diff --git a/src/content/rev5/examples/ssp/xml/fedramp-ssp-example.oscal.xml b/src/content/rev5/examples/ssp/xml/fedramp-ssp-example.oscal.xml index 3486741d3..fc1db14c8 100644 --- a/src/content/rev5/examples/ssp/xml/fedramp-ssp-example.oscal.xml +++ b/src/content/rev5/examples/ssp/xml/fedramp-ssp-example.oscal.xml @@ -1,5 +1,5 @@ - + FedRAMP [Baseline Name] System Security Plan (SSP) @@ -1196,6 +1196,12 @@ + + + + + + @@ -1781,6 +1787,14 @@ + + + + + + + + @@ -2192,6 +2206,12 @@

If 'not-applicable', attest explain why authentication is not applicable in the remarks.

+ + + + + + @@ -2438,7 +2458,7 @@ at least annually - +

Describe how Part a is satisfied within the system.

@@ -2463,7 +2483,7 @@
- +

There

@@ -2491,7 +2511,7 @@
- +

Describe how Part b-1 is satisfied.

@@ -2499,7 +2519,7 @@
- +

Describe how Part b-2 is satisfied.

@@ -2676,14 +2696,14 @@
- +

Describe how Part b-1 is satisfied.

- +

Describe how Part b-2 is satisfied.

@@ -2742,7 +2762,7 @@
- +

For the portion of the control satisfied by the service provider, describe how the control is met.

@@ -2750,7 +2770,7 @@
- +

For the portion of the control satisfied by the service provider, describe how the control is met.

@@ -2809,14 +2829,14 @@
- +

For the portion of the control satisfied by the service provider, describe how the control is met.

- +

For the portion of the control satisfied by the service provider, describe how the control is met.

@@ -2874,14 +2894,14 @@
- +

For the portion of the control satisfied by the service provider, describe how the control is met.

- +

For the portion of the control satisfied by the service provider, describe how the control is met.

@@ -2937,14 +2957,14 @@
- +

For the portion of the control satisfied by the service provider, describe how the control is met.

- +

For the portion of the control satisfied by the service provider, describe how the control is met.

@@ -3187,14 +3207,14 @@
- +

For the portion of the control satisfied by the service provider, describe how the control is met.

- +

For the portion of the control satisfied by the service provider, describe how the control is met.

@@ -3252,14 +3272,14 @@
- +

For the portion of the control satisfied by the service provider, describe how the control is met.

- +

For the portion of the control satisfied by the service provider, describe how the control is met.

@@ -3317,14 +3337,14 @@
- +

For the portion of the control satisfied by the service provider, describe how the control is met.

- +

For the portion of the control satisfied by the service provider, describe how the control is met.

@@ -3533,14 +3553,14 @@
- +

For the portion of the control satisfied by the service provider, describe how the control is met.

- +

For the portion of the control satisfied by the service provider, describe how the control is met.

@@ -3598,14 +3618,14 @@
- +

For the portion of the control satisfied by the service provider, describe how the control is met.

- +

For the portion of the control satisfied by the service provider, describe how the control is met.

@@ -3663,14 +3683,14 @@
- +

For the portion of the control satisfied by the service provider, describe how the control is met.

- +

For the portion of the control satisfied by the service provider, describe how the control is met.

@@ -3728,14 +3748,14 @@
- +

For the portion of the control satisfied by the service provider, describe how the control is met.

- +

For the portion of the control satisfied by the service provider, describe how the control is met.

@@ -3793,14 +3813,14 @@
- +

For the portion of the control satisfied by the service provider, describe how the control is met.

- +

For the portion of the control satisfied by the service provider, describe how the control is met.

@@ -3858,14 +3878,14 @@
- +

For the portion of the control satisfied by the service provider, describe how the control is met.

- +

For the portion of the control satisfied by the service provider, describe how the control is met.

@@ -3923,14 +3943,14 @@
- +

For the portion of the control satisfied by the service provider, describe how the control is met.

- +

For the portion of the control satisfied by the service provider, describe how the control is met.

@@ -3988,14 +4008,14 @@
- +

For the portion of the control satisfied by the service provider, describe how the control is met.

- +

For the portion of the control satisfied by the service provider, describe how the control is met.

diff --git a/src/validations/constraints/fedramp-external-constraints.xml b/src/validations/constraints/fedramp-external-constraints.xml index 9432986fc..63efc14e7 100644 --- a/src/validations/constraints/fedramp-external-constraints.xml +++ b/src/validations/constraints/fedramp-external-constraints.xml @@ -194,6 +194,32 @@ + + + + + + + Required Policy Attachment is Present + + {$policy-statements(@statement-id)('message')} + + + Required Procedure Attachment is Present + + {$policy-statements(@statement-id)('message')} + + + +