forked from GSA/fedramp-automation
-
Notifications
You must be signed in to change notification settings - Fork 0
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Add deprecation notifications in repo (issue#670) (GSA#708)
* Add deprecation notifications in repo (issue#670) * Update dist/content/rev4/README.md Co-authored-by: A.J. Stein <aj@gsa.gov> * Update dist/content/rev4/README.md Co-authored-by: A.J. Stein <aj@gsa.gov> * Update dist/content/rev5/resources/README.md Co-authored-by: A.J. Stein <aj@gsa.gov> * Update dist/content/rev5/resources/README.md Co-authored-by: A.J. Stein <aj@gsa.gov> * Update documents/README.md Co-authored-by: A.J. Stein <aj@gsa.gov> * Update presentations/README.md Co-authored-by: A.J. Stein <aj@gsa.gov> * Update src/examples/README.md Co-authored-by: A.J. Stein <aj@gsa.gov> * Update src/utils/README.md Co-authored-by: A.J. Stein <aj@gsa.gov> --------- Co-authored-by: A.J. Stein <aj@gsa.gov>
- Loading branch information
1 parent
5160d54
commit 24b6eac
Showing
9 changed files
with
50 additions
and
65 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,5 @@ | ||
# REV4 CONTENTS DEPRECATED | ||
|
||
FedRAMP has updated its documentation and templates to align with NIST Special Publication 800-53 Revision 5 (see https://www.fedramp.gov/rev5-transition/). All authorization and continuous monitoring activities going forward will be based on requirements in Revision 5, so FedRAMP Revision 4 baselines, resources, and templates are deprecated, as described in [ADR #007](/documents/adr/007-signal-unsupportent-content-in-github.md). | ||
|
||
**NOTE - CONTENT IN THIS FOLDER OR SUBFOLDER IS DEPRECATED. SUBSEQUENT RELEASES WILL NOT INCLUDE THIS CONTENT.** |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -1,50 +1,5 @@ | ||
<img src="https://github.com/GSA/fedramp-automation/raw/master/assets/FedRAMP_LOGO.png" alt="FedRAMP" width="76" height="94"><br /> | ||
# Federal Risk and Authorization Management Program (FedRAMP) Automation | ||
|
||
## FedRAMP OSCAL Resources | ||
|
||
These resources are experimental drafts, undergoing further updates in the near future. | ||
You are welcome to use them and provide feedback. | ||
Please let us know if you find them valuable. | ||
|
||
## FedRAMP OSCAL Registry and Resource Inventory | ||
|
||
The following resources are provided in both XML and JSON formats: | ||
- FedRAMP Extensions ([fedramp_extensions.xml](xml/fedramp_values.xml), [fedramp_values.json](json/fedramp_values.json)) | ||
- FedRAMP Information Types ([fedramp_information-types.xml](xml/fedramp_information-types.xml), [fedramp_information-types.json](json/fedramp_information-types.json)) | ||
|
||
### FedRAMP Values | ||
|
||
For your convenience, this file provides machine-readable constructs containing the acceptable values found in the FedRAMP OSCAL Registry [Acceptable Values (AV) Tab], as well as other helpful values. | ||
|
||
The content is provided in both XML and JSON formats. It is experimental and not documented at this time. It is also subject to change based on feedback. | ||
|
||
### FedRAMP Information Types | ||
|
||
The OSCAL-based SSP syntax allows an SSP author to identify the information ID of each information type within the system. FedRAMP only accepts NIST 800-60, Volume 2, Release 1 information types. | ||
|
||
For your convenience, this file provides tool developers the relevant 800-60 V2R1 identifiers and associated details in both XML and JSON formats. | ||
|
||
- JSON Format: nist-sp-800-60_vol2.json | ||
- XML Format: nist-sp-800-60_vol2.xml | ||
|
||
In anticipation of future changes to the information type references, such as when NIST updates SP 800-60 Volume 2, information types should be queried from this file using both the information-type id and the system, where these values match those in the information-type-id assembly within the SSP syntax. | ||
|
||
For example, an OSCAL-based FedRAMP SSP may contain the following: | ||
``` | ||
<system-information> | ||
<information-type name="Information Type Name" uuid="uuid-value"> | ||
<information-type-id system="https://doi.org/10.6028/NIST.SP.800-60v2r1"> | ||
C.2.4.1 | ||
</information-type-id> | ||
<!-- cut --> | ||
</system-information> | ||
``` | ||
|
||
The file should be queried based on both: | ||
- `system = "https://doi.org/10.6028/NIST.SP.800-60v2r1"`; and | ||
- `id = "C.2.4.1"` | ||
|
||
|
||
# REV5 RESOURCES DEPRECATED | ||
|
||
The experimental **fedramp_extensions.xml** and **fedramp_values.json** files are deprecated, as described in [ADR #007](/documents/adr/007-signal-unsupportent-content-in-github.md). FedRAMP will explore other options for providing information about FedRAMP OSCAL extension (all `prop` assemblies with `@ns="https://fedramp.gov/ns/oscal"' namespace) and allowed values with the community. | ||
|
||
**NOTE - CONTENT IN THIS FOLDER OR SUBFOLDER IS DEPRECATED. SUBSEQUENT RELEASES WILL NOT INCLUDE THIS CONTENT.** |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,5 @@ | ||
# REV5 TEMPLATES DEPRECATED | ||
|
||
The FedRAMP OSCAL templates will be renamed and repurposed as example files. These files will not be intended for use as templates or starter documents for creating OSCAL content. Instead, they will simply be available for OSCAL content authors as a reference for illustrative examples of how to represent certain information in FedRAMP OSCAL documents. The files will be relocated to the `/src/content/rev5/examples` folder. | ||
|
||
**NOTE - DEPRECATED CONTENTS WILL BE REMOVED FROM THE CODEBASE WHEN THE NEXT MAJOR RELEASE IS MADE AVAILABLE** |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -1,29 +1,31 @@ | ||
<img src="https://github.com/GSA/fedramp-automation/raw/master/assets/FedRAMP_LOGO.png" alt="FedRAMP" width="76" height="94"><br /> | ||
|
||
# Federal Risk and Authorization Management Program (FedRAMP) Automation Guides | ||
# Federal Risk and Authorization Management Program (FedRAMP) Automation Guides - DEPRECATED | ||
|
||
The following FedRAMP guides, based on the Open Security Controls Assessment Language (OSCAL), are available: | ||
The following FedRAMP OSCAL guides are no longer being maintained and will be deprecated and replaced by the [FedRAMP Developer Hub documentation site](https://automate.fedramp.gov/documentation): | ||
|
||
- **Guide to OSCAL-based FedRAMP Content** <span style='color:red'>[START HERE]</span> ([rev 4](./rev4/Guide_to_OSCAL-based_FedRAMP_Content.pdf) | [rev 5](./rev5/Guide_to_OSCAL-based_FedRAMP_Content_rev5.pdf)) | ||
- **Guide to OSCAL-based FedRAMP Content - DEPRECATED** <span style='color:red'>[START HERE]</span> ([rev 4](./rev4/Guide_to_OSCAL-based_FedRAMP_Content.pdf) | [rev 5](./rev5/Guide_to_OSCAL-based_FedRAMP_Content_rev5.pdf)) | ||
|
||
- **Guide to OSCAL-based FedRAMP System Security Plans (SSP)** ([rev 4](./rev4/Guide_to_OSCAL-based_FedRAMP_System_Security_Plans_(SSP)_rev4.pdf) | [rev 5](./rev5/Guide_to_OSCAL-based_FedRAMP_System_Security_Plans_(SSP)_rev5.pdf)) | ||
- **Guide to OSCAL-based FedRAMP System Security Plans (SSP)** ([rev 4](./rev4/Guide_to_OSCAL-based_FedRAMP_System_Security_Plans_(SSP)_rev4.pdf) | [rev 5](./rev5/Guide_to_OSCAL-based_FedRAMP_System_Security_Plans_(SSP)_rev5.pdf)) - **DEPRECATED** | ||
|
||
- **Guide to OSCAL-based FedRAMP Security Assessment Plans (SAP)** ([rev 4](./rev4/Guide_to_OSCAL-based_FedRAMP_Security_Assessment_Plans_(SAP)_rev4.pdf) | [rev 5](./rev5/Guide_to_OSCAL-based_FedRAMP_Security_Assessment_Plans_(SAP)_rev5.pdf)) | ||
- **Guide to OSCAL-based FedRAMP Security Assessment Plans (SAP)** ([rev 4](./rev4/Guide_to_OSCAL-based_FedRAMP_Security_Assessment_Plans_(SAP)_rev4.pdf) | [rev 5](./rev5/Guide_to_OSCAL-based_FedRAMP_Security_Assessment_Plans_(SAP)_rev5.pdf)) - **DEPRECATED** | ||
|
||
- **Guide to OSCAL-based FedRAMP Security Assessment Results (SAR)** ([rev 4](./rev4/Guide_to_OSCAL-based_FedRAMP_Security_Assessment_Reports_(SAR)_rev4.pdf) | [rev 5](./rev5/Guide_to_OSCAL-based_FedRAMP_Security_Assessment_Reports_(SAR)_rev5.pdf)) | ||
- **Guide to OSCAL-based FedRAMP Security Assessment Results (SAR)** ([rev 4](./rev4/Guide_to_OSCAL-based_FedRAMP_Security_Assessment_Reports_(SAR)_rev4.pdf) | [rev 5](./rev5/Guide_to_OSCAL-based_FedRAMP_Security_Assessment_Reports_(SAR)_rev5.pdf)) - **DEPRECATED** | ||
|
||
- **Guide to OSCAL-based FedRAMP Plan of Action and Milestones (POA&M)** ([rev 4](./rev4/Guide_to_OSCAL-based_FedRAMP_Plan_of_Action_and_Milestones_(POAM)_rev4.pdf) | [rev 5](./rev5/Guide_to_OSCAL-based_FedRAMP_Plan_of_Action_and_Milestones_(POAM)_rev5.pdf)) | ||
- **Guide to OSCAL-based FedRAMP Plan of Action and Milestones (POA&M)** ([rev 4](./rev4/Guide_to_OSCAL-based_FedRAMP_Plan_of_Action_and_Milestones_(POAM)_rev4.pdf) | [rev 5](./rev5/Guide_to_OSCAL-based_FedRAMP_Plan_of_Action_and_Milestones_(POAM)_rev5.pdf)) - **DEPRECATED** | ||
|
||
- **FedRAMP OSCAL Vendor Resource Summary** ([rev 4](./rev4/FedRAMP_OSCAL_Vendor_Resources.pdf) | rev 5) | ||
- **FedRAMP OSCAL Vendor Resource Summary** ([rev 4](./rev4/FedRAMP_OSCAL_Vendor_Resources.pdf) | rev 5) - **DEPRECATED** | ||
|
||
--- | ||
## FedRAMP OSCAL Registry | ||
## FedRAMP OSCAL Registry - DEPRECATED | ||
|
||
The FedRAMP OSCAL Registry is now a machine-readable file using the NIST OSCAL Extensions Model: | ||
The experimental FedRAMP OSCAL Registry is no longer being maintained and will be deprecate and replaced by the [FedRAMP Developer Hub documentation site](https://automate.fedramp.gov/documentation): | ||
|
||
- FedRAMP Extensions XML - ([rev 4](../dist/content/rev4/resources/xml/FedRAMP_extensions.xml) | [rev 5](../dist/content/rev5/resources/xml/FedRAMP_extensions.xml)) | ||
- FedRAMP Extensions JSON - ([rev 4](../dist/content/rev4/resources/json/FedRAMP_extensions.json) | [rev 5](../dist/content/rev5/resources/json/FedRAMP_extensions.json)) | ||
- FedRAMP Extensions HTML - ([rev 4 only](./rev4/FedRAMP_extensions.html)) | ||
- FedRAMP Extensions PDF - ([rev 4 only](./rev4/FedRAMP_extensions.pdf)) | ||
- FedRAMP Extensions XML - ([rev 4](../dist/content/rev4/resources/xml/FedRAMP_extensions.xml) | [rev 5](../dist/content/rev5/resources/xml/FedRAMP_extensions.xml)) - **DEPRECATED** | ||
- FedRAMP Extensions JSON - ([rev 4](../dist/content/rev4/resources/json/FedRAMP_extensions.json) | [rev 5](../dist/content/rev5/resources/json/FedRAMP_extensions.json)) - **DEPRECATED** | ||
- FedRAMP Extensions HTML - ([rev 4 only](./rev4/FedRAMP_extensions.html)) - **DEPRECATED** | ||
- FedRAMP Extensions PDF - ([rev 4 only](./rev4/FedRAMP_extensions.pdf)) - **DEPRECATED** | ||
|
||
**NOTE - CONTENT IN THIS FOLDER OR SUBFOLDER IS DEPRECATED. SUBSEQUENT RELEASES WILL NOT INCLUDE THIS CONTENT.** | ||
|
||
--- |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,5 @@ | ||
# PRESENTATION RELOCATING | ||
|
||
The OSCAL Implementers presentations and OSCAL Developer Data Bites presentations will be relocated to [https://github.com/GSA/automate.fedramp.gov](https://github.com/GSA/automate.fedramp.gov) and made available the [FedRAMP Developer Hub site](https://automate.fedramp.gov). | ||
|
||
**NOTE - CONTENT IN THIS FOLDER OR SUBFOLDER IS DEPRECATED. SUBSEQUENT RELEASES WILL NOT INCLUDE THIS CONTENT.** |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,5 @@ | ||
# UTILS FOLDER DEPRECATED | ||
|
||
The contents of this folder will be deprecated. | ||
|
||
**NOTE - CONTENT IN THIS FOLDER OR SUBFOLDER IS DEPRECATED. SUBSEQUENT RELEASES WILL NOT INCLUDE THIS CONTENT.** |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters