Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Feedback]: component[@type=interconnection]prop[@name="authorized-users"] #577

Open
1 of 12 tasks
Telos-sa opened this issue Mar 26, 2024 · 1 comment
Open
1 of 12 tasks

Comments

@Telos-sa
Copy link

This is a ...

question - need to understand something

This relates to ...

  • the FedRAMP OSCAL Registry
  • the FedRAMP OSCAL baselines
  • the Guide to OSCAL-based FedRAMP Content
  • the Guide to OSCAL-based FedRAMP System Security Plans (SSP)
  • the Guide to OSCAL-based FedRAMP Security Assessment Plans (SAP)
  • the Guide to OSCAL-based FedRAMP Security Assessment Results (SAR)
  • the Guide to OSCAL-based FedRAMP Plan of Action and Milestones (POA&M)
  • the FedRAMP SSP OSCAL Template (JSON or XML Format)
  • the FedRAMP SAP OSCAL Template (JSON or XML Format)
  • the FedRAMP SAR OSCAL Template (JSON or XML Format)
  • the FedRAMP POA&M OSCAL Template (JSON or XML Format)
  • the FedRAMP OSCAL Validations

What is your feedback?

The SSP Template refers this element to "Authorized Users/Authentication: List the user roles (e.g., SecOps engineers) authorized to access the service, and provide the authentication method."

image

As shown here.

Please confirm, if this is supposed to reference system-implementation/users/title (which is not required), system-implementation/users/uuid, or system-implementation/users/role-ids/role-id when creating the association.

Specifically, we are looking at the different user types that have access to the interconnection, not the role? Or whichever roles are associated with this user, which can use the interconnect?

Where, exactly?

component[@type=interconnection]prop[@name="authorized-users"]

Other information

No response

@Telos-sa
Copy link
Author

specifically, since this is not using the responsible-roles element, need to understand how this information should be correlated back to the user.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
Status: 🆕 New
Development

No branches or pull requests

1 participant