diff --git a/src/validations/constraints/content/ssp-address-type-INVALID.xml b/src/validations/constraints/content/ssp-address-type-INVALID.xml index 762b59e93..51771a8cb 100644 --- a/src/validations/constraints/content/ssp-address-type-INVALID.xml +++ b/src/validations/constraints/content/ssp-address-type-INVALID.xml @@ -4,213 +4,8 @@ xsi:schemaLocation="http://csrc.nist.gov/ns/oscal/1.0 https://github.com/usnistgov/OSCAL/releases/download/v1.1.2/oscal_ssp_schema.xsd" uuid="12345678-1234-4321-8765-123456789012"> - Enhanced Example System Security Plan - 2024-08-01T14:30:00Z - 2024-08-01T14:30:00Z - 1.1 - 1.0.0 - SSP-2024-002 - - - Document Creator - - - Content Approver - - - System Administrator - - - Asset Owner - - -
- WRONG -
- -
- Example Organization - ExOrg -
- - Jane Doe - jane.doe@example.com -
- - - - 11111111-0000-4000-9000-000000000001 - - - 22222222-0000-4000-9000-000000000002 - - - -

This SSP is an example for demonstration purposes.

-
- - - - - F00000001 - Enhanced Example System - -

This is an enhanced example system for demonstration purposes, incorporating more FedRAMP-specific elements.

-
- - - - moderate - - - Financial Information - -

Contains sensitive financial data related to organizational operations.

-
- - - - high - - - moderate - - - low - -
-
- - - moderate - moderate - moderate - - - - - - -

The authorization boundary includes all components within the main data center and the disaster recovery site.

-
- - - -
- - -

A holistic, top-level explanation of the network architecture.

-
- - - -
-
- - - - System Administrator - - - system-admin - - - - Primary Application Server - -

Main application server hosting the core system functionality.

-
- main line - - - 11111111-0000-4000-9000-000000000001 - - -

This is the primary application server for the system.

-
-
- - - External API Connection - -

Secure connection to an external API for data enrichment.

-
- - - - - 11111111-0000-4000-9000-000000000001 - - -

This connection is used for secure data exchange with external systems.

-
-
- - - -

Primary database server

-
- - - - - - - - 11111111-0000-4000-9000-000000000001 - - - - -
-
- - - -

Implementation of controls for the Enhanced Example System

-
- - - - - - - -

Access Control Policy and Procedures (AC-1) is fully implemented in our system.

-
- - - 11111111-0000-4000-9000-000000000001 - -
-
- - - - - - - -

Information System Component Inventory (CM-8) is partially implemented.

-
- - - 11111111-0000-4000-9000-000000000001 - -
-
-
- - - - -

Detailed access control policy document

-
- -
-
- + \ No newline at end of file diff --git a/src/validations/constraints/content/ssp-attachment-type-INVALID.xml b/src/validations/constraints/content/ssp-attachment-type-INVALID.xml index 762b59e93..d06c671c3 100644 --- a/src/validations/constraints/content/ssp-attachment-type-INVALID.xml +++ b/src/validations/constraints/content/ssp-attachment-type-INVALID.xml @@ -3,213 +3,8 @@ xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://csrc.nist.gov/ns/oscal/1.0 https://github.com/usnistgov/OSCAL/releases/download/v1.1.2/oscal_ssp_schema.xsd" uuid="12345678-1234-4321-8765-123456789012"> - - Enhanced Example System Security Plan - 2024-08-01T14:30:00Z - 2024-08-01T14:30:00Z - 1.1 - 1.0.0 - SSP-2024-002 - - - Document Creator - - - Content Approver - - - System Administrator - - - Asset Owner - - -
- WRONG -
- -
- - Example Organization - ExOrg - -
- - - Jane Doe - jane.doe@example.com -
- - - - 11111111-0000-4000-9000-000000000001 - - - 22222222-0000-4000-9000-000000000002 - - - -

This SSP is an example for demonstration purposes.

-
- - - - - - F00000001 - Enhanced Example System - -

This is an enhanced example system for demonstration purposes, incorporating more FedRAMP-specific elements.

-
- - - - moderate - - - Financial Information - -

Contains sensitive financial data related to organizational operations.

-
- - - - high - - - moderate - - - low - -
-
- - - moderate - moderate - moderate - - - - - - -

The authorization boundary includes all components within the main data center and the disaster recovery site.

-
- - - -
- - -

A holistic, top-level explanation of the network architecture.

-
- - - -
-
- - - - System Administrator - - - system-admin - - - - Primary Application Server - -

Main application server hosting the core system functionality.

-
- main line - - - 11111111-0000-4000-9000-000000000001 - - -

This is the primary application server for the system.

-
-
- - - External API Connection - -

Secure connection to an external API for data enrichment.

-
- - - - - 11111111-0000-4000-9000-000000000001 - - -

This connection is used for secure data exchange with external systems.

-
-
- - - -

Primary database server

-
- - - - - - - - 11111111-0000-4000-9000-000000000001 - - - - -
-
- - - -

Implementation of controls for the Enhanced Example System

-
- - - - - - - -

Access Control Policy and Procedures (AC-1) is fully implemented in our system.

-
- - - 11111111-0000-4000-9000-000000000001 - -
-
- - - - - - - -

Information System Component Inventory (CM-8) is partially implemented.

-
- - - 11111111-0000-4000-9000-000000000001 - -
-
-
- - -

Detailed access control policy document

-
diff --git a/src/validations/constraints/content/ssp-authorization-type-INVALID.xml b/src/validations/constraints/content/ssp-authorization-type-INVALID.xml index 762b59e93..dd2fab6b5 100644 --- a/src/validations/constraints/content/ssp-authorization-type-INVALID.xml +++ b/src/validations/constraints/content/ssp-authorization-type-INVALID.xml @@ -3,214 +3,7 @@ xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://csrc.nist.gov/ns/oscal/1.0 https://github.com/usnistgov/OSCAL/releases/download/v1.1.2/oscal_ssp_schema.xsd" uuid="12345678-1234-4321-8765-123456789012"> - - Enhanced Example System Security Plan - 2024-08-01T14:30:00Z - 2024-08-01T14:30:00Z - 1.1 - 1.0.0 - SSP-2024-002 - - - Document Creator - - - Content Approver - - - System Administrator - - - Asset Owner - - -
- WRONG -
- -
- - Example Organization - ExOrg - -
- - - Jane Doe - jane.doe@example.com -
- - - - 11111111-0000-4000-9000-000000000001 - - - 22222222-0000-4000-9000-000000000002 - - - -

This SSP is an example for demonstration purposes.

-
- - - - - F00000001 - Enhanced Example System - -

This is an enhanced example system for demonstration purposes, incorporating more FedRAMP-specific elements.

-
- - - moderate - - - Financial Information - -

Contains sensitive financial data related to organizational operations.

-
- - - - high - - - moderate - - - low - -
-
- - - moderate - moderate - moderate - - - - - - -

The authorization boundary includes all components within the main data center and the disaster recovery site.

-
- - - -
- - -

A holistic, top-level explanation of the network architecture.

-
- - - -
- - - - System Administrator - - - system-admin - - - - Primary Application Server - -

Main application server hosting the core system functionality.

-
- main line - - - 11111111-0000-4000-9000-000000000001 - - -

This is the primary application server for the system.

-
-
- - - External API Connection - -

Secure connection to an external API for data enrichment.

-
- - - - - 11111111-0000-4000-9000-000000000001 - - -

This connection is used for secure data exchange with external systems.

-
-
- - - -

Primary database server

-
- - - - - - - - 11111111-0000-4000-9000-000000000001 - - - - -
-
- - - -

Implementation of controls for the Enhanced Example System

-
- - - - - - - -

Access Control Policy and Procedures (AC-1) is fully implemented in our system.

-
- - - 11111111-0000-4000-9000-000000000001 - -
-
- - - - - - - -

Information System Component Inventory (CM-8) is partially implemented.

-
- - - 11111111-0000-4000-9000-000000000001 - -
-
-
- - - - -

Detailed access control policy document

-
- -
-
diff --git a/src/validations/constraints/content/ssp-categorization-has-correct-system-attribute-INVALID.xml b/src/validations/constraints/content/ssp-categorization-has-correct-system-attribute-INVALID.xml index 762b59e93..237c20ea1 100644 --- a/src/validations/constraints/content/ssp-categorization-has-correct-system-attribute-INVALID.xml +++ b/src/validations/constraints/content/ssp-categorization-has-correct-system-attribute-INVALID.xml @@ -3,214 +3,12 @@ xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://csrc.nist.gov/ns/oscal/1.0 https://github.com/usnistgov/OSCAL/releases/download/v1.1.2/oscal_ssp_schema.xsd" uuid="12345678-1234-4321-8765-123456789012"> - - Enhanced Example System Security Plan - 2024-08-01T14:30:00Z - 2024-08-01T14:30:00Z - 1.1 - 1.0.0 - SSP-2024-002 - - - Document Creator - - - Content Approver - - - System Administrator - - - Asset Owner - - -
- WRONG -
- -
- - Example Organization - ExOrg - -
- - - Jane Doe - jane.doe@example.com -
- - - - 11111111-0000-4000-9000-000000000001 - - - 22222222-0000-4000-9000-000000000002 - - - -

This SSP is an example for demonstration purposes.

-
- - - - - F00000001 - Enhanced Example System - -

This is an enhanced example system for demonstration purposes, incorporating more FedRAMP-specific elements.

-
- - - - moderate - Financial Information - -

Contains sensitive financial data related to organizational operations.

-
- - high - - - moderate - - - low -
- - - moderate - moderate - moderate - - - - - - -

The authorization boundary includes all components within the main data center and the disaster recovery site.

-
- - - -
- - -

A holistic, top-level explanation of the network architecture.

-
- - - -
- - - - System Administrator - - - system-admin - - - - Primary Application Server - -

Main application server hosting the core system functionality.

-
- main line - - - 11111111-0000-4000-9000-000000000001 - - -

This is the primary application server for the system.

-
-
- - - External API Connection - -

Secure connection to an external API for data enrichment.

-
- - - - - 11111111-0000-4000-9000-000000000001 - - -

This connection is used for secure data exchange with external systems.

-
-
- - - -

Primary database server

-
- - - - - - - - 11111111-0000-4000-9000-000000000001 - - - - -
-
- - - -

Implementation of controls for the Enhanced Example System

-
- - - - - - - -

Access Control Policy and Procedures (AC-1) is fully implemented in our system.

-
- - - 11111111-0000-4000-9000-000000000001 - -
-
- - - - - - - -

Information System Component Inventory (CM-8) is partially implemented.

-
- - - 11111111-0000-4000-9000-000000000001 - -
-
-
- - - - -

Detailed access control policy document

-
- -
-
diff --git a/src/validations/constraints/content/ssp-categorization-has-information-type-id-INVALID.xml b/src/validations/constraints/content/ssp-categorization-has-information-type-id-INVALID.xml index 762b59e93..237c20ea1 100644 --- a/src/validations/constraints/content/ssp-categorization-has-information-type-id-INVALID.xml +++ b/src/validations/constraints/content/ssp-categorization-has-information-type-id-INVALID.xml @@ -3,214 +3,12 @@ xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://csrc.nist.gov/ns/oscal/1.0 https://github.com/usnistgov/OSCAL/releases/download/v1.1.2/oscal_ssp_schema.xsd" uuid="12345678-1234-4321-8765-123456789012"> - - Enhanced Example System Security Plan - 2024-08-01T14:30:00Z - 2024-08-01T14:30:00Z - 1.1 - 1.0.0 - SSP-2024-002 - - - Document Creator - - - Content Approver - - - System Administrator - - - Asset Owner - - -
- WRONG -
- -
- - Example Organization - ExOrg - -
- - - Jane Doe - jane.doe@example.com -
- - - - 11111111-0000-4000-9000-000000000001 - - - 22222222-0000-4000-9000-000000000002 - - - -

This SSP is an example for demonstration purposes.

-
- - - - - F00000001 - Enhanced Example System - -

This is an enhanced example system for demonstration purposes, incorporating more FedRAMP-specific elements.

-
- - - - moderate - Financial Information - -

Contains sensitive financial data related to organizational operations.

-
- - high - - - moderate - - - low -
- - - moderate - moderate - moderate - - - - - - -

The authorization boundary includes all components within the main data center and the disaster recovery site.

-
- - - -
- - -

A holistic, top-level explanation of the network architecture.

-
- - - -
- - - - System Administrator - - - system-admin - - - - Primary Application Server - -

Main application server hosting the core system functionality.

-
- main line - - - 11111111-0000-4000-9000-000000000001 - - -

This is the primary application server for the system.

-
-
- - - External API Connection - -

Secure connection to an external API for data enrichment.

-
- - - - - 11111111-0000-4000-9000-000000000001 - - -

This connection is used for secure data exchange with external systems.

-
-
- - - -

Primary database server

-
- - - - - - - - 11111111-0000-4000-9000-000000000001 - - - - -
-
- - - -

Implementation of controls for the Enhanced Example System

-
- - - - - - - -

Access Control Policy and Procedures (AC-1) is fully implemented in our system.

-
- - - 11111111-0000-4000-9000-000000000001 - -
-
- - - - - - - -

Information System Component Inventory (CM-8) is partially implemented.

-
- - - 11111111-0000-4000-9000-000000000001 - -
-
-
- - - - -

Detailed access control policy document

-
- -
-
diff --git a/src/validations/constraints/content/ssp-cloud-service-model-INVALID.xml b/src/validations/constraints/content/ssp-cloud-service-model-INVALID.xml index 762b59e93..c44fa26ed 100644 --- a/src/validations/constraints/content/ssp-cloud-service-model-INVALID.xml +++ b/src/validations/constraints/content/ssp-cloud-service-model-INVALID.xml @@ -3,214 +3,7 @@ xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://csrc.nist.gov/ns/oscal/1.0 https://github.com/usnistgov/OSCAL/releases/download/v1.1.2/oscal_ssp_schema.xsd" uuid="12345678-1234-4321-8765-123456789012"> - - Enhanced Example System Security Plan - 2024-08-01T14:30:00Z - 2024-08-01T14:30:00Z - 1.1 - 1.0.0 - SSP-2024-002 - - - Document Creator - - - Content Approver - - - System Administrator - - - Asset Owner - - -
- WRONG -
- -
- - Example Organization - ExOrg - -
- - - Jane Doe - jane.doe@example.com -
- - - - 11111111-0000-4000-9000-000000000001 - - - 22222222-0000-4000-9000-000000000002 - - - -

This SSP is an example for demonstration purposes.

-
- - - - - F00000001 - Enhanced Example System - -

This is an enhanced example system for demonstration purposes, incorporating more FedRAMP-specific elements.

-
- - - moderate - - - Financial Information - -

Contains sensitive financial data related to organizational operations.

-
- - - - high - - - moderate - - - low - -
-
- - - moderate - moderate - moderate - - - - - - -

The authorization boundary includes all components within the main data center and the disaster recovery site.

-
- - - -
- - -

A holistic, top-level explanation of the network architecture.

-
- - - -
- - - - System Administrator - - - system-admin - - - - Primary Application Server - -

Main application server hosting the core system functionality.

-
- main line - - - 11111111-0000-4000-9000-000000000001 - - -

This is the primary application server for the system.

-
-
- - - External API Connection - -

Secure connection to an external API for data enrichment.

-
- - - - - 11111111-0000-4000-9000-000000000001 - - -

This connection is used for secure data exchange with external systems.

-
-
- - - -

Primary database server

-
- - - - - - - - 11111111-0000-4000-9000-000000000001 - - - - -
-
- - - -

Implementation of controls for the Enhanced Example System

-
- - - - - - - -

Access Control Policy and Procedures (AC-1) is fully implemented in our system.

-
- - - 11111111-0000-4000-9000-000000000001 - -
-
- - - - - - - -

Information System Component Inventory (CM-8) is partially implemented.

-
- - - 11111111-0000-4000-9000-000000000001 - -
-
-
- - - - -

Detailed access control policy document

-
- -
-
diff --git a/src/validations/constraints/content/ssp-component-type-INVALID.xml b/src/validations/constraints/content/ssp-component-type-INVALID.xml index 0aaa31e5b..ed513b4c3 100644 --- a/src/validations/constraints/content/ssp-component-type-INVALID.xml +++ b/src/validations/constraints/content/ssp-component-type-INVALID.xml @@ -3,192 +3,8 @@ xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://csrc.nist.gov/ns/oscal/1.0 https://github.com/usnistgov/OSCAL/releases/download/v1.1.2/oscal_ssp_schema.xsd" uuid="12345678-1234-4321-8765-123456789012"> - - Enhanced Example System Security Plan - 2024-08-01T14:30:00Z - 2024-08-01T14:30:00Z - 1.1 - 1.0.0 - SSP-2024-002 - - - Document Creator - - - Content Approver - - - System Administrator - - - Asset Owner - - - - Example Organization - ExOrg - - - - Jane Doe - jane.doe@example.com - - - - 11111111-0000-4000-9000-000000000001 - - - 22222222-0000-4000-9000-000000000002 - - - -

This SSP is an example for demonstration purposes.

-
-
- - - - - F00000001 - Enhanced Example System - -

This is an enhanced example system for demonstration purposes, incorporating more FedRAMP-specific elements.

-
- moderate - - - Financial Information - -

Contains sensitive financial data related to organizational operations.

-
- - C.2.8.12 - - - high - - - moderate - - - low - -
-
- - moderate - moderate - moderate - - - - -

The authorization boundary includes all components within the main data center and the disaster recovery site.

-
-
-
- - - System Administrator - - system-admin - - - Primary Application Server - -

Main application server hosting the core system functionality.

-
- main line - - - 11111111-0000-4000-9000-000000000001 - - -

This is the primary application server for the system.

-
- - - External API Connection - -

Secure connection to an external API for data enrichment.

-
- - - - - 11111111-0000-4000-9000-000000000001 - - -

This connection is used for secure data exchange with external systems.

-
-
- - - -

Primary database server

-
- - - - - - - - 11111111-0000-4000-9000-000000000001 - - - - -
- - - -

Implementation of controls for the Enhanced Example System

-
- - - - - - - -

Access Control Policy and Procedures (AC-1) is fully implemented in our system.

-
- - - 11111111-0000-4000-9000-000000000001 - -
-
- - - - - - - -

Information System Component Inventory (CM-8) is partially implemented.

-
- - - 11111111-0000-4000-9000-000000000001 - -
-
-
- - - - Access Control Policy - -

Detailed access control policy document

-
- - -
-
diff --git a/src/validations/constraints/content/ssp-control-implementation-status-INVALID.xml b/src/validations/constraints/content/ssp-control-implementation-status-INVALID.xml index 762b59e93..01aea8746 100644 --- a/src/validations/constraints/content/ssp-control-implementation-status-INVALID.xml +++ b/src/validations/constraints/content/ssp-control-implementation-status-INVALID.xml @@ -3,214 +3,11 @@ xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://csrc.nist.gov/ns/oscal/1.0 https://github.com/usnistgov/OSCAL/releases/download/v1.1.2/oscal_ssp_schema.xsd" uuid="12345678-1234-4321-8765-123456789012"> - - Enhanced Example System Security Plan - 2024-08-01T14:30:00Z - 2024-08-01T14:30:00Z - 1.1 - 1.0.0 - SSP-2024-002 - - - Document Creator - - - Content Approver - - - System Administrator - - - Asset Owner - - -
- WRONG -
- -
- - Example Organization - ExOrg - -
- - - Jane Doe - jane.doe@example.com -
- - - - 11111111-0000-4000-9000-000000000001 - - - 22222222-0000-4000-9000-000000000002 - - - -

This SSP is an example for demonstration purposes.

-
- - - - - - F00000001 - Enhanced Example System - -

This is an enhanced example system for demonstration purposes, incorporating more FedRAMP-specific elements.

-
- - - - moderate - - - Financial Information - -

Contains sensitive financial data related to organizational operations.

-
- - - - high - - - moderate - - - low - -
-
- - - moderate - moderate - moderate - - - - - - -

The authorization boundary includes all components within the main data center and the disaster recovery site.

-
- - - -
- - -

A holistic, top-level explanation of the network architecture.

-
- - - -
-
- - - - System Administrator - - - system-admin - - - - Primary Application Server - -

Main application server hosting the core system functionality.

-
- main line - - - 11111111-0000-4000-9000-000000000001 - - -

This is the primary application server for the system.

-
-
- - - External API Connection - -

Secure connection to an external API for data enrichment.

-
- - - - - 11111111-0000-4000-9000-000000000001 - - -

This connection is used for secure data exchange with external systems.

-
-
- - - -

Primary database server

-
- - - - - - - - 11111111-0000-4000-9000-000000000001 - - - - -
-
- - -

Implementation of controls for the Enhanced Example System

-
- - - - - -

Access Control Policy and Procedures (AC-1) is fully implemented in our system.

-
- - 11111111-0000-4000-9000-000000000001 - -
-
- - - - - - - -

Information System Component Inventory (CM-8) is partially implemented.

-
- - - 11111111-0000-4000-9000-000000000001 -
- - - - -

Detailed access control policy document

-
- -
-
diff --git a/src/validations/constraints/content/ssp-data-center-US-INVALID.xml b/src/validations/constraints/content/ssp-data-center-US-INVALID.xml index 762b59e93..aaa6e2b84 100644 --- a/src/validations/constraints/content/ssp-data-center-US-INVALID.xml +++ b/src/validations/constraints/content/ssp-data-center-US-INVALID.xml @@ -4,213 +4,11 @@ xsi:schemaLocation="http://csrc.nist.gov/ns/oscal/1.0 https://github.com/usnistgov/OSCAL/releases/download/v1.1.2/oscal_ssp_schema.xsd" uuid="12345678-1234-4321-8765-123456789012"> - Enhanced Example System Security Plan - 2024-08-01T14:30:00Z - 2024-08-01T14:30:00Z - 1.1 - 1.0.0 - SSP-2024-002 - - - Document Creator - - - Content Approver - - - System Administrator - - - Asset Owner -
WRONG
- - Example Organization - ExOrg - -
- - - Jane Doe - jane.doe@example.com -
- - - - 11111111-0000-4000-9000-000000000001 - - - 22222222-0000-4000-9000-000000000002 - - - -

This SSP is an example for demonstration purposes.

-
- - - - - F00000001 - Enhanced Example System - -

This is an enhanced example system for demonstration purposes, incorporating more FedRAMP-specific elements.

-
- - - - moderate - - - Financial Information - -

Contains sensitive financial data related to organizational operations.

-
- - - - high - - - moderate - - - low - -
-
- - - moderate - moderate - moderate - - - - - - -

The authorization boundary includes all components within the main data center and the disaster recovery site.

-
- - - -
- - -

A holistic, top-level explanation of the network architecture.

-
- - - -
-
- - - - System Administrator - - - system-admin - - - - Primary Application Server - -

Main application server hosting the core system functionality.

-
- main line - - - 11111111-0000-4000-9000-000000000001 - - -

This is the primary application server for the system.

-
-
- - - External API Connection - -

Secure connection to an external API for data enrichment.

-
- - - - - 11111111-0000-4000-9000-000000000001 - - -

This connection is used for secure data exchange with external systems.

-
-
- - - -

Primary database server

-
- - - - - - - - 11111111-0000-4000-9000-000000000001 - - - - -
-
- - - -

Implementation of controls for the Enhanced Example System

-
- - - - - - - -

Access Control Policy and Procedures (AC-1) is fully implemented in our system.

-
- - - 11111111-0000-4000-9000-000000000001 - -
-
- - - - - - - -

Information System Component Inventory (CM-8) is partially implemented.

-
- - - 11111111-0000-4000-9000-000000000001 - -
-
-
- - - - -

Detailed access control policy document

-
- -
-
diff --git a/src/validations/constraints/content/ssp-data-center-alternate-INVALID.xml b/src/validations/constraints/content/ssp-data-center-alternate-INVALID.xml index 762b59e93..aaa6e2b84 100644 --- a/src/validations/constraints/content/ssp-data-center-alternate-INVALID.xml +++ b/src/validations/constraints/content/ssp-data-center-alternate-INVALID.xml @@ -4,213 +4,11 @@ xsi:schemaLocation="http://csrc.nist.gov/ns/oscal/1.0 https://github.com/usnistgov/OSCAL/releases/download/v1.1.2/oscal_ssp_schema.xsd" uuid="12345678-1234-4321-8765-123456789012"> - Enhanced Example System Security Plan - 2024-08-01T14:30:00Z - 2024-08-01T14:30:00Z - 1.1 - 1.0.0 - SSP-2024-002 - - - Document Creator - - - Content Approver - - - System Administrator - - - Asset Owner -
WRONG
- - Example Organization - ExOrg - -
- - - Jane Doe - jane.doe@example.com -
- - - - 11111111-0000-4000-9000-000000000001 - - - 22222222-0000-4000-9000-000000000002 - - - -

This SSP is an example for demonstration purposes.

-
- - - - - F00000001 - Enhanced Example System - -

This is an enhanced example system for demonstration purposes, incorporating more FedRAMP-specific elements.

-
- - - - moderate - - - Financial Information - -

Contains sensitive financial data related to organizational operations.

-
- - - - high - - - moderate - - - low - -
-
- - - moderate - moderate - moderate - - - - - - -

The authorization boundary includes all components within the main data center and the disaster recovery site.

-
- - - -
- - -

A holistic, top-level explanation of the network architecture.

-
- - - -
-
- - - - System Administrator - - - system-admin - - - - Primary Application Server - -

Main application server hosting the core system functionality.

-
- main line - - - 11111111-0000-4000-9000-000000000001 - - -

This is the primary application server for the system.

-
-
- - - External API Connection - -

Secure connection to an external API for data enrichment.

-
- - - - - 11111111-0000-4000-9000-000000000001 - - -

This connection is used for secure data exchange with external systems.

-
-
- - - -

Primary database server

-
- - - - - - - - 11111111-0000-4000-9000-000000000001 - - - - -
-
- - - -

Implementation of controls for the Enhanced Example System

-
- - - - - - - -

Access Control Policy and Procedures (AC-1) is fully implemented in our system.

-
- - - 11111111-0000-4000-9000-000000000001 - -
-
- - - - - - - -

Information System Component Inventory (CM-8) is partially implemented.

-
- - - 11111111-0000-4000-9000-000000000001 - -
-
-
- - - - -

Detailed access control policy document

-
- -
-
diff --git a/src/validations/constraints/content/ssp-data-center-count-INVALID.xml b/src/validations/constraints/content/ssp-data-center-count-INVALID.xml index 762b59e93..aaa6e2b84 100644 --- a/src/validations/constraints/content/ssp-data-center-count-INVALID.xml +++ b/src/validations/constraints/content/ssp-data-center-count-INVALID.xml @@ -4,213 +4,11 @@ xsi:schemaLocation="http://csrc.nist.gov/ns/oscal/1.0 https://github.com/usnistgov/OSCAL/releases/download/v1.1.2/oscal_ssp_schema.xsd" uuid="12345678-1234-4321-8765-123456789012"> - Enhanced Example System Security Plan - 2024-08-01T14:30:00Z - 2024-08-01T14:30:00Z - 1.1 - 1.0.0 - SSP-2024-002 - - - Document Creator - - - Content Approver - - - System Administrator - - - Asset Owner -
WRONG
- - Example Organization - ExOrg - -
- - - Jane Doe - jane.doe@example.com -
- - - - 11111111-0000-4000-9000-000000000001 - - - 22222222-0000-4000-9000-000000000002 - - - -

This SSP is an example for demonstration purposes.

-
- - - - - F00000001 - Enhanced Example System - -

This is an enhanced example system for demonstration purposes, incorporating more FedRAMP-specific elements.

-
- - - - moderate - - - Financial Information - -

Contains sensitive financial data related to organizational operations.

-
- - - - high - - - moderate - - - low - -
-
- - - moderate - moderate - moderate - - - - - - -

The authorization boundary includes all components within the main data center and the disaster recovery site.

-
- - - -
- - -

A holistic, top-level explanation of the network architecture.

-
- - - -
-
- - - - System Administrator - - - system-admin - - - - Primary Application Server - -

Main application server hosting the core system functionality.

-
- main line - - - 11111111-0000-4000-9000-000000000001 - - -

This is the primary application server for the system.

-
-
- - - External API Connection - -

Secure connection to an external API for data enrichment.

-
- - - - - 11111111-0000-4000-9000-000000000001 - - -

This connection is used for secure data exchange with external systems.

-
-
- - - -

Primary database server

-
- - - - - - - - 11111111-0000-4000-9000-000000000001 - - - - -
-
- - - -

Implementation of controls for the Enhanced Example System

-
- - - - - - - -

Access Control Policy and Procedures (AC-1) is fully implemented in our system.

-
- - - 11111111-0000-4000-9000-000000000001 - -
-
- - - - - - - -

Information System Component Inventory (CM-8) is partially implemented.

-
- - - 11111111-0000-4000-9000-000000000001 - -
-
-
- - - - -

Detailed access control policy document

-
- -
-
diff --git a/src/validations/constraints/content/ssp-data-center-country-code-INVALID.xml b/src/validations/constraints/content/ssp-data-center-country-code-INVALID.xml index e0b33fc12..e35b0f489 100644 --- a/src/validations/constraints/content/ssp-data-center-country-code-INVALID.xml +++ b/src/validations/constraints/content/ssp-data-center-country-code-INVALID.xml @@ -4,204 +4,10 @@ xsi:schemaLocation="http://csrc.nist.gov/ns/oscal/1.0 https://github.com/usnistgov/OSCAL/releases/download/v1.1.2/oscal_ssp_schema.xsd" uuid="12345678-1234-4321-8765-123456789012"> - Enhanced Example System Security Plan - 2024-08-01T14:30:00Z - 2024-08-01T14:30:00Z - 1.1 - 1.0.0 - SSP-2024-002 - - - Document Creator - - - Content Approver - - - System Administrator - - - Asset Owner -
- - Example Organization - ExOrg - -
- - - Jane Doe - jane.doe@example.com -
- - - - 11111111-0000-4000-9000-000000000001 - - - 22222222-0000-4000-9000-000000000002 - - - -

This SSP is an example for demonstration purposes.

-
- - - - - F00000001 - Enhanced Example System - -

This is an enhanced example system for demonstration purposes, incorporating more FedRAMP-specific elements.

-
- - - - moderate - - - Financial Information - -

Contains sensitive financial data related to organizational operations.

-
- - C.2.8.12 - - - high - - - moderate - - - low - -
-
- - - moderate - moderate - moderate - - - - - - -

The authorization boundary includes all components within the main data center and the disaster recovery site.

-
-
-
- - - - System Administrator - - - system-admin - - - - Primary Application Server - -

Main application server hosting the core system functionality.

-
- main line - - - 11111111-0000-4000-9000-000000000001 - - -

This is the primary application server for the system.

-
-
- - - External API Connection - -

Secure connection to an external API for data enrichment.

-
- - - - - 11111111-0000-4000-9000-000000000001 - - -

This connection is used for secure data exchange with external systems.

-
-
- - - -

Primary database server

-
- - - - - - - - 11111111-0000-4000-9000-000000000001 - - - - -
-
- - - -

Implementation of controls for the Enhanced Example System

-
- - - - - - - -

Access Control Policy and Procedures (AC-1) is fully implemented in our system.

-
- - - 11111111-0000-4000-9000-000000000001 - -
-
- - - - - - - -

Information System Component Inventory (CM-8) is partially implemented.

-
- - - 11111111-0000-4000-9000-000000000001 - -
-
-
- - - - Access Control Policy - -

Detailed access control policy document

-
- - -
-
diff --git a/src/validations/constraints/content/ssp-data-center-primary-INVALID.xml b/src/validations/constraints/content/ssp-data-center-primary-INVALID.xml index 762b59e93..aaa6e2b84 100644 --- a/src/validations/constraints/content/ssp-data-center-primary-INVALID.xml +++ b/src/validations/constraints/content/ssp-data-center-primary-INVALID.xml @@ -4,213 +4,11 @@ xsi:schemaLocation="http://csrc.nist.gov/ns/oscal/1.0 https://github.com/usnistgov/OSCAL/releases/download/v1.1.2/oscal_ssp_schema.xsd" uuid="12345678-1234-4321-8765-123456789012"> - Enhanced Example System Security Plan - 2024-08-01T14:30:00Z - 2024-08-01T14:30:00Z - 1.1 - 1.0.0 - SSP-2024-002 - - - Document Creator - - - Content Approver - - - System Administrator - - - Asset Owner -
WRONG
- - Example Organization - ExOrg - -
- - - Jane Doe - jane.doe@example.com -
- - - - 11111111-0000-4000-9000-000000000001 - - - 22222222-0000-4000-9000-000000000002 - - - -

This SSP is an example for demonstration purposes.

-
- - - - - F00000001 - Enhanced Example System - -

This is an enhanced example system for demonstration purposes, incorporating more FedRAMP-specific elements.

-
- - - - moderate - - - Financial Information - -

Contains sensitive financial data related to organizational operations.

-
- - - - high - - - moderate - - - low - -
-
- - - moderate - moderate - moderate - - - - - - -

The authorization boundary includes all components within the main data center and the disaster recovery site.

-
- - - -
- - -

A holistic, top-level explanation of the network architecture.

-
- - - -
-
- - - - System Administrator - - - system-admin - - - - Primary Application Server - -

Main application server hosting the core system functionality.

-
- main line - - - 11111111-0000-4000-9000-000000000001 - - -

This is the primary application server for the system.

-
-
- - - External API Connection - -

Secure connection to an external API for data enrichment.

-
- - - - - 11111111-0000-4000-9000-000000000001 - - -

This connection is used for secure data exchange with external systems.

-
-
- - - -

Primary database server

-
- - - - - - - - 11111111-0000-4000-9000-000000000001 - - - - -
-
- - - -

Implementation of controls for the Enhanced Example System

-
- - - - - - - -

Access Control Policy and Procedures (AC-1) is fully implemented in our system.

-
- - - 11111111-0000-4000-9000-000000000001 - -
-
- - - - - - - -

Information System Component Inventory (CM-8) is partially implemented.

-
- - - 11111111-0000-4000-9000-000000000001 - -
-
-
- - - - -

Detailed access control policy document

-
- -
-
diff --git a/src/validations/constraints/content/ssp-deployment-model-INVALID.xml b/src/validations/constraints/content/ssp-deployment-model-INVALID.xml index 762b59e93..03c17a486 100644 --- a/src/validations/constraints/content/ssp-deployment-model-INVALID.xml +++ b/src/validations/constraints/content/ssp-deployment-model-INVALID.xml @@ -3,214 +3,7 @@ xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://csrc.nist.gov/ns/oscal/1.0 https://github.com/usnistgov/OSCAL/releases/download/v1.1.2/oscal_ssp_schema.xsd" uuid="12345678-1234-4321-8765-123456789012"> - - Enhanced Example System Security Plan - 2024-08-01T14:30:00Z - 2024-08-01T14:30:00Z - 1.1 - 1.0.0 - SSP-2024-002 - - - Document Creator - - - Content Approver - - - System Administrator - - - Asset Owner - - -
- WRONG -
- -
- - Example Organization - ExOrg - -
- - - Jane Doe - jane.doe@example.com -
- - - - 11111111-0000-4000-9000-000000000001 - - - 22222222-0000-4000-9000-000000000002 - - - -

This SSP is an example for demonstration purposes.

-
- - - - - F00000001 - Enhanced Example System - -

This is an enhanced example system for demonstration purposes, incorporating more FedRAMP-specific elements.

-
- - - moderate - - - Financial Information - -

Contains sensitive financial data related to organizational operations.

-
- - - - high - - - moderate - - - low - -
-
- - - moderate - moderate - moderate - - - - - - -

The authorization boundary includes all components within the main data center and the disaster recovery site.

-
- - - -
- - -

A holistic, top-level explanation of the network architecture.

-
- - - -
- - - - System Administrator - - - system-admin - - - - Primary Application Server - -

Main application server hosting the core system functionality.

-
- main line - - - 11111111-0000-4000-9000-000000000001 - - -

This is the primary application server for the system.

-
-
- - - External API Connection - -

Secure connection to an external API for data enrichment.

-
- - - - - 11111111-0000-4000-9000-000000000001 - - -

This connection is used for secure data exchange with external systems.

-
-
- - - -

Primary database server

-
- - - - - - - - 11111111-0000-4000-9000-000000000001 - - - - -
-
- - - -

Implementation of controls for the Enhanced Example System

-
- - - - - - - -

Access Control Policy and Procedures (AC-1) is fully implemented in our system.

-
- - - 11111111-0000-4000-9000-000000000001 - -
-
- - - - - - - -

Information System Component Inventory (CM-8) is partially implemented.

-
- - - 11111111-0000-4000-9000-000000000001 - -
-
-
- - - - -

Detailed access control policy document

-
- -
-
diff --git a/src/validations/constraints/content/ssp-has-authenticator-assurance-level-INVALID.xml b/src/validations/constraints/content/ssp-has-authenticator-assurance-level-INVALID.xml index 762b59e93..c44fa26ed 100644 --- a/src/validations/constraints/content/ssp-has-authenticator-assurance-level-INVALID.xml +++ b/src/validations/constraints/content/ssp-has-authenticator-assurance-level-INVALID.xml @@ -3,214 +3,7 @@ xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://csrc.nist.gov/ns/oscal/1.0 https://github.com/usnistgov/OSCAL/releases/download/v1.1.2/oscal_ssp_schema.xsd" uuid="12345678-1234-4321-8765-123456789012"> - - Enhanced Example System Security Plan - 2024-08-01T14:30:00Z - 2024-08-01T14:30:00Z - 1.1 - 1.0.0 - SSP-2024-002 - - - Document Creator - - - Content Approver - - - System Administrator - - - Asset Owner - - -
- WRONG -
- -
- - Example Organization - ExOrg - -
- - - Jane Doe - jane.doe@example.com -
- - - - 11111111-0000-4000-9000-000000000001 - - - 22222222-0000-4000-9000-000000000002 - - - -

This SSP is an example for demonstration purposes.

-
- - - - - F00000001 - Enhanced Example System - -

This is an enhanced example system for demonstration purposes, incorporating more FedRAMP-specific elements.

-
- - - moderate - - - Financial Information - -

Contains sensitive financial data related to organizational operations.

-
- - - - high - - - moderate - - - low - -
-
- - - moderate - moderate - moderate - - - - - - -

The authorization boundary includes all components within the main data center and the disaster recovery site.

-
- - - -
- - -

A holistic, top-level explanation of the network architecture.

-
- - - -
- - - - System Administrator - - - system-admin - - - - Primary Application Server - -

Main application server hosting the core system functionality.

-
- main line - - - 11111111-0000-4000-9000-000000000001 - - -

This is the primary application server for the system.

-
-
- - - External API Connection - -

Secure connection to an external API for data enrichment.

-
- - - - - 11111111-0000-4000-9000-000000000001 - - -

This connection is used for secure data exchange with external systems.

-
-
- - - -

Primary database server

-
- - - - - - - - 11111111-0000-4000-9000-000000000001 - - - - -
-
- - - -

Implementation of controls for the Enhanced Example System

-
- - - - - - - -

Access Control Policy and Procedures (AC-1) is fully implemented in our system.

-
- - - 11111111-0000-4000-9000-000000000001 - -
-
- - - - - - - -

Information System Component Inventory (CM-8) is partially implemented.

-
- - - 11111111-0000-4000-9000-000000000001 - -
-
-
- - - - -

Detailed access control policy document

-
- -
-
diff --git a/src/validations/constraints/content/ssp-has-authorization-boundary-diagram-INVALID.xml b/src/validations/constraints/content/ssp-has-authorization-boundary-diagram-INVALID.xml index 060f59606..d4300feee 100644 --- a/src/validations/constraints/content/ssp-has-authorization-boundary-diagram-INVALID.xml +++ b/src/validations/constraints/content/ssp-has-authorization-boundary-diagram-INVALID.xml @@ -3,214 +3,8 @@ xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://csrc.nist.gov/ns/oscal/1.0 https://github.com/usnistgov/OSCAL/releases/download/v1.1.2/oscal_ssp_schema.xsd" uuid="12345678-1234-4321-8765-123456789012"> - - Enhanced Example System Security Plan - 2024-08-01T14:30:00Z - 2024-08-01T14:30:00Z - 1.1 - 1.0.0 - SSP-2024-002 - - - Document Creator - - - Content Approver - - - System Administrator - - - Asset Owner - - -
- WRONG -
- -
- - Example Organization - ExOrg - -
- - - Jane Doe - jane.doe@example.com -
- - - - 11111111-0000-4000-9000-000000000001 - - - 22222222-0000-4000-9000-000000000002 - - - -

This SSP is an example for demonstration purposes.

-
- - - - - F00000001 - Enhanced Example System - -

This is an enhanced example system for demonstration purposes, incorporating more FedRAMP-specific elements.

-
- - - - moderate - - - Financial Information - -

Contains sensitive financial data related to organizational operations.

-
- - - - - high - - - moderate - - - low - -
-
- - - moderate - moderate - moderate - - - - - -

The authorization boundary includes all components within the main data center and the disaster recovery site.

-
- - -

A holistic, top-level explanation of the network architecture.

-
- - - -
- - - - System Administrator - - - system-admin - - - - Primary Application Server - -

Main application server hosting the core system functionality.

-
- main line - - - 11111111-0000-4000-9000-000000000001 - - -

This is the primary application server for the system.

-
-
- - - External API Connection - -

Secure connection to an external API for data enrichment.

-
- - - - - 11111111-0000-4000-9000-000000000001 - - -

This connection is used for secure data exchange with external systems.

-
-
- - - -

Primary database server

-
- - - - - - - - 11111111-0000-4000-9000-000000000001 - - - - -
-
- - - -

Implementation of controls for the Enhanced Example System

-
- - - - - - - -

Access Control Policy and Procedures (AC-1) is fully implemented in our system.

-
- - - 11111111-0000-4000-9000-000000000001 - -
-
- - - - - - - -

Information System Component Inventory (CM-8) is partially implemented.

-
- - - 11111111-0000-4000-9000-000000000001 - -
-
-
- - - - - -

Detailed access control policy document

-
- - -
-
diff --git a/src/validations/constraints/content/ssp-has-authorization-boundary-diagram-caption-INVALID.xml b/src/validations/constraints/content/ssp-has-authorization-boundary-diagram-caption-INVALID.xml index 762b59e93..99fc57dba 100644 --- a/src/validations/constraints/content/ssp-has-authorization-boundary-diagram-caption-INVALID.xml +++ b/src/validations/constraints/content/ssp-has-authorization-boundary-diagram-caption-INVALID.xml @@ -3,214 +3,11 @@ xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://csrc.nist.gov/ns/oscal/1.0 https://github.com/usnistgov/OSCAL/releases/download/v1.1.2/oscal_ssp_schema.xsd" uuid="12345678-1234-4321-8765-123456789012"> - - Enhanced Example System Security Plan - 2024-08-01T14:30:00Z - 2024-08-01T14:30:00Z - 1.1 - 1.0.0 - SSP-2024-002 - - - Document Creator - - - Content Approver - - - System Administrator - - - Asset Owner - - -
- WRONG -
- -
- - Example Organization - ExOrg - -
- - - Jane Doe - jane.doe@example.com -
- - - - 11111111-0000-4000-9000-000000000001 - - - 22222222-0000-4000-9000-000000000002 - - - -

This SSP is an example for demonstration purposes.

-
- - - - - F00000001 - Enhanced Example System - -

This is an enhanced example system for demonstration purposes, incorporating more FedRAMP-specific elements.

-
- - - - moderate - - - Financial Information - -

Contains sensitive financial data related to organizational operations.

-
- - - - high - - - moderate - - - low - -
-
- - - moderate - moderate - moderate - - - - - -

The authorization boundary includes all components within the main data center and the disaster recovery site.

-
- - -

A holistic, top-level explanation of the network architecture.

-
- - - -
- - - - System Administrator - - - system-admin - - - - Primary Application Server - -

Main application server hosting the core system functionality.

-
- main line - - - 11111111-0000-4000-9000-000000000001 - - -

This is the primary application server for the system.

-
-
- - - External API Connection - -

Secure connection to an external API for data enrichment.

-
- - - - - 11111111-0000-4000-9000-000000000001 - - -

This connection is used for secure data exchange with external systems.

-
-
- - - -

Primary database server

-
- - - - - - - - 11111111-0000-4000-9000-000000000001 - - - - -
-
- - - -

Implementation of controls for the Enhanced Example System

-
- - - - - - - -

Access Control Policy and Procedures (AC-1) is fully implemented in our system.

-
- - - 11111111-0000-4000-9000-000000000001 - -
-
- - - - - - - -

Information System Component Inventory (CM-8) is partially implemented.

-
- - - 11111111-0000-4000-9000-000000000001 - -
-
-
- - - - -

Detailed access control policy document

-
- -
-
diff --git a/src/validations/constraints/content/ssp-has-authorization-boundary-diagram-description-INVALID.xml b/src/validations/constraints/content/ssp-has-authorization-boundary-diagram-description-INVALID.xml index 762b59e93..99fc57dba 100644 --- a/src/validations/constraints/content/ssp-has-authorization-boundary-diagram-description-INVALID.xml +++ b/src/validations/constraints/content/ssp-has-authorization-boundary-diagram-description-INVALID.xml @@ -3,214 +3,11 @@ xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://csrc.nist.gov/ns/oscal/1.0 https://github.com/usnistgov/OSCAL/releases/download/v1.1.2/oscal_ssp_schema.xsd" uuid="12345678-1234-4321-8765-123456789012"> - - Enhanced Example System Security Plan - 2024-08-01T14:30:00Z - 2024-08-01T14:30:00Z - 1.1 - 1.0.0 - SSP-2024-002 - - - Document Creator - - - Content Approver - - - System Administrator - - - Asset Owner - - -
- WRONG -
- -
- - Example Organization - ExOrg - -
- - - Jane Doe - jane.doe@example.com -
- - - - 11111111-0000-4000-9000-000000000001 - - - 22222222-0000-4000-9000-000000000002 - - - -

This SSP is an example for demonstration purposes.

-
- - - - - F00000001 - Enhanced Example System - -

This is an enhanced example system for demonstration purposes, incorporating more FedRAMP-specific elements.

-
- - - - moderate - - - Financial Information - -

Contains sensitive financial data related to organizational operations.

-
- - - - high - - - moderate - - - low - -
-
- - - moderate - moderate - moderate - - - - - -

The authorization boundary includes all components within the main data center and the disaster recovery site.

-
- - -

A holistic, top-level explanation of the network architecture.

-
- - - -
- - - - System Administrator - - - system-admin - - - - Primary Application Server - -

Main application server hosting the core system functionality.

-
- main line - - - 11111111-0000-4000-9000-000000000001 - - -

This is the primary application server for the system.

-
-
- - - External API Connection - -

Secure connection to an external API for data enrichment.

-
- - - - - 11111111-0000-4000-9000-000000000001 - - -

This connection is used for secure data exchange with external systems.

-
-
- - - -

Primary database server

-
- - - - - - - - 11111111-0000-4000-9000-000000000001 - - - - -
-
- - - -

Implementation of controls for the Enhanced Example System

-
- - - - - - - -

Access Control Policy and Procedures (AC-1) is fully implemented in our system.

-
- - - 11111111-0000-4000-9000-000000000001 - -
-
- - - - - - - -

Information System Component Inventory (CM-8) is partially implemented.

-
- - - 11111111-0000-4000-9000-000000000001 - -
-
-
- - - - -

Detailed access control policy document

-
- -
-
diff --git a/src/validations/constraints/content/ssp-has-authorization-boundary-diagram-link-INVALID.xml b/src/validations/constraints/content/ssp-has-authorization-boundary-diagram-link-INVALID.xml index 6ccbfa7bc..265d709ff 100644 --- a/src/validations/constraints/content/ssp-has-authorization-boundary-diagram-link-INVALID.xml +++ b/src/validations/constraints/content/ssp-has-authorization-boundary-diagram-link-INVALID.xml @@ -3,216 +3,10 @@ xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://csrc.nist.gov/ns/oscal/1.0 https://github.com/usnistgov/OSCAL/releases/download/v1.1.2/oscal_ssp_schema.xsd" uuid="12345678-1234-4321-8765-123456789012"> - - Enhanced Example System Security Plan - 2024-08-01T14:30:00Z - 2024-08-01T14:30:00Z - 1.1 - 1.0.0 - SSP-2024-002 - - - Document Creator - - - Content Approver - - - System Administrator - - - Asset Owner - - -
- WRONG -
- -
- - Example Organization - ExOrg - -
- - - Jane Doe - jane.doe@example.com -
- - - - 11111111-0000-4000-9000-000000000001 - - - 22222222-0000-4000-9000-000000000002 - - - -

This SSP is an example for demonstration purposes.

-
- - - - - F00000001 - Enhanced Example System - -

This is an enhanced example system for demonstration purposes, incorporating more FedRAMP-specific elements.

-
- - - - moderate - - - Financial Information - -

Contains sensitive financial data related to organizational operations.

-
- - - - - high - - - moderate - - - low - -
-
- - - moderate - moderate - moderate - - - - - -

The authorization boundary includes all components within the main data center and the disaster recovery site.

-
- - -

A holistic, top-level explanation of the network architecture.

-
- - - -
- - - - System Administrator - - - system-admin - - - - Primary Application Server - -

Main application server hosting the core system functionality.

-
- main line - - - 11111111-0000-4000-9000-000000000001 - - -

This is the primary application server for the system.

-
-
- - - External API Connection - -

Secure connection to an external API for data enrichment.

-
- - - - - 11111111-0000-4000-9000-000000000001 - - -

This connection is used for secure data exchange with external systems.

-
-
- - - -

Primary database server

-
- - - - - - - - 11111111-0000-4000-9000-000000000001 - - - - -
-
- - - -

Implementation of controls for the Enhanced Example System

-
- - - - - - - -

Access Control Policy and Procedures (AC-1) is fully implemented in our system.

-
- - - 11111111-0000-4000-9000-000000000001 - -
-
- - - - - - - -

Information System Component Inventory (CM-8) is partially implemented.

-
- - - 11111111-0000-4000-9000-000000000001 - -
-
-
- - - - - -

Detailed access control policy document

-
- - -
-
diff --git a/src/validations/constraints/content/ssp-has-authorization-boundary-diagram-link-rel-INVALID.xml b/src/validations/constraints/content/ssp-has-authorization-boundary-diagram-link-rel-INVALID.xml index 762b59e93..6481cafad 100644 --- a/src/validations/constraints/content/ssp-has-authorization-boundary-diagram-link-rel-INVALID.xml +++ b/src/validations/constraints/content/ssp-has-authorization-boundary-diagram-link-rel-INVALID.xml @@ -3,214 +3,11 @@ xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://csrc.nist.gov/ns/oscal/1.0 https://github.com/usnistgov/OSCAL/releases/download/v1.1.2/oscal_ssp_schema.xsd" uuid="12345678-1234-4321-8765-123456789012"> - - Enhanced Example System Security Plan - 2024-08-01T14:30:00Z - 2024-08-01T14:30:00Z - 1.1 - 1.0.0 - SSP-2024-002 - - - Document Creator - - - Content Approver - - - System Administrator - - - Asset Owner - - -
- WRONG -
- -
- - Example Organization - ExOrg - -
- - - Jane Doe - jane.doe@example.com -
- - - - 11111111-0000-4000-9000-000000000001 - - - 22222222-0000-4000-9000-000000000002 - - - -

This SSP is an example for demonstration purposes.

-
- - - - - F00000001 - Enhanced Example System - -

This is an enhanced example system for demonstration purposes, incorporating more FedRAMP-specific elements.

-
- - - - moderate - - - Financial Information - -

Contains sensitive financial data related to organizational operations.

-
- - - - high - - - moderate - - - low - -
-
- - - moderate - moderate - moderate - - - - - -

The authorization boundary includes all components within the main data center and the disaster recovery site.

-
- - -

A holistic, top-level explanation of the network architecture.

-
- - - -
- - - - System Administrator - - - system-admin - - - - Primary Application Server - -

Main application server hosting the core system functionality.

-
- main line - - - 11111111-0000-4000-9000-000000000001 - - -

This is the primary application server for the system.

-
-
- - - External API Connection - -

Secure connection to an external API for data enrichment.

-
- - - - - 11111111-0000-4000-9000-000000000001 - - -

This connection is used for secure data exchange with external systems.

-
-
- - - -

Primary database server

-
- - - - - - - - 11111111-0000-4000-9000-000000000001 - - - - -
-
- - - -

Implementation of controls for the Enhanced Example System

-
- - - - - - - -

Access Control Policy and Procedures (AC-1) is fully implemented in our system.

-
- - - 11111111-0000-4000-9000-000000000001 - -
-
- - - - - - - -

Information System Component Inventory (CM-8) is partially implemented.

-
- - - 11111111-0000-4000-9000-000000000001 - -
-
-
- - - - -

Detailed access control policy document

-
- -
-
- + \ No newline at end of file diff --git a/src/validations/constraints/content/ssp-has-authorization-boundary-diagram-link-rel-allowed-value-INVALID.xml b/src/validations/constraints/content/ssp-has-authorization-boundary-diagram-link-rel-allowed-value-INVALID.xml index 434d043d7..375cc0d4c 100644 --- a/src/validations/constraints/content/ssp-has-authorization-boundary-diagram-link-rel-allowed-value-INVALID.xml +++ b/src/validations/constraints/content/ssp-has-authorization-boundary-diagram-link-rel-allowed-value-INVALID.xml @@ -3,217 +3,11 @@ xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://csrc.nist.gov/ns/oscal/1.0 https://github.com/usnistgov/OSCAL/releases/download/v1.1.2/oscal_ssp_schema.xsd" uuid="12345678-1234-4321-8765-123456789012"> - - Enhanced Example System Security Plan - 2024-08-01T14:30:00Z - 2024-08-01T14:30:00Z - 1.1 - 1.0.0 - SSP-2024-002 - - - Document Creator - - - Content Approver - - - System Administrator - - - Asset Owner - - -
- WRONG -
- -
- - Example Organization - ExOrg - -
- - - Jane Doe - jane.doe@example.com -
- - - - 11111111-0000-4000-9000-000000000001 - - - 22222222-0000-4000-9000-000000000002 - - - -

This SSP is an example for demonstration purposes.

-
- - - - - F00000001 - Enhanced Example System - -

This is an enhanced example system for demonstration purposes, incorporating more FedRAMP-specific elements.

-
- - - - moderate - - - Financial Information - -

Contains sensitive financial data related to organizational operations.

-
- - - - - high - - - moderate - - - low - -
-
- - - moderate - moderate - moderate - - - - - -

The authorization boundary includes all components within the main data center and the disaster recovery site.

-
- - -

A holistic, top-level explanation of the network architecture.

-
- - - -
- - - - System Administrator - - - system-admin - - - - Primary Application Server - -

Main application server hosting the core system functionality.

-
- main line - - - 11111111-0000-4000-9000-000000000001 - - -

This is the primary application server for the system.

-
-
- - - External API Connection - -

Secure connection to an external API for data enrichment.

-
- - - - - 11111111-0000-4000-9000-000000000001 - - -

This connection is used for secure data exchange with external systems.

-
-
- - - -

Primary database server

-
- - - - - - - - 11111111-0000-4000-9000-000000000001 - - - - -
-
- - - -

Implementation of controls for the Enhanced Example System

-
- - - - - - - -

Access Control Policy and Procedures (AC-1) is fully implemented in our system.

-
- - - 11111111-0000-4000-9000-000000000001 - -
-
- - - - - - - -

Information System Component Inventory (CM-8) is partially implemented.

-
- - - 11111111-0000-4000-9000-000000000001 - -
-
-
- - - - - -

Detailed access control policy document

-
- - -
-
diff --git a/src/validations/constraints/content/ssp-has-configuration-management-plan-INVALID.xml b/src/validations/constraints/content/ssp-has-configuration-management-plan-INVALID.xml index 762b59e93..d134e7119 100644 --- a/src/validations/constraints/content/ssp-has-configuration-management-plan-INVALID.xml +++ b/src/validations/constraints/content/ssp-has-configuration-management-plan-INVALID.xml @@ -3,208 +3,6 @@ xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://csrc.nist.gov/ns/oscal/1.0 https://github.com/usnistgov/OSCAL/releases/download/v1.1.2/oscal_ssp_schema.xsd" uuid="12345678-1234-4321-8765-123456789012"> - - Enhanced Example System Security Plan - 2024-08-01T14:30:00Z - 2024-08-01T14:30:00Z - 1.1 - 1.0.0 - SSP-2024-002 - - - Document Creator - - - Content Approver - - - System Administrator - - - Asset Owner - - -
- WRONG -
- -
- - Example Organization - ExOrg - -
- - - Jane Doe - jane.doe@example.com -
- - - - 11111111-0000-4000-9000-000000000001 - - - 22222222-0000-4000-9000-000000000002 - - - -

This SSP is an example for demonstration purposes.

-
- - - - - - F00000001 - Enhanced Example System - -

This is an enhanced example system for demonstration purposes, incorporating more FedRAMP-specific elements.

-
- - - - moderate - - - Financial Information - -

Contains sensitive financial data related to organizational operations.

-
- - - - high - - - moderate - - - low - -
-
- - - moderate - moderate - moderate - - - - - - -

The authorization boundary includes all components within the main data center and the disaster recovery site.

-
- - - -
- - -

A holistic, top-level explanation of the network architecture.

-
- - - -
-
- - - - System Administrator - - - system-admin - - - - Primary Application Server - -

Main application server hosting the core system functionality.

-
- main line - - - 11111111-0000-4000-9000-000000000001 - - -

This is the primary application server for the system.

-
-
- - - External API Connection - -

Secure connection to an external API for data enrichment.

-
- - - - - 11111111-0000-4000-9000-000000000001 - - -

This connection is used for secure data exchange with external systems.

-
-
- - - -

Primary database server

-
- - - - - - - - 11111111-0000-4000-9000-000000000001 - - - - -
-
- - - -

Implementation of controls for the Enhanced Example System

-
- - - - - - - -

Access Control Policy and Procedures (AC-1) is fully implemented in our system.

-
- - - 11111111-0000-4000-9000-000000000001 - -
-
- - - - - - - -

Information System Component Inventory (CM-8) is partially implemented.

-
- - - 11111111-0000-4000-9000-000000000001 - -
-
-
- diff --git a/src/validations/constraints/content/ssp-has-federation-assurance-level-INVALID.xml b/src/validations/constraints/content/ssp-has-federation-assurance-level-INVALID.xml index 762b59e93..72e6dfad0 100644 --- a/src/validations/constraints/content/ssp-has-federation-assurance-level-INVALID.xml +++ b/src/validations/constraints/content/ssp-has-federation-assurance-level-INVALID.xml @@ -3,214 +3,7 @@ xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://csrc.nist.gov/ns/oscal/1.0 https://github.com/usnistgov/OSCAL/releases/download/v1.1.2/oscal_ssp_schema.xsd" uuid="12345678-1234-4321-8765-123456789012"> - - Enhanced Example System Security Plan - 2024-08-01T14:30:00Z - 2024-08-01T14:30:00Z - 1.1 - 1.0.0 - SSP-2024-002 - - - Document Creator - - - Content Approver - - - System Administrator - - - Asset Owner - - -
- WRONG -
- -
- - Example Organization - ExOrg - -
- - - Jane Doe - jane.doe@example.com -
- - - - 11111111-0000-4000-9000-000000000001 - - - 22222222-0000-4000-9000-000000000002 - - - -

This SSP is an example for demonstration purposes.

-
- - - - - F00000001 - Enhanced Example System - -

This is an enhanced example system for demonstration purposes, incorporating more FedRAMP-specific elements.

-
- - - moderate - - - Financial Information - -

Contains sensitive financial data related to organizational operations.

-
- - - - high - - - moderate - - - low - -
-
- - - moderate - moderate - moderate - - - - - - -

The authorization boundary includes all components within the main data center and the disaster recovery site.

-
- - - -
- - -

A holistic, top-level explanation of the network architecture.

-
- - - -
- - - - System Administrator - - - system-admin - - - - Primary Application Server - -

Main application server hosting the core system functionality.

-
- main line - - - 11111111-0000-4000-9000-000000000001 - - -

This is the primary application server for the system.

-
-
- - - External API Connection - -

Secure connection to an external API for data enrichment.

-
- - - - - 11111111-0000-4000-9000-000000000001 - - -

This connection is used for secure data exchange with external systems.

-
-
- - - -

Primary database server

-
- - - - - - - - 11111111-0000-4000-9000-000000000001 - - - - -
-
- - - -

Implementation of controls for the Enhanced Example System

-
- - - - - - - -

Access Control Policy and Procedures (AC-1) is fully implemented in our system.

-
- - - 11111111-0000-4000-9000-000000000001 - -
-
- - - - - - - -

Information System Component Inventory (CM-8) is partially implemented.

-
- - - 11111111-0000-4000-9000-000000000001 - -
-
-
- - - - -

Detailed access control policy document

-
- -
-
- + \ No newline at end of file diff --git a/src/validations/constraints/content/ssp-has-identity-assurance-level-INVALID.xml b/src/validations/constraints/content/ssp-has-identity-assurance-level-INVALID.xml index 762b59e93..72e6dfad0 100644 --- a/src/validations/constraints/content/ssp-has-identity-assurance-level-INVALID.xml +++ b/src/validations/constraints/content/ssp-has-identity-assurance-level-INVALID.xml @@ -3,214 +3,7 @@ xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://csrc.nist.gov/ns/oscal/1.0 https://github.com/usnistgov/OSCAL/releases/download/v1.1.2/oscal_ssp_schema.xsd" uuid="12345678-1234-4321-8765-123456789012"> - - Enhanced Example System Security Plan - 2024-08-01T14:30:00Z - 2024-08-01T14:30:00Z - 1.1 - 1.0.0 - SSP-2024-002 - - - Document Creator - - - Content Approver - - - System Administrator - - - Asset Owner - - -
- WRONG -
- -
- - Example Organization - ExOrg - -
- - - Jane Doe - jane.doe@example.com -
- - - - 11111111-0000-4000-9000-000000000001 - - - 22222222-0000-4000-9000-000000000002 - - - -

This SSP is an example for demonstration purposes.

-
- - - - - F00000001 - Enhanced Example System - -

This is an enhanced example system for demonstration purposes, incorporating more FedRAMP-specific elements.

-
- - - moderate - - - Financial Information - -

Contains sensitive financial data related to organizational operations.

-
- - - - high - - - moderate - - - low - -
-
- - - moderate - moderate - moderate - - - - - - -

The authorization boundary includes all components within the main data center and the disaster recovery site.

-
- - - -
- - -

A holistic, top-level explanation of the network architecture.

-
- - - -
- - - - System Administrator - - - system-admin - - - - Primary Application Server - -

Main application server hosting the core system functionality.

-
- main line - - - 11111111-0000-4000-9000-000000000001 - - -

This is the primary application server for the system.

-
-
- - - External API Connection - -

Secure connection to an external API for data enrichment.

-
- - - - - 11111111-0000-4000-9000-000000000001 - - -

This connection is used for secure data exchange with external systems.

-
-
- - - -

Primary database server

-
- - - - - - - - 11111111-0000-4000-9000-000000000001 - - - - -
-
- - - -

Implementation of controls for the Enhanced Example System

-
- - - - - - - -

Access Control Policy and Procedures (AC-1) is fully implemented in our system.

-
- - - 11111111-0000-4000-9000-000000000001 - -
-
- - - - - - - -

Information System Component Inventory (CM-8) is partially implemented.

-
- - - 11111111-0000-4000-9000-000000000001 - -
-
-
- - - - -

Detailed access control policy document

-
- -
-
- + \ No newline at end of file diff --git a/src/validations/constraints/content/ssp-has-incident-response-plan-INVALID.xml b/src/validations/constraints/content/ssp-has-incident-response-plan-INVALID.xml index 762b59e93..d134e7119 100644 --- a/src/validations/constraints/content/ssp-has-incident-response-plan-INVALID.xml +++ b/src/validations/constraints/content/ssp-has-incident-response-plan-INVALID.xml @@ -3,208 +3,6 @@ xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://csrc.nist.gov/ns/oscal/1.0 https://github.com/usnistgov/OSCAL/releases/download/v1.1.2/oscal_ssp_schema.xsd" uuid="12345678-1234-4321-8765-123456789012"> - - Enhanced Example System Security Plan - 2024-08-01T14:30:00Z - 2024-08-01T14:30:00Z - 1.1 - 1.0.0 - SSP-2024-002 - - - Document Creator - - - Content Approver - - - System Administrator - - - Asset Owner - - -
- WRONG -
- -
- - Example Organization - ExOrg - -
- - - Jane Doe - jane.doe@example.com -
- - - - 11111111-0000-4000-9000-000000000001 - - - 22222222-0000-4000-9000-000000000002 - - - -

This SSP is an example for demonstration purposes.

-
- - - - - - F00000001 - Enhanced Example System - -

This is an enhanced example system for demonstration purposes, incorporating more FedRAMP-specific elements.

-
- - - - moderate - - - Financial Information - -

Contains sensitive financial data related to organizational operations.

-
- - - - high - - - moderate - - - low - -
-
- - - moderate - moderate - moderate - - - - - - -

The authorization boundary includes all components within the main data center and the disaster recovery site.

-
- - - -
- - -

A holistic, top-level explanation of the network architecture.

-
- - - -
-
- - - - System Administrator - - - system-admin - - - - Primary Application Server - -

Main application server hosting the core system functionality.

-
- main line - - - 11111111-0000-4000-9000-000000000001 - - -

This is the primary application server for the system.

-
-
- - - External API Connection - -

Secure connection to an external API for data enrichment.

-
- - - - - 11111111-0000-4000-9000-000000000001 - - -

This connection is used for secure data exchange with external systems.

-
-
- - - -

Primary database server

-
- - - - - - - - 11111111-0000-4000-9000-000000000001 - - - - -
-
- - - -

Implementation of controls for the Enhanced Example System

-
- - - - - - - -

Access Control Policy and Procedures (AC-1) is fully implemented in our system.

-
- - - 11111111-0000-4000-9000-000000000001 - -
-
- - - - - - - -

Information System Component Inventory (CM-8) is partially implemented.

-
- - - 11111111-0000-4000-9000-000000000001 - -
-
-
- diff --git a/src/validations/constraints/content/ssp-has-information-system-contingency-plan-INVALID.xml b/src/validations/constraints/content/ssp-has-information-system-contingency-plan-INVALID.xml index 762b59e93..d134e7119 100644 --- a/src/validations/constraints/content/ssp-has-information-system-contingency-plan-INVALID.xml +++ b/src/validations/constraints/content/ssp-has-information-system-contingency-plan-INVALID.xml @@ -3,208 +3,6 @@ xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://csrc.nist.gov/ns/oscal/1.0 https://github.com/usnistgov/OSCAL/releases/download/v1.1.2/oscal_ssp_schema.xsd" uuid="12345678-1234-4321-8765-123456789012"> - - Enhanced Example System Security Plan - 2024-08-01T14:30:00Z - 2024-08-01T14:30:00Z - 1.1 - 1.0.0 - SSP-2024-002 - - - Document Creator - - - Content Approver - - - System Administrator - - - Asset Owner - - -
- WRONG -
- -
- - Example Organization - ExOrg - -
- - - Jane Doe - jane.doe@example.com -
- - - - 11111111-0000-4000-9000-000000000001 - - - 22222222-0000-4000-9000-000000000002 - - - -

This SSP is an example for demonstration purposes.

-
- - - - - - F00000001 - Enhanced Example System - -

This is an enhanced example system for demonstration purposes, incorporating more FedRAMP-specific elements.

-
- - - - moderate - - - Financial Information - -

Contains sensitive financial data related to organizational operations.

-
- - - - high - - - moderate - - - low - -
-
- - - moderate - moderate - moderate - - - - - - -

The authorization boundary includes all components within the main data center and the disaster recovery site.

-
- - - -
- - -

A holistic, top-level explanation of the network architecture.

-
- - - -
-
- - - - System Administrator - - - system-admin - - - - Primary Application Server - -

Main application server hosting the core system functionality.

-
- main line - - - 11111111-0000-4000-9000-000000000001 - - -

This is the primary application server for the system.

-
-
- - - External API Connection - -

Secure connection to an external API for data enrichment.

-
- - - - - 11111111-0000-4000-9000-000000000001 - - -

This connection is used for secure data exchange with external systems.

-
-
- - - -

Primary database server

-
- - - - - - - - 11111111-0000-4000-9000-000000000001 - - - - -
-
- - - -

Implementation of controls for the Enhanced Example System

-
- - - - - - - -

Access Control Policy and Procedures (AC-1) is fully implemented in our system.

-
- - - 11111111-0000-4000-9000-000000000001 - -
-
- - - - - - - -

Information System Component Inventory (CM-8) is partially implemented.

-
- - - 11111111-0000-4000-9000-000000000001 - -
-
-
- diff --git a/src/validations/constraints/content/ssp-has-network-architecture-INVALID.xml b/src/validations/constraints/content/ssp-has-network-architecture-INVALID.xml index 565a351b8..25cbe3dbe 100644 --- a/src/validations/constraints/content/ssp-has-network-architecture-INVALID.xml +++ b/src/validations/constraints/content/ssp-has-network-architecture-INVALID.xml @@ -3,200 +3,6 @@ xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://csrc.nist.gov/ns/oscal/1.0 https://github.com/usnistgov/OSCAL/releases/download/v1.1.2/oscal_ssp_schema.xsd" uuid="12345678-1234-4321-8765-123456789012"> - - Enhanced Example System Security Plan - 2024-08-01T14:30:00Z - 2024-08-01T14:30:00Z - 1.1 - 1.0.0 - SSP-2024-002 - - - Document Creator - - - Content Approver - - - System Administrator - - - Asset Owner - - -
- WRONG -
- -
- - Example Organization - ExOrg - -
- - - Jane Doe - jane.doe@example.com -
- - - - 11111111-0000-4000-9000-000000000001 - - - 22222222-0000-4000-9000-000000000002 - - - -

This SSP is an example for demonstration purposes.

-
- - - - - F00000001 - Enhanced Example System - -

This is an enhanced example system for demonstration purposes, incorporating more FedRAMP-specific elements.

-
- - - - moderate - - - Financial Information - -

Contains sensitive financial data related to organizational operations.

-
- - - - - - -
-
- - - moderate - moderate - moderate - - - - - - -

The authorization boundary includes all components within the main data center and the disaster recovery site.

-
-
- - - - System Administrator - - - system-admin - - - - Primary Application Server - -

Main application server hosting the core system functionality.

-
- main line - - - 11111111-0000-4000-9000-000000000001 - - -

This is the primary application server for the system.

-
-
- - - External API Connection - -

Secure connection to an external API for data enrichment.

-
- - - - - 11111111-0000-4000-9000-000000000001 - - -

This connection is used for secure data exchange with external systems.

-
-
- - - -

Primary database server

-
- - - - - - - - 11111111-0000-4000-9000-000000000001 - - - - -
-
- - - -

Implementation of controls for the Enhanced Example System

-
- - - - - - - -

Access Control Policy and Procedures (AC-1) is fully implemented in our system.

-
- - - 11111111-0000-4000-9000-000000000001 - -
-
- - - - - - - -

Information System Component Inventory (CM-8) is partially implemented.

-
- - - 11111111-0000-4000-9000-000000000001 - -
-
-
- - - - - -

Detailed access control policy document

-
- - -
-
diff --git a/src/validations/constraints/content/ssp-has-network-architecture-diagram-INVALID.xml b/src/validations/constraints/content/ssp-has-network-architecture-diagram-INVALID.xml index 88c10660e..5a44dfd10 100644 --- a/src/validations/constraints/content/ssp-has-network-architecture-diagram-INVALID.xml +++ b/src/validations/constraints/content/ssp-has-network-architecture-diagram-INVALID.xml @@ -3,211 +3,8 @@ xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://csrc.nist.gov/ns/oscal/1.0 https://github.com/usnistgov/OSCAL/releases/download/v1.1.2/oscal_ssp_schema.xsd" uuid="12345678-1234-4321-8765-123456789012"> - - Enhanced Example System Security Plan - 2024-08-01T14:30:00Z - 2024-08-01T14:30:00Z - 1.1 - 1.0.0 - SSP-2024-002 - - - Document Creator - - - Content Approver - - - System Administrator - - - Asset Owner - - -
- WRONG -
- -
- - Example Organization - ExOrg - -
- - - Jane Doe - jane.doe@example.com -
- - - - 11111111-0000-4000-9000-000000000001 - - - 22222222-0000-4000-9000-000000000002 - - - -

This SSP is an example for demonstration purposes.

-
- - - - - F00000001 - Enhanced Example System - -

This is an enhanced example system for demonstration purposes, incorporating more FedRAMP-specific elements.

-
- - - - moderate - - - Financial Information - -

Contains sensitive financial data related to organizational operations.

-
- - - - - high - - - moderate - - - low - -
-
- - - moderate - moderate - moderate - - - - - - -

The authorization boundary includes all components within the main data center and the disaster recovery site.

-
-
- -

A holistic, top-level explanation of the network architecture.

-
- - - - System Administrator - - - system-admin - - - - Primary Application Server - -

Main application server hosting the core system functionality.

-
- main line - - - 11111111-0000-4000-9000-000000000001 - - -

This is the primary application server for the system.

-
-
- - - External API Connection - -

Secure connection to an external API for data enrichment.

-
- - - - - 11111111-0000-4000-9000-000000000001 - - -

This connection is used for secure data exchange with external systems.

-
-
- - - -

Primary database server

-
- - - - - - - - 11111111-0000-4000-9000-000000000001 - - - - -
-
- - - -

Implementation of controls for the Enhanced Example System

-
- - - - - - - -

Access Control Policy and Procedures (AC-1) is fully implemented in our system.

-
- - - 11111111-0000-4000-9000-000000000001 - -
-
- - - - - - - -

Information System Component Inventory (CM-8) is partially implemented.

-
- - - 11111111-0000-4000-9000-000000000001 - -
-
-
- - - - - -

Detailed access control policy document

-
- - -
-
diff --git a/src/validations/constraints/content/ssp-has-network-architecture-diagram-caption-INVALID.xml b/src/validations/constraints/content/ssp-has-network-architecture-diagram-caption-INVALID.xml index 762b59e93..3277935c9 100644 --- a/src/validations/constraints/content/ssp-has-network-architecture-diagram-caption-INVALID.xml +++ b/src/validations/constraints/content/ssp-has-network-architecture-diagram-caption-INVALID.xml @@ -3,214 +3,10 @@ xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://csrc.nist.gov/ns/oscal/1.0 https://github.com/usnistgov/OSCAL/releases/download/v1.1.2/oscal_ssp_schema.xsd" uuid="12345678-1234-4321-8765-123456789012"> - - Enhanced Example System Security Plan - 2024-08-01T14:30:00Z - 2024-08-01T14:30:00Z - 1.1 - 1.0.0 - SSP-2024-002 - - - Document Creator - - - Content Approver - - - System Administrator - - - Asset Owner - - -
- WRONG -
- -
- - Example Organization - ExOrg - -
- - - Jane Doe - jane.doe@example.com -
- - - - 11111111-0000-4000-9000-000000000001 - - - 22222222-0000-4000-9000-000000000002 - - - -

This SSP is an example for demonstration purposes.

-
- - - - - F00000001 - Enhanced Example System - -

This is an enhanced example system for demonstration purposes, incorporating more FedRAMP-specific elements.

-
- - - - moderate - - - Financial Information - -

Contains sensitive financial data related to organizational operations.

-
- - - - high - - - moderate - - - low - -
-
- - - moderate - moderate - moderate - - - - - - -

The authorization boundary includes all components within the main data center and the disaster recovery site.

-
- - - -
- -

A holistic, top-level explanation of the network architecture.

-
-
- - - - System Administrator - - - system-admin - - - - Primary Application Server - -

Main application server hosting the core system functionality.

-
- main line - - - 11111111-0000-4000-9000-000000000001 - - -

This is the primary application server for the system.

-
-
- - - External API Connection - -

Secure connection to an external API for data enrichment.

-
- - - - - 11111111-0000-4000-9000-000000000001 - - -

This connection is used for secure data exchange with external systems.

-
-
- - - -

Primary database server

-
- - - - - - - - 11111111-0000-4000-9000-000000000001 - - - - -
-
- - - -

Implementation of controls for the Enhanced Example System

-
- - - - - - - -

Access Control Policy and Procedures (AC-1) is fully implemented in our system.

-
- - - 11111111-0000-4000-9000-000000000001 - -
-
- - - - - - - -

Information System Component Inventory (CM-8) is partially implemented.

-
- - - 11111111-0000-4000-9000-000000000001 - -
-
-
- - - - -

Detailed access control policy document

-
- -
-
diff --git a/src/validations/constraints/content/ssp-has-network-architecture-diagram-description-INVALID.xml b/src/validations/constraints/content/ssp-has-network-architecture-diagram-description-INVALID.xml index 762b59e93..3277935c9 100644 --- a/src/validations/constraints/content/ssp-has-network-architecture-diagram-description-INVALID.xml +++ b/src/validations/constraints/content/ssp-has-network-architecture-diagram-description-INVALID.xml @@ -3,214 +3,10 @@ xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://csrc.nist.gov/ns/oscal/1.0 https://github.com/usnistgov/OSCAL/releases/download/v1.1.2/oscal_ssp_schema.xsd" uuid="12345678-1234-4321-8765-123456789012"> - - Enhanced Example System Security Plan - 2024-08-01T14:30:00Z - 2024-08-01T14:30:00Z - 1.1 - 1.0.0 - SSP-2024-002 - - - Document Creator - - - Content Approver - - - System Administrator - - - Asset Owner - - -
- WRONG -
- -
- - Example Organization - ExOrg - -
- - - Jane Doe - jane.doe@example.com -
- - - - 11111111-0000-4000-9000-000000000001 - - - 22222222-0000-4000-9000-000000000002 - - - -

This SSP is an example for demonstration purposes.

-
- - - - - F00000001 - Enhanced Example System - -

This is an enhanced example system for demonstration purposes, incorporating more FedRAMP-specific elements.

-
- - - - moderate - - - Financial Information - -

Contains sensitive financial data related to organizational operations.

-
- - - - high - - - moderate - - - low - -
-
- - - moderate - moderate - moderate - - - - - - -

The authorization boundary includes all components within the main data center and the disaster recovery site.

-
- - - -
- -

A holistic, top-level explanation of the network architecture.

-
-
- - - - System Administrator - - - system-admin - - - - Primary Application Server - -

Main application server hosting the core system functionality.

-
- main line - - - 11111111-0000-4000-9000-000000000001 - - -

This is the primary application server for the system.

-
-
- - - External API Connection - -

Secure connection to an external API for data enrichment.

-
- - - - - 11111111-0000-4000-9000-000000000001 - - -

This connection is used for secure data exchange with external systems.

-
-
- - - -

Primary database server

-
- - - - - - - - 11111111-0000-4000-9000-000000000001 - - - - -
-
- - - -

Implementation of controls for the Enhanced Example System

-
- - - - - - - -

Access Control Policy and Procedures (AC-1) is fully implemented in our system.

-
- - - 11111111-0000-4000-9000-000000000001 - -
-
- - - - - - - -

Information System Component Inventory (CM-8) is partially implemented.

-
- - - 11111111-0000-4000-9000-000000000001 - -
-
-
- - - - -

Detailed access control policy document

-
- -
-
diff --git a/src/validations/constraints/content/ssp-has-network-architecture-diagram-link-INVALID.xml b/src/validations/constraints/content/ssp-has-network-architecture-diagram-link-INVALID.xml index 8d90f8e22..3277935c9 100644 --- a/src/validations/constraints/content/ssp-has-network-architecture-diagram-link-INVALID.xml +++ b/src/validations/constraints/content/ssp-has-network-architecture-diagram-link-INVALID.xml @@ -3,213 +3,10 @@ xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://csrc.nist.gov/ns/oscal/1.0 https://github.com/usnistgov/OSCAL/releases/download/v1.1.2/oscal_ssp_schema.xsd" uuid="12345678-1234-4321-8765-123456789012"> - - Enhanced Example System Security Plan - 2024-08-01T14:30:00Z - 2024-08-01T14:30:00Z - 1.1 - 1.0.0 - SSP-2024-002 - - - Document Creator - - - Content Approver - - - System Administrator - - - Asset Owner - - -
- WRONG -
- -
- - Example Organization - ExOrg - -
- - - Jane Doe - jane.doe@example.com -
- - - - 11111111-0000-4000-9000-000000000001 - - - 22222222-0000-4000-9000-000000000002 - - - -

This SSP is an example for demonstration purposes.

-
- - - - - F00000001 - Enhanced Example System - -

This is an enhanced example system for demonstration purposes, incorporating more FedRAMP-specific elements.

-
- - - - moderate - - - Financial Information - -

Contains sensitive financial data related to organizational operations.

-
- - - - - high - - - moderate - - - low - -
-
- - - moderate - moderate - moderate - - - - - - -

The authorization boundary includes all components within the main data center and the disaster recovery site.

-
-
- -

A holistic, top-level explanation of the network architecture.

-
- - - - System Administrator - - - system-admin - - - - Primary Application Server - -

Main application server hosting the core system functionality.

-
- main line - - - 11111111-0000-4000-9000-000000000001 - - -

This is the primary application server for the system.

-
-
- - - External API Connection - -

Secure connection to an external API for data enrichment.

-
- - - - - 11111111-0000-4000-9000-000000000001 - - -

This connection is used for secure data exchange with external systems.

-
-
- - - -

Primary database server

-
- - - - - - - - 11111111-0000-4000-9000-000000000001 - - - - -
-
- - - -

Implementation of controls for the Enhanced Example System

-
- - - - - - - -

Access Control Policy and Procedures (AC-1) is fully implemented in our system.

-
- - - 11111111-0000-4000-9000-000000000001 - -
-
- - - - - - - -

Information System Component Inventory (CM-8) is partially implemented.

-
- - - 11111111-0000-4000-9000-000000000001 - -
-
-
- - - - - -

Detailed access control policy document

-
- - -
-
diff --git a/src/validations/constraints/content/ssp-has-network-architecture-diagram-link-rel-INVALID.xml b/src/validations/constraints/content/ssp-has-network-architecture-diagram-link-rel-INVALID.xml index 9733ce9a4..c42b4e606 100644 --- a/src/validations/constraints/content/ssp-has-network-architecture-diagram-link-rel-INVALID.xml +++ b/src/validations/constraints/content/ssp-has-network-architecture-diagram-link-rel-INVALID.xml @@ -3,215 +3,11 @@ xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://csrc.nist.gov/ns/oscal/1.0 https://github.com/usnistgov/OSCAL/releases/download/v1.1.2/oscal_ssp_schema.xsd" uuid="12345678-1234-4321-8765-123456789012"> - - Enhanced Example System Security Plan - 2024-08-01T14:30:00Z - 2024-08-01T14:30:00Z - 1.1 - 1.0.0 - SSP-2024-002 - - - Document Creator - - - Content Approver - - - System Administrator - - - Asset Owner - - -
- WRONG -
- -
- - Example Organization - ExOrg - -
- - - Jane Doe - jane.doe@example.com -
- - - - 11111111-0000-4000-9000-000000000001 - - - 22222222-0000-4000-9000-000000000002 - - - -

This SSP is an example for demonstration purposes.

-
- - - - - F00000001 - Enhanced Example System - -

This is an enhanced example system for demonstration purposes, incorporating more FedRAMP-specific elements.

-
- - - - moderate - - - Financial Information - -

Contains sensitive financial data related to organizational operations.

-
- - - - - high - - - moderate - - - low - -
-
- - - moderate - moderate - moderate - - - - - - -

The authorization boundary includes all components within the main data center and the disaster recovery site.

-
-
- -

A holistic, top-level explanation of the network architecture.

-
- Network Diagram
- - - - System Administrator - - - system-admin - - - - Primary Application Server - -

Main application server hosting the core system functionality.

-
- main line - - - 11111111-0000-4000-9000-000000000001 - - -

This is the primary application server for the system.

-
-
- - - External API Connection - -

Secure connection to an external API for data enrichment.

-
- - - - - 11111111-0000-4000-9000-000000000001 - - -

This connection is used for secure data exchange with external systems.

-
-
- - - -

Primary database server

-
- - - - - - - - 11111111-0000-4000-9000-000000000001 - - - - -
-
- - - -

Implementation of controls for the Enhanced Example System

-
- - - - - - - -

Access Control Policy and Procedures (AC-1) is fully implemented in our system.

-
- - - 11111111-0000-4000-9000-000000000001 - -
-
- - - - - - - -

Information System Component Inventory (CM-8) is partially implemented.

-
- - - 11111111-0000-4000-9000-000000000001 - -
-
-
- - - - - -

Detailed access control policy document

-
- - -
-
diff --git a/src/validations/constraints/content/ssp-has-network-architecture-diagram-link-rel-allowed-value-INVALID.xml b/src/validations/constraints/content/ssp-has-network-architecture-diagram-link-rel-allowed-value-INVALID.xml index 762b59e93..957a5f279 100644 --- a/src/validations/constraints/content/ssp-has-network-architecture-diagram-link-rel-allowed-value-INVALID.xml +++ b/src/validations/constraints/content/ssp-has-network-architecture-diagram-link-rel-allowed-value-INVALID.xml @@ -3,214 +3,11 @@ xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://csrc.nist.gov/ns/oscal/1.0 https://github.com/usnistgov/OSCAL/releases/download/v1.1.2/oscal_ssp_schema.xsd" uuid="12345678-1234-4321-8765-123456789012"> - - Enhanced Example System Security Plan - 2024-08-01T14:30:00Z - 2024-08-01T14:30:00Z - 1.1 - 1.0.0 - SSP-2024-002 - - - Document Creator - - - Content Approver - - - System Administrator - - - Asset Owner - - -
- WRONG -
- -
- - Example Organization - ExOrg - -
- - - Jane Doe - jane.doe@example.com -
- - - - 11111111-0000-4000-9000-000000000001 - - - 22222222-0000-4000-9000-000000000002 - - - -

This SSP is an example for demonstration purposes.

-
- - - - - F00000001 - Enhanced Example System - -

This is an enhanced example system for demonstration purposes, incorporating more FedRAMP-specific elements.

-
- - - - moderate - - - Financial Information - -

Contains sensitive financial data related to organizational operations.

-
- - - - high - - - moderate - - - low - -
-
- - - moderate - moderate - moderate - - - - - - -

The authorization boundary includes all components within the main data center and the disaster recovery site.

-
- - - -
- -

A holistic, top-level explanation of the network architecture.

-
- - - - System Administrator - - - system-admin - - - - Primary Application Server - -

Main application server hosting the core system functionality.

-
- main line - - - 11111111-0000-4000-9000-000000000001 - - -

This is the primary application server for the system.

-
-
- - - External API Connection - -

Secure connection to an external API for data enrichment.

-
- - - - - 11111111-0000-4000-9000-000000000001 - - -

This connection is used for secure data exchange with external systems.

-
-
- - - -

Primary database server

-
- - - - - - - - 11111111-0000-4000-9000-000000000001 - - - - -
-
- - - -

Implementation of controls for the Enhanced Example System

-
- - - - - - - -

Access Control Policy and Procedures (AC-1) is fully implemented in our system.

-
- - - 11111111-0000-4000-9000-000000000001 - -
-
- - - - - - - -

Information System Component Inventory (CM-8) is partially implemented.

-
- - - 11111111-0000-4000-9000-000000000001 - -
-
-
- - - - -

Detailed access control policy document

-
- -
-
diff --git a/src/validations/constraints/content/ssp-has-rules-of-behavior-INVALID.xml b/src/validations/constraints/content/ssp-has-rules-of-behavior-INVALID.xml index 762b59e93..d134e7119 100644 --- a/src/validations/constraints/content/ssp-has-rules-of-behavior-INVALID.xml +++ b/src/validations/constraints/content/ssp-has-rules-of-behavior-INVALID.xml @@ -3,208 +3,6 @@ xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://csrc.nist.gov/ns/oscal/1.0 https://github.com/usnistgov/OSCAL/releases/download/v1.1.2/oscal_ssp_schema.xsd" uuid="12345678-1234-4321-8765-123456789012"> - - Enhanced Example System Security Plan - 2024-08-01T14:30:00Z - 2024-08-01T14:30:00Z - 1.1 - 1.0.0 - SSP-2024-002 - - - Document Creator - - - Content Approver - - - System Administrator - - - Asset Owner - - -
- WRONG -
- -
- - Example Organization - ExOrg - -
- - - Jane Doe - jane.doe@example.com -
- - - - 11111111-0000-4000-9000-000000000001 - - - 22222222-0000-4000-9000-000000000002 - - - -

This SSP is an example for demonstration purposes.

-
- - - - - - F00000001 - Enhanced Example System - -

This is an enhanced example system for demonstration purposes, incorporating more FedRAMP-specific elements.

-
- - - - moderate - - - Financial Information - -

Contains sensitive financial data related to organizational operations.

-
- - - - high - - - moderate - - - low - -
-
- - - moderate - moderate - moderate - - - - - - -

The authorization boundary includes all components within the main data center and the disaster recovery site.

-
- - - -
- - -

A holistic, top-level explanation of the network architecture.

-
- - - -
-
- - - - System Administrator - - - system-admin - - - - Primary Application Server - -

Main application server hosting the core system functionality.

-
- main line - - - 11111111-0000-4000-9000-000000000001 - - -

This is the primary application server for the system.

-
-
- - - External API Connection - -

Secure connection to an external API for data enrichment.

-
- - - - - 11111111-0000-4000-9000-000000000001 - - -

This connection is used for secure data exchange with external systems.

-
-
- - - -

Primary database server

-
- - - - - - - - 11111111-0000-4000-9000-000000000001 - - - - -
-
- - - -

Implementation of controls for the Enhanced Example System

-
- - - - - - - -

Access Control Policy and Procedures (AC-1) is fully implemented in our system.

-
- - - 11111111-0000-4000-9000-000000000001 - -
-
- - - - - - - -

Information System Component Inventory (CM-8) is partially implemented.

-
- - - 11111111-0000-4000-9000-000000000001 - -
-
-
- diff --git a/src/validations/constraints/content/ssp-has-separation-of-duties-matrix-INVALID.xml b/src/validations/constraints/content/ssp-has-separation-of-duties-matrix-INVALID.xml index 762b59e93..d134e7119 100644 --- a/src/validations/constraints/content/ssp-has-separation-of-duties-matrix-INVALID.xml +++ b/src/validations/constraints/content/ssp-has-separation-of-duties-matrix-INVALID.xml @@ -3,208 +3,6 @@ xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://csrc.nist.gov/ns/oscal/1.0 https://github.com/usnistgov/OSCAL/releases/download/v1.1.2/oscal_ssp_schema.xsd" uuid="12345678-1234-4321-8765-123456789012"> - - Enhanced Example System Security Plan - 2024-08-01T14:30:00Z - 2024-08-01T14:30:00Z - 1.1 - 1.0.0 - SSP-2024-002 - - - Document Creator - - - Content Approver - - - System Administrator - - - Asset Owner - - -
- WRONG -
- -
- - Example Organization - ExOrg - -
- - - Jane Doe - jane.doe@example.com -
- - - - 11111111-0000-4000-9000-000000000001 - - - 22222222-0000-4000-9000-000000000002 - - - -

This SSP is an example for demonstration purposes.

-
- - - - - - F00000001 - Enhanced Example System - -

This is an enhanced example system for demonstration purposes, incorporating more FedRAMP-specific elements.

-
- - - - moderate - - - Financial Information - -

Contains sensitive financial data related to organizational operations.

-
- - - - high - - - moderate - - - low - -
-
- - - moderate - moderate - moderate - - - - - - -

The authorization boundary includes all components within the main data center and the disaster recovery site.

-
- - - -
- - -

A holistic, top-level explanation of the network architecture.

-
- - - -
-
- - - - System Administrator - - - system-admin - - - - Primary Application Server - -

Main application server hosting the core system functionality.

-
- main line - - - 11111111-0000-4000-9000-000000000001 - - -

This is the primary application server for the system.

-
-
- - - External API Connection - -

Secure connection to an external API for data enrichment.

-
- - - - - 11111111-0000-4000-9000-000000000001 - - -

This connection is used for secure data exchange with external systems.

-
-
- - - -

Primary database server

-
- - - - - - - - 11111111-0000-4000-9000-000000000001 - - - - -
-
- - - -

Implementation of controls for the Enhanced Example System

-
- - - - - - - -

Access Control Policy and Procedures (AC-1) is fully implemented in our system.

-
- - - 11111111-0000-4000-9000-000000000001 - -
-
- - - - - - - -

Information System Component Inventory (CM-8) is partially implemented.

-
- - - 11111111-0000-4000-9000-000000000001 - -
-
-
- diff --git a/src/validations/constraints/content/ssp-has-user-guide-INVALID.xml b/src/validations/constraints/content/ssp-has-user-guide-INVALID.xml index 762b59e93..d134e7119 100644 --- a/src/validations/constraints/content/ssp-has-user-guide-INVALID.xml +++ b/src/validations/constraints/content/ssp-has-user-guide-INVALID.xml @@ -3,208 +3,6 @@ xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://csrc.nist.gov/ns/oscal/1.0 https://github.com/usnistgov/OSCAL/releases/download/v1.1.2/oscal_ssp_schema.xsd" uuid="12345678-1234-4321-8765-123456789012"> - - Enhanced Example System Security Plan - 2024-08-01T14:30:00Z - 2024-08-01T14:30:00Z - 1.1 - 1.0.0 - SSP-2024-002 - - - Document Creator - - - Content Approver - - - System Administrator - - - Asset Owner - - -
- WRONG -
- -
- - Example Organization - ExOrg - -
- - - Jane Doe - jane.doe@example.com -
- - - - 11111111-0000-4000-9000-000000000001 - - - 22222222-0000-4000-9000-000000000002 - - - -

This SSP is an example for demonstration purposes.

-
- - - - - - F00000001 - Enhanced Example System - -

This is an enhanced example system for demonstration purposes, incorporating more FedRAMP-specific elements.

-
- - - - moderate - - - Financial Information - -

Contains sensitive financial data related to organizational operations.

-
- - - - high - - - moderate - - - low - -
-
- - - moderate - moderate - moderate - - - - - - -

The authorization boundary includes all components within the main data center and the disaster recovery site.

-
- - - -
- - -

A holistic, top-level explanation of the network architecture.

-
- - - -
-
- - - - System Administrator - - - system-admin - - - - Primary Application Server - -

Main application server hosting the core system functionality.

-
- main line - - - 11111111-0000-4000-9000-000000000001 - - -

This is the primary application server for the system.

-
-
- - - External API Connection - -

Secure connection to an external API for data enrichment.

-
- - - - - 11111111-0000-4000-9000-000000000001 - - -

This connection is used for secure data exchange with external systems.

-
-
- - - -

Primary database server

-
- - - - - - - - 11111111-0000-4000-9000-000000000001 - - - - -
-
- - - -

Implementation of controls for the Enhanced Example System

-
- - - - - - - -

Access Control Policy and Procedures (AC-1) is fully implemented in our system.

-
- - - 11111111-0000-4000-9000-000000000001 - -
-
- - - - - - - -

Information System Component Inventory (CM-8) is partially implemented.

-
- - - 11111111-0000-4000-9000-000000000001 - -
-
-
- diff --git a/src/validations/constraints/content/ssp-information-type-system-INVALID.xml b/src/validations/constraints/content/ssp-information-type-system-INVALID.xml index 762b59e93..237c20ea1 100644 --- a/src/validations/constraints/content/ssp-information-type-system-INVALID.xml +++ b/src/validations/constraints/content/ssp-information-type-system-INVALID.xml @@ -3,214 +3,12 @@ xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://csrc.nist.gov/ns/oscal/1.0 https://github.com/usnistgov/OSCAL/releases/download/v1.1.2/oscal_ssp_schema.xsd" uuid="12345678-1234-4321-8765-123456789012"> - - Enhanced Example System Security Plan - 2024-08-01T14:30:00Z - 2024-08-01T14:30:00Z - 1.1 - 1.0.0 - SSP-2024-002 - - - Document Creator - - - Content Approver - - - System Administrator - - - Asset Owner - - -
- WRONG -
- -
- - Example Organization - ExOrg - -
- - - Jane Doe - jane.doe@example.com -
- - - - 11111111-0000-4000-9000-000000000001 - - - 22222222-0000-4000-9000-000000000002 - - - -

This SSP is an example for demonstration purposes.

-
- - - - - F00000001 - Enhanced Example System - -

This is an enhanced example system for demonstration purposes, incorporating more FedRAMP-specific elements.

-
- - - - moderate - Financial Information - -

Contains sensitive financial data related to organizational operations.

-
- - high - - - moderate - - - low -
- - - moderate - moderate - moderate - - - - - - -

The authorization boundary includes all components within the main data center and the disaster recovery site.

-
- - - -
- - -

A holistic, top-level explanation of the network architecture.

-
- - - -
- - - - System Administrator - - - system-admin - - - - Primary Application Server - -

Main application server hosting the core system functionality.

-
- main line - - - 11111111-0000-4000-9000-000000000001 - - -

This is the primary application server for the system.

-
-
- - - External API Connection - -

Secure connection to an external API for data enrichment.

-
- - - - - 11111111-0000-4000-9000-000000000001 - - -

This connection is used for secure data exchange with external systems.

-
-
- - - -

Primary database server

-
- - - - - - - - 11111111-0000-4000-9000-000000000001 - - - - -
-
- - - -

Implementation of controls for the Enhanced Example System

-
- - - - - - - -

Access Control Policy and Procedures (AC-1) is fully implemented in our system.

-
- - - 11111111-0000-4000-9000-000000000001 - -
-
- - - - - - - -

Information System Component Inventory (CM-8) is partially implemented.

-
- - - 11111111-0000-4000-9000-000000000001 - -
-
-
- - - - -

Detailed access control policy document

-
- -
-
diff --git a/src/validations/constraints/content/ssp-interconnection-direction-INVALID.xml b/src/validations/constraints/content/ssp-interconnection-direction-INVALID.xml index 0d4703ec6..1a9a7bc8c 100644 --- a/src/validations/constraints/content/ssp-interconnection-direction-INVALID.xml +++ b/src/validations/constraints/content/ssp-interconnection-direction-INVALID.xml @@ -3,113 +3,7 @@ xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://csrc.nist.gov/ns/oscal/1.0 https://github.com/usnistgov/OSCAL/releases/download/v1.1.2/oscal_ssp_schema.xsd" uuid="12345678-1234-4321-8765-123456789012"> - - Enhanced Example System Security Plan - 2024-08-01T14:30:00Z - 2024-08-01T14:30:00Z - 1.1 - 1.0.0 - SSP-2024-002 - - - Document Creator - - - Content Approver - - - System Administrator - - - Asset Owner - - - - Example Organization - ExOrg - - - - Jane Doe - jane.doe@example.com - - - - 11111111-0000-4000-9000-000000000001 - - - 22222222-0000-4000-9000-000000000002 - - - -

This SSP is an example for demonstration purposes.

-
-
- - - - - F00000001 - Enhanced Example System - -

This is an enhanced example system for demonstration purposes, incorporating more FedRAMP-specific elements.

-
- moderate - - - Financial Information - -

Contains sensitive financial data related to organizational operations.

-
- - C.2.8.12 - - - high - - - moderate - - - low - -
-
- - moderate - moderate - moderate - - - - -

The authorization boundary includes all components within the main data center and the disaster recovery site.

-
-
-
- - - System Administrator - - system-admin - - - - Primary Application Server - -

Main application server hosting the core system functionality.

-
- main line - - - 11111111-0000-4000-9000-000000000001 - - -

This is the primary application server for the system.

-
-
- External API Connection @@ -125,70 +19,5 @@

This connection is used for secure data exchange with external systems.

- - - -

Primary database server

-
- - - - - - - - 11111111-0000-4000-9000-000000000001 - - - - -
- - - -

Implementation of controls for the Enhanced Example System

-
- - - - - - - -

Access Control Policy and Procedures (AC-1) is fully implemented in our system.

-
- - - 11111111-0000-4000-9000-000000000001 - -
-
- - - - - - - -

Information System Component Inventory (CM-8) is partially implemented.

-
- - - 11111111-0000-4000-9000-000000000001 - -
-
-
- - - - Access Control Policy - -

Detailed access control policy document

-
- - -
-
\ No newline at end of file diff --git a/src/validations/constraints/content/ssp-interconnection-security-INVALID.xml b/src/validations/constraints/content/ssp-interconnection-security-INVALID.xml index 0d4703ec6..1a9a7bc8c 100644 --- a/src/validations/constraints/content/ssp-interconnection-security-INVALID.xml +++ b/src/validations/constraints/content/ssp-interconnection-security-INVALID.xml @@ -3,113 +3,7 @@ xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://csrc.nist.gov/ns/oscal/1.0 https://github.com/usnistgov/OSCAL/releases/download/v1.1.2/oscal_ssp_schema.xsd" uuid="12345678-1234-4321-8765-123456789012"> - - Enhanced Example System Security Plan - 2024-08-01T14:30:00Z - 2024-08-01T14:30:00Z - 1.1 - 1.0.0 - SSP-2024-002 - - - Document Creator - - - Content Approver - - - System Administrator - - - Asset Owner - - - - Example Organization - ExOrg - - - - Jane Doe - jane.doe@example.com - - - - 11111111-0000-4000-9000-000000000001 - - - 22222222-0000-4000-9000-000000000002 - - - -

This SSP is an example for demonstration purposes.

-
-
- - - - - F00000001 - Enhanced Example System - -

This is an enhanced example system for demonstration purposes, incorporating more FedRAMP-specific elements.

-
- moderate - - - Financial Information - -

Contains sensitive financial data related to organizational operations.

-
- - C.2.8.12 - - - high - - - moderate - - - low - -
-
- - moderate - moderate - moderate - - - - -

The authorization boundary includes all components within the main data center and the disaster recovery site.

-
-
-
- - - System Administrator - - system-admin - - - - Primary Application Server - -

Main application server hosting the core system functionality.

-
- main line - - - 11111111-0000-4000-9000-000000000001 - - -

This is the primary application server for the system.

-
-
- External API Connection @@ -125,70 +19,5 @@

This connection is used for secure data exchange with external systems.

- - - -

Primary database server

-
- - - - - - - - 11111111-0000-4000-9000-000000000001 - - - - -
- - - -

Implementation of controls for the Enhanced Example System

-
- - - - - - - -

Access Control Policy and Procedures (AC-1) is fully implemented in our system.

-
- - - 11111111-0000-4000-9000-000000000001 - -
-
- - - - - - - -

Information System Component Inventory (CM-8) is partially implemented.

-
- - - 11111111-0000-4000-9000-000000000001 - -
-
-
- - - - Access Control Policy - -

Detailed access control policy document

-
- - -
-
\ No newline at end of file diff --git a/src/validations/constraints/content/ssp-missing-response-components-INVALID.xml b/src/validations/constraints/content/ssp-missing-response-components-INVALID.xml index ceeee823a..9af07aea0 100644 --- a/src/validations/constraints/content/ssp-missing-response-components-INVALID.xml +++ b/src/validations/constraints/content/ssp-missing-response-components-INVALID.xml @@ -3,162 +3,6 @@ xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://csrc.nist.gov/ns/oscal/1.0 https://github.com/usnistgov/OSCAL/releases/download/v1.1.2/oscal_ssp_schema.xsd" uuid="12345678-1234-4321-8765-123456789012"> - - Enhanced Example System Security Plan - 2024-08-01T14:30:00Z - 2024-08-01T14:30:00Z - 1.1 - 1.0.0 - SSP-2024-002 - - - Document Creator - - - Content Approver - - - System Administrator - - - Asset Owner - - -
- WRONG -
- -
- - Example Organization - ExOrg - -
- - - Jane Doe - jane.doe@example.com -
- - - - 11111111-0000-4000-9000-000000000001 - - - 22222222-0000-4000-9000-000000000002 - - - -

This SSP is an example for demonstration purposes.

-
- - - - - - F00000001 - Enhanced Example System - -

This is an enhanced example system for demonstration purposes, incorporating more FedRAMP-specific elements.

-
- - - - moderate - - - Financial Information - -

Contains sensitive financial data related to organizational operations.

-
- - C.2.8.12 - - - high - - - moderate - - - low - -
-
- - - moderate - moderate - moderate - - - - - - -

The authorization boundary includes all components within the main data center and the disaster recovery site.

-
-
-
- - - - System Administrator - - - system-admin - - - - Primary Application Server - -

Main application server hosting the core system functionality.

-
- main line - - - 11111111-0000-4000-9000-000000000001 - - -

This is the primary application server for the system.

-
-
- - - External API Connection - -

Secure connection to an external API for data enrichment.

-
- - - - - 11111111-0000-4000-9000-000000000001 - - -

This connection is used for secure data exchange with external systems.

-
-
- - - -

Primary database server

-
- - - - - - - - 11111111-0000-4000-9000-000000000001 - - - - -
-
-

Implementation of controls for the Enhanced Example System

@@ -176,15 +20,4 @@
- - - - - -

Detailed access control policy document

-
- - -
-
diff --git a/src/validations/constraints/content/ssp-privilege-level-INVALID.xml b/src/validations/constraints/content/ssp-privilege-level-INVALID.xml index 762b59e93..8413ce1bc 100644 --- a/src/validations/constraints/content/ssp-privilege-level-INVALID.xml +++ b/src/validations/constraints/content/ssp-privilege-level-INVALID.xml @@ -3,214 +3,9 @@ xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://csrc.nist.gov/ns/oscal/1.0 https://github.com/usnistgov/OSCAL/releases/download/v1.1.2/oscal_ssp_schema.xsd" uuid="12345678-1234-4321-8765-123456789012"> - - Enhanced Example System Security Plan - 2024-08-01T14:30:00Z - 2024-08-01T14:30:00Z - 1.1 - 1.0.0 - SSP-2024-002 - - - Document Creator - - - Content Approver - - - System Administrator - - - Asset Owner - - -
- WRONG -
- -
- - Example Organization - ExOrg - -
- - - Jane Doe - jane.doe@example.com -
- - - - 11111111-0000-4000-9000-000000000001 - - - 22222222-0000-4000-9000-000000000002 - - - -

This SSP is an example for demonstration purposes.

-
- - - - - - F00000001 - Enhanced Example System - -

This is an enhanced example system for demonstration purposes, incorporating more FedRAMP-specific elements.

-
- - - - moderate - - - Financial Information - -

Contains sensitive financial data related to organizational operations.

-
- - - - high - - - moderate - - - low - -
-
- - - moderate - moderate - moderate - - - - - - -

The authorization boundary includes all components within the main data center and the disaster recovery site.

-
- - - -
- - -

A holistic, top-level explanation of the network architecture.

-
- - - -
-
- - System Administrator - - system-admin - - - Primary Application Server - -

Main application server hosting the core system functionality.

-
- main line - - - 11111111-0000-4000-9000-000000000001 - - -

This is the primary application server for the system.

-
-
- - - External API Connection - -

Secure connection to an external API for data enrichment.

-
- - - - - 11111111-0000-4000-9000-000000000001 - - -

This connection is used for secure data exchange with external systems.

-
-
- - - -

Primary database server

-
- - - - - - - - 11111111-0000-4000-9000-000000000001 - - - - -
- - - -

Implementation of controls for the Enhanced Example System

-
- - - - - - - -

Access Control Policy and Procedures (AC-1) is fully implemented in our system.

-
- - - 11111111-0000-4000-9000-000000000001 - -
-
- - - - - - - -

Information System Component Inventory (CM-8) is partially implemented.

-
- - - 11111111-0000-4000-9000-000000000001 - -
-
-
- - - - -

Detailed access control policy document

-
- -
-
- + \ No newline at end of file diff --git a/src/validations/constraints/content/ssp-resource-has-base64-or-rlink-INVALID.xml b/src/validations/constraints/content/ssp-resource-has-base64-or-rlink-INVALID.xml index 762b59e93..d134e7119 100644 --- a/src/validations/constraints/content/ssp-resource-has-base64-or-rlink-INVALID.xml +++ b/src/validations/constraints/content/ssp-resource-has-base64-or-rlink-INVALID.xml @@ -3,208 +3,6 @@ xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://csrc.nist.gov/ns/oscal/1.0 https://github.com/usnistgov/OSCAL/releases/download/v1.1.2/oscal_ssp_schema.xsd" uuid="12345678-1234-4321-8765-123456789012"> - - Enhanced Example System Security Plan - 2024-08-01T14:30:00Z - 2024-08-01T14:30:00Z - 1.1 - 1.0.0 - SSP-2024-002 - - - Document Creator - - - Content Approver - - - System Administrator - - - Asset Owner - - -
- WRONG -
- -
- - Example Organization - ExOrg - -
- - - Jane Doe - jane.doe@example.com -
- - - - 11111111-0000-4000-9000-000000000001 - - - 22222222-0000-4000-9000-000000000002 - - - -

This SSP is an example for demonstration purposes.

-
- - - - - - F00000001 - Enhanced Example System - -

This is an enhanced example system for demonstration purposes, incorporating more FedRAMP-specific elements.

-
- - - - moderate - - - Financial Information - -

Contains sensitive financial data related to organizational operations.

-
- - - - high - - - moderate - - - low - -
-
- - - moderate - moderate - moderate - - - - - - -

The authorization boundary includes all components within the main data center and the disaster recovery site.

-
- - - -
- - -

A holistic, top-level explanation of the network architecture.

-
- - - -
-
- - - - System Administrator - - - system-admin - - - - Primary Application Server - -

Main application server hosting the core system functionality.

-
- main line - - - 11111111-0000-4000-9000-000000000001 - - -

This is the primary application server for the system.

-
-
- - - External API Connection - -

Secure connection to an external API for data enrichment.

-
- - - - - 11111111-0000-4000-9000-000000000001 - - -

This connection is used for secure data exchange with external systems.

-
-
- - - -

Primary database server

-
- - - - - - - - 11111111-0000-4000-9000-000000000001 - - - - -
-
- - - -

Implementation of controls for the Enhanced Example System

-
- - - - - - - -

Access Control Policy and Procedures (AC-1) is fully implemented in our system.

-
- - - 11111111-0000-4000-9000-000000000001 - -
-
- - - - - - - -

Information System Component Inventory (CM-8) is partially implemented.

-
- - - 11111111-0000-4000-9000-000000000001 - -
-
-
- diff --git a/src/validations/constraints/content/ssp-resource-has-title-INVALID.xml b/src/validations/constraints/content/ssp-resource-has-title-INVALID.xml index 1b69c94ac..d134e7119 100644 --- a/src/validations/constraints/content/ssp-resource-has-title-INVALID.xml +++ b/src/validations/constraints/content/ssp-resource-has-title-INVALID.xml @@ -3,217 +3,12 @@ xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://csrc.nist.gov/ns/oscal/1.0 https://github.com/usnistgov/OSCAL/releases/download/v1.1.2/oscal_ssp_schema.xsd" uuid="12345678-1234-4321-8765-123456789012"> - - Enhanced Example System Security Plan - 2024-08-01T14:30:00Z - 2024-08-01T14:30:00Z - 1.1 - 1.0.0 - SSP-2024-002 - - - Document Creator - - - Content Approver - - - System Administrator - - - Asset Owner - - -
- WRONG -
- -
- - Example Organization - ExOrg - -
- - - Jane Doe - jane.doe@example.com -
- - - - 11111111-0000-4000-9000-000000000001 - - - 22222222-0000-4000-9000-000000000002 - - - -

This SSP is an example for demonstration purposes.

-
- - - - - - F00000001 - Enhanced Example System - -

This is an enhanced example system for demonstration purposes, incorporating more FedRAMP-specific elements.

-
- - - - moderate - - - Financial Information - -

Contains sensitive financial data related to organizational operations.

-
- - - - - high - - - moderate - - - low - -
-
- - - moderate - moderate - moderate - - - - - - -

The authorization boundary includes all components within the main data center and the disaster recovery site.

-
- - - -
- - -

A holistic, top-level explanation of the network architecture.

-
- - - -
-
- - - - System Administrator - - - system-admin - - - - Primary Application Server - -

Main application server hosting the core system functionality.

-
- main line - - - 11111111-0000-4000-9000-000000000001 - - -

This is the primary application server for the system.

-
-
- - - External API Connection - -

Secure connection to an external API for data enrichment.

-
- - - - - 11111111-0000-4000-9000-000000000001 - - -

This connection is used for secure data exchange with external systems.

-
-
- - - -

Primary database server

-
- - - - - - - - 11111111-0000-4000-9000-000000000001 - - - - -
-
- - - -

Implementation of controls for the Enhanced Example System

-
- - - - - - - -

Access Control Policy and Procedures (AC-1) is fully implemented in our system.

-
- - - 11111111-0000-4000-9000-000000000001 - -
-
- - - - - - - -

Information System Component Inventory (CM-8) is partially implemented.

-
- - - 11111111-0000-4000-9000-000000000001 - -
-
-
- -

Detailed access control policy document

-
diff --git a/src/validations/constraints/content/ssp-role-defined-authorizing-official-poc-INVALID.xml b/src/validations/constraints/content/ssp-role-defined-authorizing-official-poc-INVALID.xml index 762b59e93..97c9f68a5 100644 --- a/src/validations/constraints/content/ssp-role-defined-authorizing-official-poc-INVALID.xml +++ b/src/validations/constraints/content/ssp-role-defined-authorizing-official-poc-INVALID.xml @@ -52,165 +52,4 @@

This SSP is an example for demonstration purposes.

- - - - - F00000001 - Enhanced Example System - -

This is an enhanced example system for demonstration purposes, incorporating more FedRAMP-specific elements.

-
- - - - moderate - - - Financial Information - -

Contains sensitive financial data related to organizational operations.

-
- - - - high - - - moderate - - - low - -
-
- - - moderate - moderate - moderate - - - - - - -

The authorization boundary includes all components within the main data center and the disaster recovery site.

-
- - - -
- - -

A holistic, top-level explanation of the network architecture.

-
- - - -
-
- - - - System Administrator - - - system-admin - - - - Primary Application Server - -

Main application server hosting the core system functionality.

-
- main line - - - 11111111-0000-4000-9000-000000000001 - - -

This is the primary application server for the system.

-
-
- - - External API Connection - -

Secure connection to an external API for data enrichment.

-
- - - - - 11111111-0000-4000-9000-000000000001 - - -

This connection is used for secure data exchange with external systems.

-
-
- - - -

Primary database server

-
- - - - - - - - 11111111-0000-4000-9000-000000000001 - - - - -
-
- - - -

Implementation of controls for the Enhanced Example System

-
- - - - - - - -

Access Control Policy and Procedures (AC-1) is fully implemented in our system.

-
- - - 11111111-0000-4000-9000-000000000001 - -
-
- - - - - - - -

Information System Component Inventory (CM-8) is partially implemented.

-
- - - 11111111-0000-4000-9000-000000000001 - -
-
-
- - - - -

Detailed access control policy document

-
- -
-
diff --git a/src/validations/constraints/content/ssp-role-defined-information-system-security-officer-INVALID.xml b/src/validations/constraints/content/ssp-role-defined-information-system-security-officer-INVALID.xml index 762b59e93..97c9f68a5 100644 --- a/src/validations/constraints/content/ssp-role-defined-information-system-security-officer-INVALID.xml +++ b/src/validations/constraints/content/ssp-role-defined-information-system-security-officer-INVALID.xml @@ -52,165 +52,4 @@

This SSP is an example for demonstration purposes.

- - - - - F00000001 - Enhanced Example System - -

This is an enhanced example system for demonstration purposes, incorporating more FedRAMP-specific elements.

-
- - - - moderate - - - Financial Information - -

Contains sensitive financial data related to organizational operations.

-
- - - - high - - - moderate - - - low - -
-
- - - moderate - moderate - moderate - - - - - - -

The authorization boundary includes all components within the main data center and the disaster recovery site.

-
- - - -
- - -

A holistic, top-level explanation of the network architecture.

-
- - - -
-
- - - - System Administrator - - - system-admin - - - - Primary Application Server - -

Main application server hosting the core system functionality.

-
- main line - - - 11111111-0000-4000-9000-000000000001 - - -

This is the primary application server for the system.

-
-
- - - External API Connection - -

Secure connection to an external API for data enrichment.

-
- - - - - 11111111-0000-4000-9000-000000000001 - - -

This connection is used for secure data exchange with external systems.

-
-
- - - -

Primary database server

-
- - - - - - - - 11111111-0000-4000-9000-000000000001 - - - - -
-
- - - -

Implementation of controls for the Enhanced Example System

-
- - - - - - - -

Access Control Policy and Procedures (AC-1) is fully implemented in our system.

-
- - - 11111111-0000-4000-9000-000000000001 - -
-
- - - - - - - -

Information System Component Inventory (CM-8) is partially implemented.

-
- - - 11111111-0000-4000-9000-000000000001 - -
-
-
- - - - -

Detailed access control policy document

-
- -
-
diff --git a/src/validations/constraints/content/ssp-role-defined-system-owner-INVALID.xml b/src/validations/constraints/content/ssp-role-defined-system-owner-INVALID.xml index 762b59e93..97c9f68a5 100644 --- a/src/validations/constraints/content/ssp-role-defined-system-owner-INVALID.xml +++ b/src/validations/constraints/content/ssp-role-defined-system-owner-INVALID.xml @@ -52,165 +52,4 @@

This SSP is an example for demonstration purposes.

- - - - - F00000001 - Enhanced Example System - -

This is an enhanced example system for demonstration purposes, incorporating more FedRAMP-specific elements.

-
- - - - moderate - - - Financial Information - -

Contains sensitive financial data related to organizational operations.

-
- - - - high - - - moderate - - - low - -
-
- - - moderate - moderate - moderate - - - - - - -

The authorization boundary includes all components within the main data center and the disaster recovery site.

-
- - - -
- - -

A holistic, top-level explanation of the network architecture.

-
- - - -
-
- - - - System Administrator - - - system-admin - - - - Primary Application Server - -

Main application server hosting the core system functionality.

-
- main line - - - 11111111-0000-4000-9000-000000000001 - - -

This is the primary application server for the system.

-
-
- - - External API Connection - -

Secure connection to an external API for data enrichment.

-
- - - - - 11111111-0000-4000-9000-000000000001 - - -

This connection is used for secure data exchange with external systems.

-
-
- - - -

Primary database server

-
- - - - - - - - 11111111-0000-4000-9000-000000000001 - - - - -
-
- - - -

Implementation of controls for the Enhanced Example System

-
- - - - - - - -

Access Control Policy and Procedures (AC-1) is fully implemented in our system.

-
- - - 11111111-0000-4000-9000-000000000001 - -
-
- - - - - - - -

Information System Component Inventory (CM-8) is partially implemented.

-
- - - 11111111-0000-4000-9000-000000000001 - -
-
-
- - - - -

Detailed access control policy document

-
- -
-
diff --git a/src/validations/constraints/content/ssp-scan-type-INVALID.xml b/src/validations/constraints/content/ssp-scan-type-INVALID.xml index 762b59e93..4e64d0cbf 100644 --- a/src/validations/constraints/content/ssp-scan-type-INVALID.xml +++ b/src/validations/constraints/content/ssp-scan-type-INVALID.xml @@ -3,214 +3,9 @@ xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://csrc.nist.gov/ns/oscal/1.0 https://github.com/usnistgov/OSCAL/releases/download/v1.1.2/oscal_ssp_schema.xsd" uuid="12345678-1234-4321-8765-123456789012"> - - Enhanced Example System Security Plan - 2024-08-01T14:30:00Z - 2024-08-01T14:30:00Z - 1.1 - 1.0.0 - SSP-2024-002 - - - Document Creator - - - Content Approver - - - System Administrator - - - Asset Owner - - -
- WRONG -
- -
- - Example Organization - ExOrg - -
- - - Jane Doe - jane.doe@example.com -
- - - - 11111111-0000-4000-9000-000000000001 - - - 22222222-0000-4000-9000-000000000002 - - - -

This SSP is an example for demonstration purposes.

-
- - - - - - F00000001 - Enhanced Example System - -

This is an enhanced example system for demonstration purposes, incorporating more FedRAMP-specific elements.

-
- - - - moderate - - - Financial Information - -

Contains sensitive financial data related to organizational operations.

-
- - - - high - - - moderate - - - low - -
-
- - - moderate - moderate - moderate - - - - - - -

The authorization boundary includes all components within the main data center and the disaster recovery site.

-
- - - -
- - -

A holistic, top-level explanation of the network architecture.

-
- - - -
-
- - - System Administrator - - - system-admin - - - - Primary Application Server - -

Main application server hosting the core system functionality.

-
- main line - - - 11111111-0000-4000-9000-000000000001 - - -

This is the primary application server for the system.

-
-
- - - External API Connection - -

Secure connection to an external API for data enrichment.

-
- - - - - 11111111-0000-4000-9000-000000000001 - - -

This connection is used for secure data exchange with external systems.

-
-
- - -

Primary database server

-
- - - - - - - 11111111-0000-4000-9000-000000000001 - - - -
- - - -

Implementation of controls for the Enhanced Example System

-
- - - - - - - -

Access Control Policy and Procedures (AC-1) is fully implemented in our system.

-
- - - 11111111-0000-4000-9000-000000000001 - -
-
- - - - - - - -

Information System Component Inventory (CM-8) is partially implemented.

-
- - - 11111111-0000-4000-9000-000000000001 - -
-
-
- - - - -

Detailed access control policy document

-
- -
-
diff --git a/src/validations/constraints/content/ssp-user-type-INVALID.xml b/src/validations/constraints/content/ssp-user-type-INVALID.xml index 762b59e93..c18c69815 100644 --- a/src/validations/constraints/content/ssp-user-type-INVALID.xml +++ b/src/validations/constraints/content/ssp-user-type-INVALID.xml @@ -3,214 +3,9 @@ xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://csrc.nist.gov/ns/oscal/1.0 https://github.com/usnistgov/OSCAL/releases/download/v1.1.2/oscal_ssp_schema.xsd" uuid="12345678-1234-4321-8765-123456789012"> - - Enhanced Example System Security Plan - 2024-08-01T14:30:00Z - 2024-08-01T14:30:00Z - 1.1 - 1.0.0 - SSP-2024-002 - - - Document Creator - - - Content Approver - - - System Administrator - - - Asset Owner - - -
- WRONG -
- -
- - Example Organization - ExOrg - -
- - - Jane Doe - jane.doe@example.com -
- - - - 11111111-0000-4000-9000-000000000001 - - - 22222222-0000-4000-9000-000000000002 - - - -

This SSP is an example for demonstration purposes.

-
- - - - - - F00000001 - Enhanced Example System - -

This is an enhanced example system for demonstration purposes, incorporating more FedRAMP-specific elements.

-
- - - - moderate - - - Financial Information - -

Contains sensitive financial data related to organizational operations.

-
- - - - high - - - moderate - - - low - -
-
- - - moderate - moderate - moderate - - - - - - -

The authorization boundary includes all components within the main data center and the disaster recovery site.

-
- - - -
- - -

A holistic, top-level explanation of the network architecture.

-
- - - -
-
- - System Administrator - - system-admin - - - Primary Application Server - -

Main application server hosting the core system functionality.

-
- main line - - - 11111111-0000-4000-9000-000000000001 - - -

This is the primary application server for the system.

-
-
- - - External API Connection - -

Secure connection to an external API for data enrichment.

-
- - - - - 11111111-0000-4000-9000-000000000001 - - -

This connection is used for secure data exchange with external systems.

-
-
- - - -

Primary database server

-
- - - - - - - - 11111111-0000-4000-9000-000000000001 - - - - -
- - - -

Implementation of controls for the Enhanced Example System

-
- - - - - - - -

Access Control Policy and Procedures (AC-1) is fully implemented in our system.

-
- - - 11111111-0000-4000-9000-000000000001 - -
-
- - - - - - - -

Information System Component Inventory (CM-8) is partially implemented.

-
- - - 11111111-0000-4000-9000-000000000001 - -
-
-
- - - - -

Detailed access control policy document

-
- -
-