated by this security assessment effort, is to be handled securely, in such a way to protect the confidentiality, integrity and availability of the data, and according to [CSP Name] and [IA Name] acceptable requirements. Security testing results will be provided and disclosed to the individual POCs at [CSP Name] as noted in this document. This should be accomplished within [Number of Days] days after security testing has been completed.
-
+
Limitation of Liability
-
+
[IA Name], and its stated partners, shall not be held liable to [CSP Name] for any and all liabilities, claims, or damages arising out of or relating to the security vulnerability testing portion of this Agreement, howsoever caused and regardless of the legal theory asserted, including breach of contract or warranty, tort, strict liability, statutory liability, or otherwise.
-
+
[CSP Name] acknowledges that there are limitations inherent in the methodologies implemented, and the assessment of security and vulnerability relating to information technology is an uncertain process based on past experiences, currently available information, and the anticipation of reasonable threats at the time of the analysis. There is no assurance that an analysis of this nature will identify all vulnerabilities or propose exhaustive and operationally viable recommendations to mitigate all exposure.
@@ -1031,9 +1031,9 @@
These are found in control statements (for CSPs to use in their SSP) and in control objectives (for assessors to use in their SAP and SAR).
SAP tools should scan the appropriate baseline (as identified by the SSP's import-profile
statement), find the response points associated with control objectives (ignoring response points associated with statements), and insert one include-objective
field for each identified response point.
For this task, tools should either scan the resolved profile catalog version of each baseline, or resolve the profile against its catalog before processing.
- XPath for all control objectie response points in a resolved profile catalog: //control/part[@name='objective']//prop[@name='response-point'][@ns='https://fedramp.gov/ns/oscal']/../@id
+
XPath for all control objectie response points in a resolved profile catalog: //control/part[@name='objective']//prop[@name='response-point'][@ns='http://fedramp.gov/ns/oscal']/../@id
- XPath for AC-2(f) control objective response points in a resolved profile catalog: //*/part[@name='objective' and contains(@id, 'ac-2.f')]/prop[@name='response-point'][@ns='https://fedramp.gov/ns/oscal']/../@id
+
XPath for AC-2(f) control objective response points in a resolved profile catalog: //*/part[@name='objective' and contains(@id, 'ac-2.f')]/prop[@name='response-point'][@ns='http://fedramp.gov/ns/oscal']/../@id
@@ -1138,7 +1138,7 @@
Describe assessment laptop.
-
+
Ideally, this assessment laptop would have been defined in the SAP, and not repeated here.
@@ -1150,8 +1150,8 @@
Describe the purpose of the tool here.
-
-
+
+
@@ -1160,8 +1160,8 @@
Describe the purpose of the tool here.
-
-
+
+
@@ -1174,9 +1174,9 @@
Scanning Tools
-
-
-
+
+
+
Cites assessment laptop.
@@ -1404,7 +1404,7 @@
[System Name] [FIPS-199 Level] SSP
-
+
@@ -1421,12 +1421,12 @@
ONLY USE THIS RESOURCE WHEN NO OSCAL-BASED SSP EXISTS
Briefly describe the system. This will appear in the SAR.
-
-
-
-
-
-
+
+
+
+
+
+
Only include this resource if no OSCAL-based SSP is available.
Delete it otherwise.
@@ -1435,7 +1435,7 @@
FedRAMP Applicable Laws and Regulations
-
+
00000000
@@ -1445,7 +1445,7 @@
FedRAMP Master Acronym and Glossary
-
+
00000000
@@ -1459,7 +1459,7 @@
The following individuals at [IA Name] and [CSP Name] have been identified as having the authority to agree to security testing of [CSO Name]. [CSP Name] has validated that the [IA Name] assessors assigned to this project fulfill the FedRAMP assessor requirements, as noted in Section 6.1 and formally named in Table 6-1. This section must be signed and dated prior to an IA beginning an assessment.
-
+
00000000
@@ -1479,7 +1479,7 @@
Embed or reference copies of the sampling methodology for security controls assessment and vulnerability scanning (if applicable).
-
+
@@ -1550,7 +1550,7 @@
-
+
00000000
@@ -1580,7 +1580,7 @@
-
+
diff --git a/src/content/rev5/templates/sar/xml/FedRAMP-SAR-OSCAL-Template.xml b/src/content/rev5/templates/sar/xml/FedRAMP-SAR-OSCAL-Template.xml
index 5541224da..5635d2e3e 100644
--- a/src/content/rev5/templates/sar/xml/FedRAMP-SAR-OSCAL-Template.xml
+++ b/src/content/rev5/templates/sar/xml/FedRAMP-SAR-OSCAL-Template.xml
@@ -9,7 +9,7 @@
1.0.4
-
+
@@ -114,7 +114,7 @@
Assessment Organization Name
Acronym/Short Name
-
+
2ba201ac-8ee9-4a1d-812a-a755591a3963
@@ -396,24 +396,24 @@
This describes an activity that was not defined in the SAP, but was performed during the assessment. The justification must be included.
-
+
Describe test step #1
-
+
Describe test step #2
-
+
Describe test step #3
-
+
@@ -430,7 +430,7 @@
A Windows laptop, which is not defined in the SSP inventory.
-
+
@@ -439,7 +439,7 @@
Describe assessment laptop.
-
+
Ideally, this assessment laptop would have been defined in the SAP, and not repeated here.
@@ -493,36 +493,36 @@
-
+
-
+
[IA Name] recommends this system for authorization.
-
+
[IA Name] does not recommend this system for authorization.
-
+
[IA Name] recommends this system for continued authorization.
-
+
[IA Name] does not recommend this system for continued authorization.
-
+
[IA Name] recommends the following [significant change/significant changes] for authorization:
[list significant changes approved for authorization]
-
+
[IA Name] does not recommend the following [significant change/significant changes] for authorization:
@@ -515,7 +515,7 @@
Separation of Duties Matrix
-
+
diff --git a/src/validations/constraints/content/ssp-component-has-authentication-method-INVALID.xml b/src/validations/constraints/content/ssp-component-has-authentication-method-INVALID.xml
index 41bba60e6..76c638f63 100644
--- a/src/validations/constraints/content/ssp-component-has-authentication-method-INVALID.xml
+++ b/src/validations/constraints/content/ssp-component-has-authentication-method-INVALID.xml
@@ -7,8 +7,8 @@
-
-
+
diff --git a/src/validations/constraints/content/ssp-fully-operational-date-type-INVALID-1.xml b/src/validations/constraints/content/ssp-fully-operational-date-type-INVALID-1.xml
index 9777a0709..903819fa8 100644
--- a/src/validations/constraints/content/ssp-fully-operational-date-type-INVALID-1.xml
+++ b/src/validations/constraints/content/ssp-fully-operational-date-type-INVALID-1.xml
@@ -5,7 +5,7 @@
uuid="12345678-1234-4321-8765-123456789012">
-
+
\ No newline at end of file
diff --git a/src/validations/constraints/content/ssp-fully-operational-date-type-INVALID-2.xml b/src/validations/constraints/content/ssp-fully-operational-date-type-INVALID-2.xml
index f56852859..d3dda7a06 100644
--- a/src/validations/constraints/content/ssp-fully-operational-date-type-INVALID-2.xml
+++ b/src/validations/constraints/content/ssp-fully-operational-date-type-INVALID-2.xml
@@ -5,7 +5,7 @@
uuid="12345678-1234-4321-8765-123456789012">
-
+
\ No newline at end of file
diff --git a/src/validations/constraints/content/ssp-has-authenticator-assurance-level-INVALID.xml b/src/validations/constraints/content/ssp-has-authenticator-assurance-level-INVALID.xml
index c44fa26ed..ee2130ab0 100644
--- a/src/validations/constraints/content/ssp-has-authenticator-assurance-level-INVALID.xml
+++ b/src/validations/constraints/content/ssp-has-authenticator-assurance-level-INVALID.xml
@@ -4,6 +4,6 @@
xsi:schemaLocation="http://csrc.nist.gov/ns/oscal/1.0 https://github.com/usnistgov/OSCAL/releases/download/v1.1.2/oscal_ssp_schema.xsd"
uuid="12345678-1234-4321-8765-123456789012">
-
+
diff --git a/src/validations/constraints/content/ssp-has-authorization-boundary-diagram-link-href-target-VALID-1.xml b/src/validations/constraints/content/ssp-has-authorization-boundary-diagram-link-href-target-VALID-1.xml
index 58e27a345..f9bab68de 100644
--- a/src/validations/constraints/content/ssp-has-authorization-boundary-diagram-link-href-target-VALID-1.xml
+++ b/src/validations/constraints/content/ssp-has-authorization-boundary-diagram-link-href-target-VALID-1.xml
@@ -10,7 +10,7 @@
1.1
1.1.2
SSP-2024-002
-
+
Document Creator
@@ -118,9 +118,9 @@
This is an enhanced example system for demonstration purposes, incorporating more FedRAMP-specific elements.
-
-
-
+
+
+
@@ -203,8 +203,8 @@
System Administrator
-
-
+
+
system-admin
Admin
@@ -234,8 +234,8 @@
Secure connection to an external API for data enrichment.
-
-
+
+
11111111-0000-4000-9000-000000000001
@@ -254,7 +254,7 @@
-
+
11111111-0000-4000-9000-000000000001
@@ -269,15 +269,15 @@
Implementation of controls for the Enhanced Example System
-
-
+
+
Access Control Policy and Procedures (AC-1) is fully implemented in our system.
-
+
11111111-0000-4000-9000-000000000001
@@ -285,14 +285,14 @@
-
+
Information System Component Inventory (CM-8) is partially implemented.
-
+
11111111-0000-4000-9000-000000000001
@@ -306,7 +306,7 @@
Detailed access control policy document
-
+
@@ -387,7 +387,7 @@
Separation of Duties Matrix
-
+
@@ -403,7 +403,7 @@
Authorization Boundary Diagram
-
+
@@ -418,7 +418,7 @@
Network Architecture Diagram
-
+
@@ -433,7 +433,7 @@
Data flow Diagram
-
+
diff --git a/src/validations/constraints/content/ssp-has-configuration-management-plan-INVALID.xml b/src/validations/constraints/content/ssp-has-configuration-management-plan-INVALID.xml
index d134e7119..ab9d648ee 100644
--- a/src/validations/constraints/content/ssp-has-configuration-management-plan-INVALID.xml
+++ b/src/validations/constraints/content/ssp-has-configuration-management-plan-INVALID.xml
@@ -8,7 +8,7 @@
Detailed access control policy document
-
+
diff --git a/src/validations/constraints/content/ssp-has-data-flow-diagram-link-href-target-VALID-1.xml b/src/validations/constraints/content/ssp-has-data-flow-diagram-link-href-target-VALID-1.xml
index e9b6b0087..70a94069d 100644
--- a/src/validations/constraints/content/ssp-has-data-flow-diagram-link-href-target-VALID-1.xml
+++ b/src/validations/constraints/content/ssp-has-data-flow-diagram-link-href-target-VALID-1.xml
@@ -10,7 +10,7 @@
1.1
1.1.2
SSP-2024-002
-
+
Document Creator
@@ -118,9 +118,9 @@
This is an enhanced example system for demonstration purposes, incorporating more FedRAMP-specific elements.
-
-
-
+
+
+
@@ -203,8 +203,8 @@
System Administrator
-
-
+
+
system-admin
Admin
@@ -234,8 +234,8 @@
Secure connection to an external API for data enrichment.
-
-
+
+
11111111-0000-4000-9000-000000000001
@@ -254,7 +254,7 @@
-
+
11111111-0000-4000-9000-000000000001
@@ -269,15 +269,15 @@
Implementation of controls for the Enhanced Example System
-
-
+
+
Access Control Policy and Procedures (AC-1) is fully implemented in our system.
-
+
11111111-0000-4000-9000-000000000001
@@ -285,14 +285,14 @@
-
+
Information System Component Inventory (CM-8) is partially implemented.
-
+
11111111-0000-4000-9000-000000000001
@@ -306,7 +306,7 @@
Detailed access control policy document
-
+
@@ -387,7 +387,7 @@
Separation of Duties Matrix
-
+
@@ -403,7 +403,7 @@
Authorization Boundary Diagram
-
+
@@ -418,7 +418,7 @@
Network Architecture Diagram
-
+
@@ -433,7 +433,7 @@
Data flow Diagram
-
+
diff --git a/src/validations/constraints/content/ssp-has-federation-assurance-level-INVALID.xml b/src/validations/constraints/content/ssp-has-federation-assurance-level-INVALID.xml
index 72e6dfad0..24c15bdec 100644
--- a/src/validations/constraints/content/ssp-has-federation-assurance-level-INVALID.xml
+++ b/src/validations/constraints/content/ssp-has-federation-assurance-level-INVALID.xml
@@ -4,6 +4,6 @@
xsi:schemaLocation="http://csrc.nist.gov/ns/oscal/1.0 https://github.com/usnistgov/OSCAL/releases/download/v1.1.2/oscal_ssp_schema.xsd"
uuid="12345678-1234-4321-8765-123456789012">
-
+
\ No newline at end of file
diff --git a/src/validations/constraints/content/ssp-has-identity-assurance-level-INVALID.xml b/src/validations/constraints/content/ssp-has-identity-assurance-level-INVALID.xml
index 72e6dfad0..24c15bdec 100644
--- a/src/validations/constraints/content/ssp-has-identity-assurance-level-INVALID.xml
+++ b/src/validations/constraints/content/ssp-has-identity-assurance-level-INVALID.xml
@@ -4,6 +4,6 @@
xsi:schemaLocation="http://csrc.nist.gov/ns/oscal/1.0 https://github.com/usnistgov/OSCAL/releases/download/v1.1.2/oscal_ssp_schema.xsd"
uuid="12345678-1234-4321-8765-123456789012">
-
+
\ No newline at end of file
diff --git a/src/validations/constraints/content/ssp-has-incident-response-plan-INVALID.xml b/src/validations/constraints/content/ssp-has-incident-response-plan-INVALID.xml
index d134e7119..ab9d648ee 100644
--- a/src/validations/constraints/content/ssp-has-incident-response-plan-INVALID.xml
+++ b/src/validations/constraints/content/ssp-has-incident-response-plan-INVALID.xml
@@ -8,7 +8,7 @@
Detailed access control policy document
-
+
diff --git a/src/validations/constraints/content/ssp-has-information-system-contingency-plan-INVALID.xml b/src/validations/constraints/content/ssp-has-information-system-contingency-plan-INVALID.xml
index d134e7119..ab9d648ee 100644
--- a/src/validations/constraints/content/ssp-has-information-system-contingency-plan-INVALID.xml
+++ b/src/validations/constraints/content/ssp-has-information-system-contingency-plan-INVALID.xml
@@ -8,7 +8,7 @@
Detailed access control policy document
-
+
diff --git a/src/validations/constraints/content/ssp-has-inventory-items-INVALID.xml b/src/validations/constraints/content/ssp-has-inventory-items-INVALID.xml
index e395ad924..ae3e4e5ac 100644
--- a/src/validations/constraints/content/ssp-has-inventory-items-INVALID.xml
+++ b/src/validations/constraints/content/ssp-has-inventory-items-INVALID.xml
@@ -14,7 +14,7 @@
-
+
11111111-0000-4000-9000-000000000001
diff --git a/src/validations/constraints/content/ssp-has-network-architecture-diagram-link-href-target-VALID-1.xml b/src/validations/constraints/content/ssp-has-network-architecture-diagram-link-href-target-VALID-1.xml
index 53592f60e..7ee2ad2c5 100644
--- a/src/validations/constraints/content/ssp-has-network-architecture-diagram-link-href-target-VALID-1.xml
+++ b/src/validations/constraints/content/ssp-has-network-architecture-diagram-link-href-target-VALID-1.xml
@@ -10,7 +10,7 @@
1.1
1.1.2
SSP-2024-002
-
+
Document Creator
@@ -115,9 +115,9 @@
This is an enhanced example system for demonstration purposes, incorporating more FedRAMP-specific elements.
-
-
-
+
+
+
@@ -200,8 +200,8 @@
System Administrator
-
-
+
+
system-admin
Admin
@@ -231,8 +231,8 @@
Secure connection to an external API for data enrichment.
-
-
+
+
11111111-0000-4000-9000-000000000001
@@ -251,7 +251,7 @@
-
+
11111111-0000-4000-9000-000000000001
@@ -266,15 +266,15 @@
Implementation of controls for the Enhanced Example System
-
-
+
+
Access Control Policy and Procedures (AC-1) is fully implemented in our system.
-
+
11111111-0000-4000-9000-000000000001
@@ -282,14 +282,14 @@
-
+
Information System Component Inventory (CM-8) is partially implemented.
-
+
11111111-0000-4000-9000-000000000001
@@ -303,7 +303,7 @@
Detailed access control policy document
-
+
@@ -384,7 +384,7 @@
Separation of Duties Matrix
-
+
@@ -400,7 +400,7 @@
Authorization Boundary Diagram
-
+
@@ -415,7 +415,7 @@
Network Architecture Diagram
-
+
@@ -430,7 +430,7 @@
Data flow Diagram
-
+
diff --git a/src/validations/constraints/content/ssp-has-rules-of-behavior-INVALID.xml b/src/validations/constraints/content/ssp-has-rules-of-behavior-INVALID.xml
index d134e7119..ab9d648ee 100644
--- a/src/validations/constraints/content/ssp-has-rules-of-behavior-INVALID.xml
+++ b/src/validations/constraints/content/ssp-has-rules-of-behavior-INVALID.xml
@@ -8,7 +8,7 @@
Detailed access control policy document
-
+
diff --git a/src/validations/constraints/content/ssp-has-user-guide-INVALID.xml b/src/validations/constraints/content/ssp-has-user-guide-INVALID.xml
index d134e7119..ab9d648ee 100644
--- a/src/validations/constraints/content/ssp-has-user-guide-INVALID.xml
+++ b/src/validations/constraints/content/ssp-has-user-guide-INVALID.xml
@@ -8,7 +8,7 @@
Detailed access control policy document
-
+
diff --git a/src/validations/constraints/content/ssp-import-profile-resolves-to-fedramp-content-VALID-1.xml b/src/validations/constraints/content/ssp-import-profile-resolves-to-fedramp-content-VALID-1.xml
index fcf746648..02f2ada98 100644
--- a/src/validations/constraints/content/ssp-import-profile-resolves-to-fedramp-content-VALID-1.xml
+++ b/src/validations/constraints/content/ssp-import-profile-resolves-to-fedramp-content-VALID-1.xml
@@ -10,7 +10,7 @@
1.1
1.1.2
SSP-2024-002
-
+
Document Creator
@@ -76,9 +76,9 @@
This is an enhanced example system for demonstration purposes, incorporating more FedRAMP-specific elements.
-
-
-
+
+
+
@@ -175,8 +175,8 @@
Secure connection to an external API for data enrichment.
-
-
+
+
11111111-0000-4000-9000-000000000001
@@ -195,7 +195,7 @@
-
+
11111111-0000-4000-9000-000000000001
@@ -210,15 +210,15 @@
Implementation of controls for the Enhanced Example System
-
-
+
+
Access Control Policy and Procedures (AC-1) is fully implemented in our system.
-
+
11111111-0000-4000-9000-000000000001
@@ -226,14 +226,14 @@
-
+
Information System Component Inventory (CM-8) is partially implemented.
-
+
11111111-0000-4000-9000-000000000001
@@ -247,7 +247,7 @@
Detailed access control policy document
-
+
@@ -328,7 +328,7 @@
Separation of Duties Matrix
-
+
@@ -344,7 +344,7 @@
Authorization Boundary Diagram
-
+
@@ -359,7 +359,7 @@
Network Architecture Diagram
-
+
@@ -374,7 +374,7 @@
Data flow Diagram
-
+
diff --git a/src/validations/constraints/content/ssp-import-profile-resolves-to-fedramp-content-VALID-2.xml b/src/validations/constraints/content/ssp-import-profile-resolves-to-fedramp-content-VALID-2.xml
index c423b81e2..a69708716 100644
--- a/src/validations/constraints/content/ssp-import-profile-resolves-to-fedramp-content-VALID-2.xml
+++ b/src/validations/constraints/content/ssp-import-profile-resolves-to-fedramp-content-VALID-2.xml
@@ -10,7 +10,7 @@
1.1
1.1.2
SSP-2024-002
-
+
Document Creator
@@ -76,9 +76,9 @@
This is an enhanced example system for demonstration purposes, incorporating more FedRAMP-specific elements.
-
-
-
+
+
+
@@ -175,8 +175,8 @@
Secure connection to an external API for data enrichment.
-
-
+
+
11111111-0000-4000-9000-000000000001
@@ -195,7 +195,7 @@
-
+
11111111-0000-4000-9000-000000000001
@@ -210,15 +210,15 @@
Implementation of controls for the Enhanced Example System
-
-
+
+
Access Control Policy and Procedures (AC-1) is fully implemented in our system.
-
+
11111111-0000-4000-9000-000000000001
@@ -226,14 +226,14 @@
-
+
Information System Component Inventory (CM-8) is partially implemented.
-
+
11111111-0000-4000-9000-000000000001
@@ -247,7 +247,7 @@
Detailed access control policy document
-
+
@@ -255,8 +255,8 @@
Profile to be imported
-
-
+
+
User's Guide
@@ -336,7 +336,7 @@
Separation of Duties Matrix
-
+
@@ -352,7 +352,7 @@
Authorization Boundary Diagram
-
+
@@ -367,7 +367,7 @@
Network Architecture Diagram
-
+
@@ -382,7 +382,7 @@
Data flow Diagram
-
+
diff --git a/src/validations/constraints/content/ssp-import-profile-resolves-to-fedramp-content-VALID-3.xml b/src/validations/constraints/content/ssp-import-profile-resolves-to-fedramp-content-VALID-3.xml
index b658e6310..481190f47 100644
--- a/src/validations/constraints/content/ssp-import-profile-resolves-to-fedramp-content-VALID-3.xml
+++ b/src/validations/constraints/content/ssp-import-profile-resolves-to-fedramp-content-VALID-3.xml
@@ -10,7 +10,7 @@
1.1
1.1.2
SSP-2024-002
-
+
Document Creator
@@ -76,9 +76,9 @@
This is an enhanced example system for demonstration purposes, incorporating more FedRAMP-specific elements.
-
-
-
+
+
+
@@ -175,8 +175,8 @@
Secure connection to an external API for data enrichment.
-
-
+
+
11111111-0000-4000-9000-000000000001
@@ -195,7 +195,7 @@
-
+
11111111-0000-4000-9000-000000000001
@@ -210,15 +210,15 @@
Implementation of controls for the Enhanced Example System
-
-
+
+
Access Control Policy and Procedures (AC-1) is fully implemented in our system.
-
+
11111111-0000-4000-9000-000000000001
@@ -226,14 +226,14 @@
-
+
Information System Component Inventory (CM-8) is partially implemented.
-
+
11111111-0000-4000-9000-000000000001
@@ -247,7 +247,7 @@
Detailed access control policy document
-
+
@@ -255,7 +255,7 @@
Profile to be imported
-
+
@@ -336,7 +336,7 @@
Separation of Duties Matrix
-
+
@@ -352,7 +352,7 @@
Authorization Boundary Diagram
-
+
@@ -367,7 +367,7 @@
Network Architecture Diagram
-
+
@@ -382,7 +382,7 @@
Data flow Diagram
-
+
diff --git a/src/validations/constraints/content/ssp-inter-boundary-component-direction-incoming-has-ipv-uri-INVALID.xml b/src/validations/constraints/content/ssp-inter-boundary-component-direction-incoming-has-ipv-uri-INVALID.xml
index adbd9b3ef..d71ab7754 100644
--- a/src/validations/constraints/content/ssp-inter-boundary-component-direction-incoming-has-ipv-uri-INVALID.xml
+++ b/src/validations/constraints/content/ssp-inter-boundary-component-direction-incoming-has-ipv-uri-INVALID.xml
@@ -13,8 +13,8 @@
-
-
+
+
diff --git a/src/validations/constraints/content/ssp-inter-boundary-component-has-direction-INVALID.xml b/src/validations/constraints/content/ssp-inter-boundary-component-has-direction-INVALID.xml
index 2bb436e61..8b4b3742b 100644
--- a/src/validations/constraints/content/ssp-inter-boundary-component-has-direction-INVALID.xml
+++ b/src/validations/constraints/content/ssp-inter-boundary-component-has-direction-INVALID.xml
@@ -13,10 +13,10 @@
-
-
-
-
+
+
+
+
diff --git a/src/validations/constraints/content/ssp-interconnection-direction-INVALID.xml b/src/validations/constraints/content/ssp-interconnection-direction-INVALID.xml
index 1a9a7bc8c..987fe20b7 100644
--- a/src/validations/constraints/content/ssp-interconnection-direction-INVALID.xml
+++ b/src/validations/constraints/content/ssp-interconnection-direction-INVALID.xml
@@ -9,8 +9,8 @@
Secure connection to an external API for data enrichment.
-
-
+
+
11111111-0000-4000-9000-000000000001
diff --git a/src/validations/constraints/content/ssp-interconnection-direction-VALID.xml b/src/validations/constraints/content/ssp-interconnection-direction-VALID.xml
index 715a29c66..8fe51dc65 100644
--- a/src/validations/constraints/content/ssp-interconnection-direction-VALID.xml
+++ b/src/validations/constraints/content/ssp-interconnection-direction-VALID.xml
@@ -10,7 +10,7 @@
1.1
1.1.2
SSP-2024-002
-
+
Authorizing Official
@@ -178,11 +178,11 @@
Remarks are required if service model is "other". Optional otherwise.
-
+
-
+
fips-199-moderate
@@ -262,9 +262,9 @@
GovCloud
-
-
-
+
+
+
f0bc13a4-3303-47dd-80d3-380e159c8362
2015-01-01
@@ -277,8 +277,8 @@
System Administrator
-
-
+
+
system-admin
Admin
@@ -306,13 +306,13 @@
CLI for updating firebase Secure connection to an external API for data enrichment.
-
+
Some description of the authentication method.
-
-
+
+
@@ -331,8 +331,8 @@
-
-
+
+
Some description of the external authentication method.
@@ -345,7 +345,7 @@
11111111-0000-4000-9000-000000000001
-
+
@@ -355,10 +355,10 @@
Secure connection to an external API for data enrichment.
-
-
-
-
+
+
+
+
Some description of the authentication method.
@@ -380,12 +380,12 @@
Briefly describe the external system.
-
-
+
+
-
-
+
+
Some description of the authentication method.
@@ -408,7 +408,7 @@
-
+
11111111-0000-4000-9000-000000000001
@@ -426,7 +426,7 @@
-
+
11111111-0000-4000-9000-000000000001
@@ -442,15 +442,15 @@
Implementation of controls for the Enhanced Example System
-
-
+
+
Access Control Policy and Procedures (AC-1) is fully implemented in our system.
-
+
11111111-0000-4000-9000-000000000001
@@ -458,14 +458,14 @@
-
+
Information System Component Inventory (CM-8) is partially implemented.
-
+
11111111-0000-4000-9000-000000000001
@@ -479,7 +479,7 @@
Detailed access control policy document
-
+
@@ -560,7 +560,7 @@
Separation of Duties Matrix
-
+
diff --git a/src/validations/constraints/content/ssp-interconnection-security-INVALID.xml b/src/validations/constraints/content/ssp-interconnection-security-INVALID.xml
index 1a9a7bc8c..987fe20b7 100644
--- a/src/validations/constraints/content/ssp-interconnection-security-INVALID.xml
+++ b/src/validations/constraints/content/ssp-interconnection-security-INVALID.xml
@@ -9,8 +9,8 @@
Secure connection to an external API for data enrichment.
-
-
+
+
11111111-0000-4000-9000-000000000001
diff --git a/src/validations/constraints/content/ssp-interconnection-security-VALID.xml b/src/validations/constraints/content/ssp-interconnection-security-VALID.xml
index 715a29c66..8fe51dc65 100644
--- a/src/validations/constraints/content/ssp-interconnection-security-VALID.xml
+++ b/src/validations/constraints/content/ssp-interconnection-security-VALID.xml
@@ -10,7 +10,7 @@
1.1
1.1.2
SSP-2024-002
-
+
Authorizing Official
@@ -178,11 +178,11 @@
Remarks are required if service model is "other". Optional otherwise.
-
+
-
+
fips-199-moderate
@@ -262,9 +262,9 @@
GovCloud
-
-
-
+
+
+
f0bc13a4-3303-47dd-80d3-380e159c8362
2015-01-01
@@ -277,8 +277,8 @@
System Administrator
-
-
+
+
system-admin
Admin
@@ -306,13 +306,13 @@
CLI for updating firebase Secure connection to an external API for data enrichment.
-
+
Some description of the authentication method.
-
-
+
+
@@ -331,8 +331,8 @@
-
-
+
+
Some description of the external authentication method.
@@ -345,7 +345,7 @@
11111111-0000-4000-9000-000000000001
-
+
@@ -355,10 +355,10 @@
Secure connection to an external API for data enrichment.
-
-
-
-
+
+
+
+
Some description of the authentication method.
@@ -380,12 +380,12 @@
Briefly describe the external system.
-
-
+
+
-
-
+
+
Some description of the authentication method.
@@ -408,7 +408,7 @@
-
+
11111111-0000-4000-9000-000000000001
@@ -426,7 +426,7 @@
-
+
11111111-0000-4000-9000-000000000001
@@ -442,15 +442,15 @@
Implementation of controls for the Enhanced Example System
-
-
+
+
Access Control Policy and Procedures (AC-1) is fully implemented in our system.
-
+
11111111-0000-4000-9000-000000000001
@@ -458,14 +458,14 @@
-
+
Information System Component Inventory (CM-8) is partially implemented.
-
+
11111111-0000-4000-9000-000000000001
@@ -479,7 +479,7 @@
Detailed access control policy document
-
+
@@ -560,7 +560,7 @@
Separation of Duties Matrix
-
+
diff --git a/src/validations/constraints/content/ssp-leveraged-authorization-has-valid-impact-level-INVALID.xml b/src/validations/constraints/content/ssp-leveraged-authorization-has-valid-impact-level-INVALID.xml
index 13bf1f266..e8f9caa20 100644
--- a/src/validations/constraints/content/ssp-leveraged-authorization-has-valid-impact-level-INVALID.xml
+++ b/src/validations/constraints/content/ssp-leveraged-authorization-has-valid-impact-level-INVALID.xml
@@ -4,7 +4,7 @@
-
+
\ No newline at end of file
diff --git a/src/validations/constraints/content/ssp-leveraged-authorization-has-valid-impact-level-VALID.xml b/src/validations/constraints/content/ssp-leveraged-authorization-has-valid-impact-level-VALID.xml
index f3c9ec506..d5b67b751 100644
--- a/src/validations/constraints/content/ssp-leveraged-authorization-has-valid-impact-level-VALID.xml
+++ b/src/validations/constraints/content/ssp-leveraged-authorization-has-valid-impact-level-VALID.xml
@@ -10,7 +10,7 @@
1.1
1.1.2
SSP-2024-002
-
+
Authorizing Official
@@ -178,11 +178,11 @@
Remarks are required if service model is "other". Optional otherwise.
-
+
-
+
fips-199-moderate
@@ -261,17 +261,17 @@
GovCloud
-
-
-
+
+
+
f0bc13a4-3303-47dd-80d3-380e159c8362
2020-01-01
System Administrator
-
-
+
+
system-admin
Admin
@@ -301,8 +301,8 @@
Secure connection to an external API for data enrichment.
-
-
+
+
11111111-0000-4000-9000-000000000001
@@ -321,7 +321,7 @@
-
+
11111111-0000-4000-9000-000000000001
@@ -339,7 +339,7 @@
-
+
11111111-0000-4000-9000-000000000001
@@ -355,15 +355,15 @@
Implementation of controls for the Enhanced Example System
-
-
+
+
Access Control Policy and Procedures (AC-1) is fully implemented in our system.
-
+
11111111-0000-4000-9000-000000000001
@@ -371,14 +371,14 @@
-
+
Information System Component Inventory (CM-8) is partially implemented.
-
+
11111111-0000-4000-9000-000000000001
@@ -392,7 +392,7 @@
Detailed access control policy document
-
+
@@ -473,7 +473,7 @@
Separation of Duties Matrix
-
+
@@ -489,7 +489,7 @@
Authorization Boundary Diagram
-
+
@@ -504,7 +504,7 @@
Network Architecture Diagram
-
+
@@ -519,7 +519,7 @@
Data flow Diagram
-
+
diff --git a/src/validations/constraints/content/ssp-leveraged-authorization-nature-of-agreement-INVALID.xml b/src/validations/constraints/content/ssp-leveraged-authorization-nature-of-agreement-INVALID.xml
index 560d3183d..96ce1e1a3 100644
--- a/src/validations/constraints/content/ssp-leveraged-authorization-nature-of-agreement-INVALID.xml
+++ b/src/validations/constraints/content/ssp-leveraged-authorization-nature-of-agreement-INVALID.xml
@@ -11,7 +11,7 @@
An external leveraged system.
-
+
diff --git a/src/validations/constraints/content/ssp-misplaced-response-components-INVALID.xml b/src/validations/constraints/content/ssp-misplaced-response-components-INVALID.xml
index 16ed10bf7..bb9d231ce 100644
--- a/src/validations/constraints/content/ssp-misplaced-response-components-INVALID.xml
+++ b/src/validations/constraints/content/ssp-misplaced-response-components-INVALID.xml
@@ -18,7 +18,7 @@
Implementation of controls for the System to be Authorized
-
+
diff --git a/src/validations/constraints/content/ssp-missing-response-components-INVALID.xml b/src/validations/constraints/content/ssp-missing-response-components-INVALID.xml
index 64e940884..851747a16 100644
--- a/src/validations/constraints/content/ssp-missing-response-components-INVALID.xml
+++ b/src/validations/constraints/content/ssp-missing-response-components-INVALID.xml
@@ -8,15 +8,15 @@
Implementation of controls for the Enhanced Example System
-
-
+
+
-
+
diff --git a/src/validations/constraints/content/ssp-network-component-has-connection-security-prop-INVALID.xml b/src/validations/constraints/content/ssp-network-component-has-connection-security-prop-INVALID.xml
index 1475cf502..6a7d3bad5 100644
--- a/src/validations/constraints/content/ssp-network-component-has-connection-security-prop-INVALID.xml
+++ b/src/validations/constraints/content/ssp-network-component-has-connection-security-prop-INVALID.xml
@@ -10,8 +10,8 @@
Secure connection to an external API for data enrichment.
-
-
+
+
11111111-0000-4000-9000-000000000001
diff --git a/src/validations/constraints/content/ssp-non-provider-responsible-role-references-user-INVALID.xml b/src/validations/constraints/content/ssp-non-provider-responsible-role-references-user-INVALID.xml
index 3416c1cd0..4f8997816 100644
--- a/src/validations/constraints/content/ssp-non-provider-responsible-role-references-user-INVALID.xml
+++ b/src/validations/constraints/content/ssp-non-provider-responsible-role-references-user-INVALID.xml
@@ -7,7 +7,7 @@
-
+
diff --git a/src/validations/constraints/content/ssp-privilege-level-INVALID.xml b/src/validations/constraints/content/ssp-privilege-level-INVALID.xml
index dcd963ded..84120558b 100644
--- a/src/validations/constraints/content/ssp-privilege-level-INVALID.xml
+++ b/src/validations/constraints/content/ssp-privilege-level-INVALID.xml
@@ -5,7 +5,7 @@
uuid="12345678-1234-4321-8765-123456789012">
-
+
\ No newline at end of file
diff --git a/src/validations/constraints/content/ssp-profile-response-point-INVALID.xml b/src/validations/constraints/content/ssp-profile-response-point-INVALID.xml
index b4839d067..d83e672c0 100644
--- a/src/validations/constraints/content/ssp-profile-response-point-INVALID.xml
+++ b/src/validations/constraints/content/ssp-profile-response-point-INVALID.xml
@@ -93,8 +93,8 @@
-
-
+
+
diff --git a/src/validations/constraints/content/ssp-resource-has-base64-or-rlink-INVALID.xml b/src/validations/constraints/content/ssp-resource-has-base64-or-rlink-INVALID.xml
index d134e7119..ab9d648ee 100644
--- a/src/validations/constraints/content/ssp-resource-has-base64-or-rlink-INVALID.xml
+++ b/src/validations/constraints/content/ssp-resource-has-base64-or-rlink-INVALID.xml
@@ -8,7 +8,7 @@
Detailed access control policy document
-
+
diff --git a/src/validations/constraints/content/ssp-resource-has-title-INVALID.xml b/src/validations/constraints/content/ssp-resource-has-title-INVALID.xml
index d134e7119..ab9d648ee 100644
--- a/src/validations/constraints/content/ssp-resource-has-title-INVALID.xml
+++ b/src/validations/constraints/content/ssp-resource-has-title-INVALID.xml
@@ -8,7 +8,7 @@
Detailed access control policy document
-
+
diff --git a/src/validations/constraints/content/ssp-responsible-party-is-person-INVALID.xml b/src/validations/constraints/content/ssp-responsible-party-is-person-INVALID.xml
index 321c778df..77558dca9 100644
--- a/src/validations/constraints/content/ssp-responsible-party-is-person-INVALID.xml
+++ b/src/validations/constraints/content/ssp-responsible-party-is-person-INVALID.xml
@@ -45,7 +45,7 @@
US
-
+
Example Organization
diff --git a/src/validations/constraints/content/ssp-responsible-party-prepared-by-location-valid-VALID-1.xml b/src/validations/constraints/content/ssp-responsible-party-prepared-by-location-valid-VALID-1.xml
index deffeb3d5..cbdb9aa0b 100644
--- a/src/validations/constraints/content/ssp-responsible-party-prepared-by-location-valid-VALID-1.xml
+++ b/src/validations/constraints/content/ssp-responsible-party-prepared-by-location-valid-VALID-1.xml
@@ -10,7 +10,7 @@
1.1
1.1.2
SSP-2024-002
-
+
Prepared By
@@ -142,9 +142,9 @@
This is an enhanced example system for demonstration purposes, incorporating more FedRAMP-specific elements.
-
-
-
+
+
+
@@ -227,8 +227,8 @@
System Administrator
-
-
+
+
system-admin
Admin
@@ -258,8 +258,8 @@
Secure connection to an external API for data enrichment.
-
-
+
+
11111111-0000-4000-9000-000000000001
@@ -278,7 +278,7 @@
-
+
11111111-0000-4000-9000-000000000001
@@ -293,15 +293,15 @@
Implementation of controls for the Enhanced Example System
-
-
+
+
Access Control Policy and Procedures (AC-1) is fully implemented in our system.
-
+
11111111-0000-4000-9000-000000000001
@@ -309,14 +309,14 @@
-
+
Information System Component Inventory (CM-8) is partially implemented.
-
+
11111111-0000-4000-9000-000000000001
@@ -330,7 +330,7 @@
Detailed access control policy document
-
+
@@ -411,7 +411,7 @@
Separation of Duties Matrix
-
+
@@ -427,7 +427,7 @@
Authorization Boundary Diagram
-
+
@@ -442,7 +442,7 @@
Network Architecture Diagram
-
+
@@ -457,7 +457,7 @@
Data flow Diagram
-
+
diff --git a/src/validations/constraints/content/ssp-responsible-party-prepared-for-location-valid-VALID-1.xml b/src/validations/constraints/content/ssp-responsible-party-prepared-for-location-valid-VALID-1.xml
index 2cbfddbc6..ec321dfc2 100644
--- a/src/validations/constraints/content/ssp-responsible-party-prepared-for-location-valid-VALID-1.xml
+++ b/src/validations/constraints/content/ssp-responsible-party-prepared-for-location-valid-VALID-1.xml
@@ -10,7 +10,7 @@
1.1
1.1.2
SSP-2024-002
-
+
Prepared For
@@ -138,9 +138,9 @@
This is an enhanced example system for demonstration purposes, incorporating more FedRAMP-specific elements.
-
-
-
+
+
+
@@ -223,8 +223,8 @@
System Administrator
-
-
+
+
system-admin
Admin
@@ -254,8 +254,8 @@
Secure connection to an external API for data enrichment.
-
-
+
+
11111111-0000-4000-9000-000000000001
@@ -274,7 +274,7 @@
-
+
11111111-0000-4000-9000-000000000001
@@ -289,15 +289,15 @@
Implementation of controls for the Enhanced Example System
-
-
+
+
Access Control Policy and Procedures (AC-1) is fully implemented in our system.
-
+
11111111-0000-4000-9000-000000000001
@@ -305,14 +305,14 @@
-
+
Information System Component Inventory (CM-8) is partially implemented.
-
+
11111111-0000-4000-9000-000000000001
@@ -326,7 +326,7 @@
Detailed access control policy document
-
+
@@ -407,7 +407,7 @@
Separation of Duties Matrix
-
+
@@ -423,7 +423,7 @@
Authorization Boundary Diagram
-
+
@@ -438,7 +438,7 @@
Network Architecture Diagram
-
+
@@ -453,7 +453,7 @@
Data flow Diagram
-
+
diff --git a/src/validations/constraints/content/ssp-saas-has-leveraged-authorization-VALID.xml b/src/validations/constraints/content/ssp-saas-has-leveraged-authorization-VALID.xml
index d501f09d9..072ec3217 100644
--- a/src/validations/constraints/content/ssp-saas-has-leveraged-authorization-VALID.xml
+++ b/src/validations/constraints/content/ssp-saas-has-leveraged-authorization-VALID.xml
@@ -10,7 +10,7 @@
1.1
1.1.2
SSP-2024-002
-
+
@@ -173,11 +173,11 @@
Remarks are required if service model is "other". Optional otherwise.
-
+
-
+
fips-199-moderate
@@ -272,8 +272,8 @@
System Administrator
-
-
+
+
system-admin
Admin
@@ -303,8 +303,8 @@
Secure connection to an external API for data enrichment.
-
-
+
+
11111111-0000-4000-9000-000000000001
@@ -323,7 +323,7 @@
-
+
11111111-0000-4000-9000-000000000001
@@ -341,7 +341,7 @@
-
+
11111111-0000-4000-9000-000000000001
@@ -357,15 +357,15 @@
Implementation of controls for the Enhanced Example System
-
-
+
+
Access Control Policy and Procedures (AC-1) is fully implemented in our system.
-
+
11111111-0000-4000-9000-000000000001
@@ -373,14 +373,14 @@
-
+
Information System Component Inventory (CM-8) is partially implemented.
-
+
11111111-0000-4000-9000-000000000001
@@ -394,7 +394,7 @@
Detailed access control policy document
-
+
@@ -475,7 +475,7 @@
Separation of Duties Matrix
-
+
@@ -491,7 +491,7 @@
Authorization Boundary Diagram
-
+
@@ -506,7 +506,7 @@
Network Architecture Diagram
-
+
@@ -521,7 +521,7 @@
Data flow Diagram
-
+
diff --git a/src/validations/constraints/content/ssp-scan-type-INVALID.xml b/src/validations/constraints/content/ssp-scan-type-INVALID.xml
index 4e64d0cbf..4c6c62b54 100644
--- a/src/validations/constraints/content/ssp-scan-type-INVALID.xml
+++ b/src/validations/constraints/content/ssp-scan-type-INVALID.xml
@@ -5,7 +5,7 @@
uuid="12345678-1234-4321-8765-123456789012">
-
+
diff --git a/src/validations/constraints/content/ssp-unique-inventory-item-asset-id-INVALID.xml b/src/validations/constraints/content/ssp-unique-inventory-item-asset-id-INVALID.xml
index 5460bc49d..06768b340 100644
--- a/src/validations/constraints/content/ssp-unique-inventory-item-asset-id-INVALID.xml
+++ b/src/validations/constraints/content/ssp-unique-inventory-item-asset-id-INVALID.xml
@@ -9,7 +9,7 @@
-
+
11111111-0000-4000-9000-000000000001
@@ -26,7 +26,7 @@
-
+
11111111-0000-4000-9000-000000000001
diff --git a/src/validations/constraints/content/ssp-user-authentication-INVALID.xml b/src/validations/constraints/content/ssp-user-authentication-INVALID.xml
index 2f95792f2..beddedf80 100644
--- a/src/validations/constraints/content/ssp-user-authentication-INVALID.xml
+++ b/src/validations/constraints/content/ssp-user-authentication-INVALID.xml
@@ -7,8 +7,8 @@
-
-
+
+
If 'yes', describe the authentication method.
If 'no', explain why no authentication is used.
@@ -24,8 +24,8 @@
-
-
+
+
If 'yes', describe the authentication method.
If 'no', explain why no authentication is used.
@@ -36,9 +36,9 @@
-
-
-
+
+
+
If 'yes', describe the authentication method in the remarks.
If 'no', explain why no authentication is used in the remarks.
@@ -54,7 +54,7 @@
-
+
If 'yes', describe the authentication method in the remarks.
If 'no', explain why no authentication is used in the remarks.
@@ -70,7 +70,7 @@
-
+
If 'yes', describe the authentication method in the remarks.
If 'no', explain why no authentication is used in the remarks.
diff --git a/src/validations/constraints/content/ssp-user-privilege-level-INVALID.xml b/src/validations/constraints/content/ssp-user-privilege-level-INVALID.xml
index 695e56111..d7b35a773 100644
--- a/src/validations/constraints/content/ssp-user-privilege-level-INVALID.xml
+++ b/src/validations/constraints/content/ssp-user-privilege-level-INVALID.xml
@@ -2,7 +2,7 @@
-
+
diff --git a/src/validations/constraints/content/ssp-user-sensitivity-level-INVALID.xml b/src/validations/constraints/content/ssp-user-sensitivity-level-INVALID.xml
index a1e2b8801..6332bfb15 100644
--- a/src/validations/constraints/content/ssp-user-sensitivity-level-INVALID.xml
+++ b/src/validations/constraints/content/ssp-user-sensitivity-level-INVALID.xml
@@ -2,7 +2,7 @@
-
+
diff --git a/src/validations/constraints/fedramp-external-allowed-values.xml b/src/validations/constraints/fedramp-external-allowed-values.xml
index 82e467efa..bc71ed801 100644
--- a/src/validations/constraints/fedramp-external-allowed-values.xml
+++ b/src/validations/constraints/fedramp-external-allowed-values.xml
@@ -30,7 +30,7 @@
Controlled Unclassified Information
-
+
Attachment Type
Identifies the type of attachment.
Law or Statute
@@ -71,7 +71,7 @@
-
+
Authorization Type
The FedRAMP Authorization Type
FedRAMP JAB P-ATO
@@ -127,7 +127,7 @@
Other
-
+
Nature of Agreement for External Systems
Identifies nature of agreement for external systems.
@@ -140,13 +140,13 @@
A service-level agreement between the CSP and the organization that owns the external system.
-
+
FedRAMP Version
Identifies the FedRAMP version of the document.
FedRAMP Version
-
+
NIST SP 800-60 Volume 2 Revision 1 Information Types
Contains a list of all supported information types from NIST SP 800-60 Volume 2 Revision 1.
Controls and Oversight: Corrective Action Information Type as defined by NIST.SP.800-60v2r1
@@ -326,7 +326,7 @@
NIST SP 800-60 Volume 2 Revision 1
-
+
Interconnection Direction
Identifies the direction of information flow for the interconnection.
Incoming
@@ -334,7 +334,7 @@
Bi-Directional
-
+
Interconnection Security
Identifies the type of security applied to the interconnection.
IPsec
@@ -367,7 +367,7 @@
No
-
+
Nature of Agreement for Leveraged Authorizations
Identifies nature of agreement for leveraged authorizations.
@@ -379,7 +379,7 @@
A service-level agreement between the CSP and the organization that owns the leveraged system.
-
+
Privilege Level
The privilege level of the user.
@@ -389,7 +389,7 @@
No Access
-
+
Scan Type
Identifies the type of scan.
Infrastructure and Operating System Scan
@@ -398,7 +398,7 @@
Other
-
+
User Authentication
Identifies if user authentication is required.
@@ -412,7 +412,7 @@
-
+
Privilege Level
The privilege level of the user.
@@ -422,7 +422,7 @@
No Access
-
+
User Sensitvity Level
Sensitivity level of the user.
diff --git a/src/validations/constraints/fedramp-external-constraints.xml b/src/validations/constraints/fedramp-external-constraints.xml
index db02b599b..690649a6d 100644
--- a/src/validations/constraints/fedramp-external-constraints.xml
+++ b/src/validations/constraints/fedramp-external-constraints.xml
@@ -31,7 +31,7 @@
-
+
Prop Response Point Has Cardinality One
MUST NOT have Duplicate response point at '{ path(.) }'.
@@ -55,24 +55,24 @@
else if (system-characteristics/security-sensitivity-level = 'fips-199-moderate')
then ('fips-199-moderate', 'fips-199-high')
else ('fips-199-low', 'fips-199-moderate', 'fips-199-high')"/>
-
+
-
+
-
+
Component Has Authentication Method
A FedRAMP SSP MUST include at least one authentication method for each leveraged system.
-
+
Component Has Non-Provider Responsible Role
A FedRAMP SSP MUST have each component describing leveraged systems, interconnections, or authorized services identify at least one responsible role other than "provider".
-
+
Component Has Provider Responsible Role
A FedRAMP SSP MUST have each component describing leveraged systems, interconnections, or authorized services identify a "provider" role that references one responsible party.
@@ -82,7 +82,7 @@
A FedRAMP SSP MUST import a profile or catalog with a valid file or HTTP(S) address.
-
+
Import Profile resolves to Fedramp content
A FedRAMP SSP MUST import a profile or catalog of security controls to reference implemented requirements against those control(s).
@@ -90,7 +90,7 @@
A FedRAMP SSP MUST use a valid FedRAMP catalog to reference security controls. It MUST NOT reference controls from a non-FedRAMP catalog.
-
+
Leveraged Authorization Has Valid Impact Level
A FedRAMP SSP MUST define the appropriate FIPS-199 impact level (low, moderate, or high) for each leveraged authorization.
@@ -322,12 +322,12 @@
A FedRAMP SSP information type confidentiality, integrity, or availability impact MUST specify the selected impact.
-
+
Fully Operational Date Is Valid
A system MUST be fully implemented prior to submitting the SSP to FedRAMP.
-
+
Fully Operational Date Type
A FedRAMP SSP MUST specify the system's fully operational data as a "full-date" per RFC3339 with the addition of a timezone.
@@ -440,7 +440,7 @@
A FedRAMP SSP MUST define its NIST SP 800-63 federation assurance level (FAL).
-
+
Fully Operational Date
A FedRAMP SSP MUST define the system's fully operational date.
@@ -536,8 +536,8 @@
-
-